In an advisory issued last week, CISA reported that the July attacks targeted systems across at least a dozen states, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey, predominantly at small, rural utilities. While federal and state authorities have not publicly identified all affected states, the agency stressed that connecting PLCs—industrial control devices that manage pumps, valves, and other equipment—directly to cellular modems leaves critical infrastructure dangerously exposed.
“This is very serious,” said Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber. “More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets.”
The United States has not formally attributed the attacks to any specific group, though third-party analysts widely suspect Iranian involvement. The lack of official attribution, Hartman explained, is due to the difficulty of tracing cyber operations. “Adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems,” he said. “CISA has done the most important thing: quickly getting actionable information into the hands of water-sector operators so they can defend their systems.”
The July campaign represents about 0.5 percent of the roughly 16,000 water utilities in the U.S., but cybersecurity experts warn the real danger lies in what the intrusions portend. “These are test runs for a larger-scale attack,” said John Gallagher, vice president at Viakoo, an OT and IoT cybersecurity provider. The concern is amplified by a separate warning issued last week by five federal agencies, which noted that attackers are now using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, and energy facilities.
Cynthia Kaiser, senior vice president at Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, linked the latest activity to the earlier campaign. “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” she said. “Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society.”
In response, CISA recommended that water utilities disconnect PLCs from the internet, enforce password protection and multi-factor authentication, and restrict remote access to authorized engineering devices via VPNs or gateway systems. The agency urged owner-operators to change default passwords and implement allowlists for IP addresses.
The disclosures come amid rising concerns over the security of U.S. critical infrastructure, much of which relies on operational technology designed decades ago for closed, physical environments. “It was never built with the assumption that it would be reachable from the open internet,” Hartman noted.