Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Copilot worm can spread through Microsoft Word docs

    July 31, 2026

    The good and the bad of perps, according to crypto traders

    July 31, 2026

    NASA Opens New Flight Dynamics Research Facility in Virginia

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Copilot worm can spread through Microsoft Word docs
    • The good and the bad of perps, according to crypto traders
    • NASA Opens New Flight Dynamics Research Facility in Virginia
    • 7th Circuit rejects Trump mandatory immigration detention policy
    • Africa’s Energy Curse Is a Political Choice by Rabah Arezki & Michael L. Ross
    • Council document doesn’t prove lease for Number 10 North was agreed before Andy Burnham was elected as Makerfield MP – Full Fact
    • George Clooney’s family evacuates their home in France amid wildfires
    • Trump administration slams Spain’s Sánchez for migrant ‘invasion’ of Ceuta – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of cyberattacks disrupting U.S. water utilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 31, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.

    The agency’s urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday.

    CISA’s alert refers to threat activity involved hackers targeting exposed programmable logic controllers (PLC) and changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and other actions that disrupted operations.

    image

    “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.”

    Organizations of all sizes running water and wastewater systems are being targeted, including some with mature cybersecurity programs.

    The bulletin notes that exposed operational technology (OT) may include undocumented cellular modems installed by operators, vendors, or system integrators.

    Internet-facing assets are exposed to defacement attacks, configuration changes, operational disruptions, and even physical damage, the agency said.

    CISA recommends immediately removing these assets from direct internet exposure. If this is not possible, organizations should use a VPN connection or gateway devices for secure access.

    Additionally, default passwords should be changed, and access should be limited to an IP address allow-list.

    The agency also pointed owners of Rockwell Automation MicroLogix 1400 PLCs to vendor guidance for recovering access if passwords have been changed.

    Cybersecurity search company Censys published a blog post where it quantifies internet exposure, estimating that currently there are more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts.

    Map
    Exposure map for Rockwell/Allen-Bradley PLCs
    Source: Censys

    However, it should be clarified that the map above shows devices reachable over the public internet, not systems that are necessarily being targeted or compromised.

    Regarding the MicroLogix 1400 controllers mentioned in CISA’s bulletin, Censys notes that many appear to be running EoS (end-of-sale) firmware versions.

    The cybersecurity company also highlighted the problem of undocumented cellular modems as a common blind spot, reporting that nearly half of the exposed Rockwell devices are reachable via Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink networks.

    ASNs hosting internet-exposed Rockwell/Allen-Bradley PLCs
    ASNs hosting internet-exposed Rockwell/Allen-Bradley PLCs
    Source: Censys

    Censys also provided an expanded set of indicators of compromise (IoCs) in its report, along with threat-hunting guidance.

    Earlier this week, the Minnesota IT Services (MNIT) agency activated the state’s cybersecurity incident response plan after identifying what it described as “a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems.”

    Multiple municipalities reported disruptions caused by the cyberattack, with equipment malfunctions forcing some utilities to temporarily switch to manual operations.

    MNIT has shared threat intelligence collected from the affected systems and provided guidance and best practices to help impacted utilities restore normal operations.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    CISA Cyberattacks disrupting U.S utilities warns water
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Copilot worm can spread through Microsoft Word docs

    In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

    ESET tracks rise in malicious AI skills and adaptable malware

    Interpol Leverages Global System to Curtail Fraud Payments

    USA Fencing: The Hidden Identity Challenge in Amateur Sports

    U.S. Military Boat Strikes in Latin America Are Shrouded in Secrecy

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Copilot worm can spread through Microsoft Word docs

    July 31, 2026

    The good and the bad of perps, according to crypto traders

    July 31, 2026

    NASA Opens New Flight Dynamics Research Facility in Virginia

    July 31, 2026

    7th Circuit rejects Trump mandatory immigration detention policy

    July 31, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Copilot worm can spread through Microsoft Word docs

    July 31, 2026

    The good and the bad of perps, according to crypto traders

    July 31, 2026

    NASA Opens New Flight Dynamics Research Facility in Virginia

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.