Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

    July 30, 2026

    Wild Footage Shows Man Blocking Flock Camera With Comically Gigantic Protest Sign

    July 30, 2026

    Q Acoustics 3040c review: floorstanding speakers for entry-level bookshelf money — and they look and sound so much more expensive

    July 30, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
    CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
    Cybersecurity

    CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

    The Tech GuyBy The Tech GuyJuly 30, 2026No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The US Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater system (WWS) operators to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs).

    Advertisement

    The alert is a fresh call to action that comes just days after a coordinated cyberattack disrupted automated controls at dozens of water utilities in Minnesota.

    In an alert published July 30, CISA said it is observing a significant increase in threat actors targeting PLCs in the water and wastewater sector, and urged critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the internet as soon as possible.

    The agency described specific tactics it has seen against exposed controllers: attackers have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses. According to CISA, the attacks have resulted in “boil water notices” and sustained manual operations that closely mirror what several Minnesota utilities reported this week.

    Notably, the alert stressed that the targeting spans water entities of all sizes, and that even organizations with mature cybersecurity programs should validate their external connections. CISA specifically called out cellular modems installed by operators, vendors, or system integrators that may not be documented or captured in routine attack surface scans.

    Minnesota attacks underscore the warning

    CISA’s renewed push follows a coordinated cyberattack that, according to Minnesota IT Services (MNIT), hit OT systems at more than 30 community water systems on July 26 and 27.

    Advertisement. Scroll to continue reading.

    As SecurityWeek reported earlier this week, statements from affected cities, including Maple Plain, Braham, South St. Paul, and Plymouth, indicated that some automated control functions were disrupted, though contingency procedures were activated and water and wastewater operations remained functional in most cases. The affected cities told residents that drinking water remained safe.

    State and federal agencies are investigating, and no formal attribution has been made.

    Ties to the Iranian PLC campaign

    The timing of the Minnesota intrusions is notable. They came shortly after the US government warned critical infrastructure organizations about Iran-linked attacks on industrial control systems made by Siemens, Rockwell Automation, and Schneider Electric.

    That warning came via a July 22 update to advisory AA26-097A, originally published in April, which expanded the list of targeted vendors beyond Rockwell Automation’s Allen-Bradley controllers to include Schneider Electric and Siemens devices, and noted that PLCs from other manufacturers may also be at risk. Investigators have observed activity against Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 series PLCs.

    Iranian threat groups including CyberAv3ngers and Handala fit the profile for attacks on water systems of the kind seen in Minnesota, though investigators have not linked the incidents to any specific actor. CyberAv3ngers has a long track record of targeting small water utilities and municipal facilities, and in 2020 attacks on water facilities in Israel, Iran-linked actors exploited vulnerable cellular routers as an entry point.

    What OT operators should do

    CISA’s core message to the sector is unchanged but increasingly urgent: internet-exposed OT must be secured. The July 30 alert recommends three immediate steps. Operators should disconnect the PLC from the internet, routing any remote access for operational purposes through a VPN or gateway device rather than directly to the controller; enable password protection and change default passwords; and allowlist IP addresses so that remote access is permitted only from known engineering laptops or other critical OT assets.

    CISA also advised that, after disconnecting PLCs, operators ensure they have a known-clean backup of the PLC image in case they are locked out by a modified password. Owners and operators of Rockwell Automation MicroLogix 1400 controllers are pointed to Rockwell’s dedicated guidance for restoring access when the password is unknown.

    Beyond the immediate steps, utilities are encouraged to review the tactics, techniques, and indicators of compromise in AA26-097A for signs of current or historical activity on their networks. For more information, read the full alert from CISA.

    Learn More at the ICS Cybersecurity Conference | Nashville

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Timeless Compliance: Why Better Questions Beat Bigger Frameworks

    July 30, 2026

    Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

    July 30, 2026

    ThreatLocker Raises $190 Million in Series F Funding

    July 30, 2026

    Mate Security Raises $35 Million for Agentic SOC

    July 29, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 29, 2026

    OpenAI’s Rogue AI Ventured Beyond Hugging Face

    July 29, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

    July 30, 2026

    Wild Footage Shows Man Blocking Flock Camera With Comically Gigantic Protest Sign

    July 30, 2026

    Q Acoustics 3040c review: floorstanding speakers for entry-level bookshelf money — and they look and sound so much more expensive

    July 30, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.