CISA says malicious actors targeted more than 100 internet-exposed systems in the US water and wastewater sector during July, mostly programmable logic controllers connected directly to cellular modems.
The disclosure, published as part of fresh guidance on shrinking internet attack surface, is the first time federal agencies have quantified the number of systems hit in the recent wave of water utility attacks. The advisory attributes the spate of intrusions to Iranian-state aligned groups whose focus was taking down operational technology.
Officials put the number of affected states at more than a dozen. Utilities that acknowledged hits include operations in Alabama, Georgia, New Jersey, Michigan, Minnesota and South Dakota. No major outages resulted, yet the episode underscored how freely many utilities leave control gear exposed on the open internet.
CISA’s guidance urges organizations to inventory every internet-accessible system, remove unnecessary exposures, and for systems that must stay online: change default passwords, apply updates, route remote access through secure gateways, enforce multifactor authentication, and monitor traffic continuously.
The warning lands alongside a rare public CISA red-team report comparing two voluntary assessments. Red teamers reached both targets, but the water organization detected the simulated attack and halted it, while the government organization did neither.
CISA did not name either organization. The findings come as repeated federal warnings highlight water infrastructure as a soft spot in US critical infrastructure defense.
