Skip to content

SecurityIndependently confirmed2 publishers2 min readPublished

CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems

The count federal agencies had not published arrives attached to a remediation list that begins with taking inventory, which says more about this campaign than the attribution does.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems
Generated illustration

What happened

  • CISA says it observed malicious activity against more than 100 internet-exposed systems in the water and wastewater sector during July 2026.
  • The agency describes the common route in as programmable logic controllers connected directly to a cellular modem.
  • It is the first time federal agencies have publicly put a number on the recent wave of attacks against water utilities.
  • At least a dozen states appear to be in scope, with Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama confirming they were targeted.

Why it matters

  • constraint Password changes, patching, jump hosts and MFA all presuppose a known asset, so an unlogged modem-attached controller caps how far any of those controls can reach.
  • exposure Utility size is beside the point in this target set: the qualifying condition is a controller answering the public internet, and one forgotten cellular link satisfies it.
  • decision Each remaining internet-facing OT connection now has to be justified as operationally necessary rather than inherited as plumbing that came with the site.
  • precedent A federal figure on the record becomes the yardstick for the next campaign, and utilities without an exposure list will be measured against it.

A programmable logic controller with its own cellular modem answers to a carrier network rather than to anything the IT department fronts, and CISA says that is the path the July activity commonly took [2]. The guidance does not say how those links came to exist. It says only that leaving PLCs and other industrial control systems reachable by cellular modem or the public internet is what enabled the activity against water and wastewater utilities [10].

The order of CISA's advice is the tell. It begins with identifying every internet-accessible system through internal inventories and external scanning, and only then asks which of those exposures operations actually require [8]. Everything that follows, including default password changes, security updates, remote access through gateways or jump hosts, multifactor authentication and traffic monitoring, applies to assets an operator already knows it owns [9]. An agency confident that water utilities held that list would not have led with building it.

The published arithmetic is thin in a specific way. Over 100 systems [1] spread across the at least 12 states the report places in scope [5] averages about eight per state [14]. Six states have confirmed publicly that they were targeted [6], which leaves at least six affected states unnamed in the public record [13]. Both figures are floors, so the per-state number is a shape rather than a measurement, and there is no published breakdown by utility size to tell whether the exposure sits mostly in small unstaffed sites.

Attribution and intent come from the same reporting: activity linked to Iranian threat actors, aimed at disrupting operational technology [3]. No significant disruption resulted [4], which describes an outcome and not the reach. The distinction matters because the remediation CISA is asking for does not depend on the intruders having done anything at all. A controller answering the public internet is the finding. This also arrived on the heels of CISA warnings about Iran-linked attacks on ICS built by Siemens, Schneider Electric and Rockwell Automation [11], so the vendor advisories and the exposure advisory are pointing at the same equipment population from opposite ends.

The last line of the guidance is the one utilities will find most expensive: reassess regularly, because networks and third-party connections keep changing [12]. That reframes internet exposure as a condition that returns whenever an integrator, a contractor or a maintenance visit adds a link, not a defect that a single scan retires. Water systems that treat this as a one-time cleanup will produce a clean inventory and then drift away from it, and the next count will be someone else's number to publish.

What to watch

  • Whether CISA publishes a breakdown of the 100-plus systems by state or by utility size, which would show if the exposure concentrates in small unstaffed sites.
  • Whether the states not yet named disclose, or the count of affected states rises above 12.
  • Whether the Siemens, Schneider Electric and Rockwell advisories turn out to describe the same modem-attached controllers as the exposure guidance.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence74
Adoption34
Hype gap+14
Incentives66
Confidence71
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    CISA said it is aware of over 100 internet-exposed systems in the Water and Wastewater Systems sector targeted by malicious cyber activity in July 2026.

    ReportedSupportedSource: CISA, via SecurityWeek2 sources— create a free account to open themView cited source
  2. [2]

    CISA said the activity came commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.

    ReportedSupportedSource: CISA, via SecurityWeek2 sources— create a free account to open themView cited source
  3. [3]

    The water sector attacks are linked to Iranian threat actors and sought to cause disruption to operational technology systems.

Sources

2 independent publishers whose own reporting we read for this story.

  1. scworld.com

    1 article · August 26, 2026

    Over 100 US water utilities had cyberattacks in July, says CISA
  2. securityweek.com

    1 article · August 26, 2026

    CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories