Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The protein craze may not be for everyone

    July 31, 2026

    Land records reveal how Mennonites are reshaping Belize’s forests

    July 31, 2026

    Opinion: Manufacturing’s comeback depends on Wisconsin’s workforce

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The protein craze may not be for everyone
    • Land records reveal how Mennonites are reshaping Belize’s forests
    • Opinion: Manufacturing’s comeback depends on Wisconsin’s workforce
    • ‘Star Trek’ Still Captures Humanity’s Space Dreams
    • Here’s how many times Trump invoked Fifth Amendment in civil fraud trial, according to a judge
    • Trump says he is not sure about giving Patriot missiles to Ukraine, calling it a ‘big step’ – live | Trump administration
    • Spain’s PM blames traffickers after 60,000 migrants reach Ceuta from Morocco
    • The Guardian view on England’s centralised state: Andy Burnham must unbundle it | Editorial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of cyberattacks disrupting U.S. water utilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 31, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.

    The agency’s urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday.

    CISA’s alert refers to threat activity involved hackers targeting exposed programmable logic controllers (PLC) and changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and other actions that disrupted operations.

    image

    “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.”

    Organizations of all sizes running water and wastewater systems are being targeted, including some with mature cybersecurity programs.

    The bulletin notes that exposed operational technology (OT) may include undocumented cellular modems installed by operators, vendors, or system integrators.

    Internet-facing assets are exposed to defacement attacks, configuration changes, operational disruptions, and even physical damage, the agency said.

    CISA recommends immediately removing these assets from direct internet exposure. If this is not possible, organizations should use a VPN connection or gateway devices for secure access.

    Additionally, default passwords should be changed, and access should be limited to an IP address allow-list.

    The agency also pointed owners of Rockwell Automation MicroLogix 1400 PLCs to vendor guidance for recovering access if passwords have been changed.

    Cybersecurity search company Censys published a blog post where it quantifies internet exposure, estimating that currently there are more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts.

    Map
    Exposure map for Rockwell/Allen-Bradley PLCs
    Source: Censys

    However, it should be clarified that the map above shows devices reachable over the public internet, not systems that are necessarily being targeted or compromised.

    Regarding the MicroLogix 1400 controllers mentioned in CISA’s bulletin, Censys notes that many appear to be running EoS (end-of-sale) firmware versions.

    The cybersecurity company also highlighted the problem of undocumented cellular modems as a common blind spot, reporting that nearly half of the exposed Rockwell devices are reachable via Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink networks.

    ASNs hosting internet-exposed Rockwell/Allen-Bradley PLCs
    ASNs hosting internet-exposed Rockwell/Allen-Bradley PLCs
    Source: Censys

    Censys also provided an expanded set of indicators of compromise (IoCs) in its report, along with threat-hunting guidance.

    Earlier this week, the Minnesota IT Services (MNIT) agency activated the state’s cybersecurity incident response plan after identifying what it described as “a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems.”

    Multiple municipalities reported disruptions caused by the cyberattack, with equipment malfunctions forcing some utilities to temporarily switch to manual operations.

    MNIT has shared threat intelligence collected from the affected systems and provided guidance and best practices to help impacted utilities restore normal operations.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    CISA Cyberattacks disrupting U.S utilities warns water
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Copilot worm can spread through Microsoft Word docs

    In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

    ESET tracks rise in malicious AI skills and adaptable malware

    Interpol Leverages Global System to Curtail Fraud Payments

    USA Fencing: The Hidden Identity Challenge in Amateur Sports

    U.S. Military Boat Strikes in Latin America Are Shrouded in Secrecy

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The protein craze may not be for everyone

    July 31, 2026

    Land records reveal how Mennonites are reshaping Belize’s forests

    July 31, 2026

    Opinion: Manufacturing’s comeback depends on Wisconsin’s workforce

    July 31, 2026

    ‘Star Trek’ Still Captures Humanity’s Space Dreams

    July 31, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The protein craze may not be for everyone

    July 31, 2026

    Land records reveal how Mennonites are reshaping Belize’s forests

    July 31, 2026

    Opinion: Manufacturing’s comeback depends on Wisconsin’s workforce

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.