Security1 distinct publisher2 min readPublished
CISA says attackers reached programmable logic controllers over the internet during July 2026, changed IP addresses and passwords, and left some utilities unable to monitor their own equipment. No actor has been named.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Two configuration writes cover most of the damage described. Change a controller's IP address and the HMI or historian that polls it stops finding it. Change the password and the engineer who would undo that is locked out of the device [2]. That is the shape of these incidents: utilities lost monitoring and control, and some took operational disruption [3], without confirmed widespread drinking-water contamination [c3b]. None of it needs OT-specific tooling. It needs a reachable controller and credentials that work.
CISA names the delivery route plainly. Directly connecting PLCs to the internet through cellular modems "can create significant security risks," the agency said in its guidance [6]. The fixes it lists are removal and interposition rather than detection: strip unnecessary remote access, and route legitimate access through a secure gateway, firewall, VPN or centrally managed solution instead of pointing it at a PLC, HMI or RTU [7]. Then the housekeeping, which is the same housekeeping as ever: default passwords, security patches, replacement of unsupported equipment, and multifactor authentication where the gear supports it [8].
The headline number needs care. Minnesota confirmed malicious activity involving more than 30 community water systems [5]. Set against a national figure of more than 100, that is at least 30 percent of the count sitting in one state [15]. The units are not the same, since Minnesota is counting community water systems with confirmed activity and CISA is counting internet-exposed systems targeted, so read the share as a rough proportion rather than a statistic. CISA's own caveat runs the same direction: the count measures systems targeted, and does not establish successful breaches, separate compromised utilities, or one actor behind all of it [11].
The line in the guidance that does the most work is the one about third parties. Vendors and contractors install and maintain equipment that faces the internet and never reaches the utility's asset register, so the exposed device is the one the operator would not think to check [9]. CISA's suggested starting point is accordingly discovery, not deployment: inventory internet-facing equipment, remove unnecessary direct connections, and verify systems installed or maintained by vendors and contractors [13]. It also points operators at Shodan, Censys and Shadowserver [14]. For a small provider whose security work competes with operational demands and a thin budget [12], that is the cheap end of the problem, because it is the same public scan data an attacker uses, read first by the utility.
Ranked by verification strength, evidence, and original report placement.
CISA said malicious actors targeted more than 100 internet-exposed systems in the U.S. Water and Wastewater Systems sector during July 2026.
CISA said attackers remotely accessed exposed programmable logic controllers and changed device IP addresses and passwords.
In some cases utilities lost monitoring and control capabilities, and some incidents led to operational disruptions.
There was no confirmed widespread drinking-water contamination.
The campaign affected utilities in at least a dozen states according to reports, including Minnesota, Michigan, Georgia, South Dakota and New Jersey.
Minnesota alone confirmed malicious activity involving more than 30 community water systems.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
A cellular modem hands a PLC an address your firewall never issued1 distinct publisher
security
CISA's water-sector answer is an inventory: 100-plus exposed systems, most of them PLCs1 distinct publisher
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet relaying one agency, with the caveats included
Every quantity that matters here — 100-plus systems, a dozen states, Minnesota's 30-plus — originates with CISA and reaches readers through eSecurity Planet alone; the underlying advisory is quoted for a single sentence and never linked, and the state list is sourced to unnamed 'reports'. What keeps this from being thin is that the outlet argues against its own headline in the body, defining the count as targets rather than breaches and conceding no actor has been identified. Honest framing of weak sourcing is not the same as strong sourcing, but it is worth several points.
Real footprint on the attack side, nothing measured on the fix side
The intrusion side of this is concrete: PLCs reached over the internet, IP addresses and passwords changed, monitoring and control lost at some utilities, more than 30 community water systems confirmed in Minnesota alone. The remediation side is entirely prescriptive. Not one utility in this reporting is on record having completed an inventory, pulled a device off the public internet, or put a gateway in front of a controller, and no state or federal program is described as driving that work. Half the picture is counted; the other half is advice.
The headline holds; 'campaign' is the word doing extra work
eSecurity Planet's headline is defensible — over 100 systems targeted in a single month is what CISA said — and the piece declines the obvious escalations: no nation-state, no contamination scare, an explicit note that no widespread drinking-water contamination was confirmed. The one overreach is vocabulary. Calling this a 'campaign' four times implies coordination that the same article says has not been established, and the concentrated Minnesota figure sits next to the national one closely enough to invite arithmetic that the differing units do not support.
An agency measured by whether anyone listens, an outlet read by buyers
CISA supplies the numbers and the remedy in the same breath, and an agency's warning succeeds only if utilities act on it — that shapes emphasis toward urgency even when attribution is empty. eSecurity Planet's readership is security practitioners and the people who buy for them, and the piece closes by naming three commercial exposure-discovery services as the first step. Offsetting all that: no vendor is quoted, no product is positioned as the answer, and the tools named are the cheap generic ones rather than a sponsor's platform.
Nothing contradicts it, and nothing confirms it either
The account is internally consistent, technically plausible and openly hedged where it should be, which is why this lands mid-scale rather than low. But a single publisher relaying a single agency leaves no way to test the dozen-state claim, no utility or vendor voice, and no read on what has changed since July. Confidence would move on a primary advisory or one state regulator confirming its own numbers.