July attack wave hit 100 exposed water systems, CISA says

CISA counts over 100 internet-exposed water systems targeted in July and urges utilities to shrink their attack surface.

CSBadmin
2 Min Read

CISA says malicious actors targeted more than 100 internet-exposed systems in the US water and wastewater sector during July, mostly programmable logic controllers connected directly to cellular modems.

The disclosure, published as part of fresh guidance on shrinking internet attack surface, is the first time federal agencies have quantified the number of systems hit in the recent wave of water utility attacks. The advisory attributes the spate of intrusions to Iranian-state aligned groups whose focus was taking down operational technology.

Officials put the number of affected states at more than a dozen. Utilities that acknowledged hits include operations in Alabama, Georgia, New Jersey, Michigan, Minnesota and South Dakota. No major outages resulted, yet the episode underscored how freely many utilities leave control gear exposed on the open internet.

CISA’s guidance urges organizations to inventory every internet-accessible system, remove unnecessary exposures, and for systems that must stay online: change default passwords, apply updates, route remote access through secure gateways, enforce multifactor authentication, and monitor traffic continuously.

The warning lands alongside a rare public CISA red-team report comparing two voluntary assessments. Red teamers reached both targets, but the water organization detected the simulated attack and halted it, while the government organization did neither.

CISA did not name either organization. The findings come as repeated federal warnings highlight water infrastructure as a soft spot in US critical infrastructure defense.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.