CISA Warns of Rising Cyberattacks on Water-System PLCs After Minnesota Disruptions

The US Cybersecurity and Infrastructure Security Agency has warned water and wastewater operators about a sharp rise in cyberattacks targeting programmable logic controllers, or PLCs, connected to the public internet.

Attackers have reportedly changed controller passwords, locked legitimate operators out of systems and modified device IP addresses, causing PLCs to lose communication with operational networks.

The warning follows a series of coordinated cyber incidents affecting more than 30 community water systems in Minnesota. While utilities largely maintained essential services using manual or backup procedures, the attacks disrupted automated operations and exposed a much wider security problem across critical infrastructure.

CISA said it is observing a “significant increase” in threat activity targeting PLCs used by water and wastewater organisations.

Attackers Are Targeting the Systems That Control Physical Operations

PLCs are specialised industrial computers used to control equipment such as pumps, valves, motors and treatment processes.

Unlike traditional business systems, these devices can directly influence physical operations. Losing access to a corporate laptop may interrupt office work. Losing access to a controller inside a water facility can force operators to manage essential infrastructure manually.

According to CISA, attackers have been changing PLC passwords and altering network configurations. In some cases, modifying the controller’s IP address disconnected it from the wider operational technology environment.

This does not automatically mean attackers contaminated drinking water or gained control over every treatment process. However, the activity can still create serious operational disruption by disabling automation, preventing remote administration and delaying an organisation’s ability to restore normal control.

More Than 30 Minnesota Water Systems Were Affected

The federal warning arrived after coordinated cyberattacks affected operational technology at more than 30 Minnesota community water systems on July 26 and 27.

Some automated systems were disrupted during the incidents. Nevertheless, affected utilities reportedly activated contingency procedures and continued operating through manual or alternative processes.

Available information does not indicate that drinking water was contaminated. Authorities have also not publicly identified the attackers responsible for the campaign.

Several Iran-linked threat groups have previously targeted exposed industrial controllers, particularly within the water sector. Even so, no authoritative evidence currently connects those actors to the Minnesota incidents.

Attribution therefore remains open.

The Hidden Cellular Modem Problem

The most important part of CISA’s warning may not be the password changes or altered IP addresses.

Instead, the alert highlights a less visible security weakness: cellular modems connected to industrial equipment.

Water facilities sometimes use cellular connections to allow vendors, system integrators or local operators to monitor and manage equipment remotely. These connections can be convenient, especially for small or geographically distributed facilities.

However, they may also create internet exposure that the organisation’s central security team does not know exists.

A controller may appear isolated from the corporate network while still being reachable through a modem installed by a contractor several years earlier. Standard vulnerability scanners and IT asset inventories may never detect that connection.

Consequently, an organisation can believe its operational technology is protected by network isolation when an undocumented external route remains available.

Internet-Exposed PLCs Remain an Easy Target

Industrial control attacks do not always require advanced malware or highly sophisticated zero-day vulnerabilities.

Poorly protected PLCs may be exposed through public IP addresses, remote-management interfaces, reused passwords or weakly secured cellular gateways.

Once attackers find an accessible controller, even relatively simple changes can create disruption. Resetting credentials may lock out operators. Changing the device’s network settings can make it disappear from the control environment. Modifying logic or configuration could produce more serious consequences, although CISA has not confirmed that such manipulation occurred in these incidents.

The threat is particularly serious for smaller utilities that may depend heavily on third-party vendors and have limited internal cybersecurity resources.

Why This Warning Matters Beyond the United States

Although CISA’s alert focuses on the US water sector, the underlying exposure is global.

Water utilities, manufacturing plants, smart-city systems, energy companies and other industrial organisations often use similar remote-access models. Many also operate legacy equipment that was designed for reliability and availability rather than modern internet security.

Indian organisations should pay particular attention to PLCs and gateways managed by external system integrators.

A facility may have strong firewalls around its primary IT and OT networks while still overlooking a vendor-installed modem connected directly to a controller. That type of unmanaged connection can bypass normal monitoring, access controls and security review processes.

The larger risk is not limited to one PLC manufacturer or one country. It comes from industrial equipment being reachable through pathways that defenders cannot see.

CISA Calls for Immediate Exposure Checks

CISA is urging water and wastewater operators to identify operational technology connected to the internet, including equipment using cellular communications.

Organisations should verify whether PLCs, human-machine interfaces, gateways and remote-management devices are publicly reachable. Default credentials should be removed, remote access should be restricted and clean configuration backups should be maintained.

Operators also need an accurate inventory of cellular modems and vendor-managed connections.

Simply checking the corporate firewall may not reveal the full exposure. Security teams must work with engineering staff, maintenance teams and external integrators to identify every pathway into the operational environment.

What Remains Unknown

Several important questions have not yet been answered.

Authorities have not disclosed the exact initial-access method used against the Minnesota water systems. It is also unclear whether the affected organisations shared a common equipment vendor, remote-access provider or system integrator.

No attacker has been formally identified, and the number of PLCs successfully compromised remains uncertain.

Those missing details will determine whether the incidents were opportunistic attacks against publicly visible systems or part of a more deliberate campaign targeting specific infrastructure.

Conclusion

The Minnesota attacks show why critical-infrastructure security cannot depend on assumed isolation.

A system is not truly isolated simply because it is separated from the corporate network. Every cellular modem, vendor connection, maintenance gateway and remotely accessible controller creates another potential entry point.

For many utilities, the greatest problem may not be a newly discovered vulnerability. It may be equipment that has been exposed for years without appearing in any official asset inventory.

CISA’s warning should therefore be treated as more than a regional incident update. It is a reminder that attackers are actively searching for weakly protected industrial systems—and that even basic access can disrupt services communities depend on every day.

Leave a Reply

Your email address will not be published. Required fields are marked *