SecurityIndependently confirmed2 publishers2 min readPublished
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems
The count federal agencies had not published arrives attached to a remediation list that begins with taking inventory, which says more about this campaign than the attribution does.
The Watch · Security desk

What happened
- CISA says it observed malicious activity against more than 100 internet-exposed systems in the water and wastewater sector during July 2026.
- The agency describes the common route in as programmable logic controllers connected directly to a cellular modem.
- It is the first time federal agencies have publicly put a number on the recent wave of attacks against water utilities.
- At least a dozen states appear to be in scope, with Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama confirming they were targeted.
Why it matters
- constraint Password changes, patching, jump hosts and MFA all presuppose a known asset, so an unlogged modem-attached controller caps how far any of those controls can reach.
- exposure Utility size is beside the point in this target set: the qualifying condition is a controller answering the public internet, and one forgotten cellular link satisfies it.
- decision Each remaining internet-facing OT connection now has to be justified as operationally necessary rather than inherited as plumbing that came with the site.
- precedent A federal figure on the record becomes the yardstick for the next campaign, and utilities without an exposure list will be measured against it.
A programmable logic controller with its own cellular modem answers to a carrier network rather than to anything the IT department fronts, and CISA says that is the path the July activity commonly took [2]. The guidance does not say how those links came to exist. It says only that leaving PLCs and other industrial control systems reachable by cellular modem or the public internet is what enabled the activity against water and wastewater utilities [10].
The order of CISA's advice is the tell. It begins with identifying every internet-accessible system through internal inventories and external scanning, and only then asks which of those exposures operations actually require [8]. Everything that follows, including default password changes, security updates, remote access through gateways or jump hosts, multifactor authentication and traffic monitoring, applies to assets an operator already knows it owns [9]. An agency confident that water utilities held that list would not have led with building it.
The published arithmetic is thin in a specific way. Over 100 systems [1] spread across the at least 12 states the report places in scope [5] averages about eight per state [14]. Six states have confirmed publicly that they were targeted [6], which leaves at least six affected states unnamed in the public record [13]. Both figures are floors, so the per-state number is a shape rather than a measurement, and there is no published breakdown by utility size to tell whether the exposure sits mostly in small unstaffed sites.
Attribution and intent come from the same reporting: activity linked to Iranian threat actors, aimed at disrupting operational technology [3]. No significant disruption resulted [4], which describes an outcome and not the reach. The distinction matters because the remediation CISA is asking for does not depend on the intruders having done anything at all. A controller answering the public internet is the finding. This also arrived on the heels of CISA warnings about Iran-linked attacks on ICS built by Siemens, Schneider Electric and Rockwell Automation [11], so the vendor advisories and the exposure advisory are pointing at the same equipment population from opposite ends.
The last line of the guidance is the one utilities will find most expensive: reassess regularly, because networks and third-party connections keep changing [12]. That reframes internet exposure as a condition that returns whenever an integrator, a contractor or a maintenance visit adds a link, not a defect that a single scan retires. Water systems that treat this as a one-time cleanup will produce a clean inventory and then drift away from it, and the next count will be someone else's number to publish.
What to watch
- Whether CISA publishes a breakdown of the 100-plus systems by state or by utility size, which would show if the exposure concentrates in small unstaffed sites.
- Whether the states not yet named disclose, or the count of affected states rises above 12.
- Whether the Siemens, Schneider Electric and Rockwell advisories turn out to describe the same modem-attached controllers as the exposure guidance.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence74
- Adoption34
- Hype gap+14
- Incentives66
- Confidence71
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA said it is aware of over 100 internet-exposed systems in the Water and Wastewater Systems sector targeted by malicious cyber activity in July 2026.
ReportedSupportedSource: CISA, via SecurityWeek2 sources— create a free account to open themView cited source - [2]
CISA said the activity came commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.
ReportedSupportedSource: CISA, via SecurityWeek2 sources— create a free account to open themView cited source - [3]
The water sector attacks are linked to Iranian threat actors and sought to cause disruption to operational technology systems.
- [4]
The cyberattacks did not manage to cause any significant disruption.
- [5]
The government has not said how many states were affected, but it appears there were at least 12 states.
- [6]
Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama have confirmed that they were targeted.
- [7]
Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.
- [8]
CISA's updated guidance recommends first identifying all internet-accessible systems via internal inventories and external scanning tools, then determining which exposures are truly necessary for operations and removing or restricting the rest.
- [9]
For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.
- [10]
The guidance highlights the risks of leaving PLCs and other industrial control systems reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems.
- [11]
The guidance came shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric and Rockwell Automation.
- [12]
CISA recommends regular reassessments as networks and third-party connections evolve.
- [13]
At least six of the at least 12 affected states have not been publicly identified.
- [14]
Over 100 targeted systems across at least 12 states works out to roughly eight systems per state if spread evenly, with both inputs being floors rather than exact counts.
Sources
2 independent publishers whose own reporting we read for this story.
- scworld.comOver 100 US water utilities had cyberattacks in July, says CISA
1 article · August 26, 2026
- securityweek.comCISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Water Sector Critical InfrastructureFollow
- Nation-State Threat ActivityFollow
- CISA Guidance and AdvisoriesFollow
- AI-Assisted ExploitationFollow
- OT and ICS SecurityFollow
- Supplier and Supply Chain RiskFollow
- Internet-Exposed Attack SurfaceFollow
Entities
- Merlin GroupFollow
- Denis CalderoneFollow
- CyberAv3ngersFollow
- Matt HartmanFollow
- SCADAview CSXFollow
- Suzu LabsFollow
- UnitronicsFollow
- Danny JenkinsFollow
- TokenCoreFollow
- Kevin SuraceFollow
- SiemensFollow
- Barracuda (ransomware group)Follow
- ThreatLockerFollow
- Federal Bureau of InvestigationFollow
- Schneider ElectricFollow
- CISAFollow
- Micro-CommFollow
- Rockwell AutomationFollow