CISA tells water utilities: pull PLCs off the internet now
The alert marks CISA's sharpest operational directive yet for the water sector, not monitor, not patch, but deprovision immediately.
TL;DR
CISA issued a public alert Thursday warning of a "significant increase" in coordinated attacks on water utility programmable logic controllers across at least seven states, with Minnesota reporting more than 30 systems affected since July 26. Attackers are modifying PLC passwords and IP addresses, locking out operators, triggering boil water notices, and forcing sustained manual operations. CISA's direction is unambiguous: remove publicly exposed PLCs and OT from the internet as soon as possible, and validate undocumented cellular modem connections that may not appear in routine scans. The alert does not name Iran, though concurrent investigations and an earlier April advisory tied similar OT targeting to Iranian-affiliated actors.

Thursday's alert is the first time CISA has told water utilities to pull operational technology off the internet immediately, no qualifiers, no phased roadmap. "Remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." That's the lede, and it's sharper than anything the agency has put out for the water sector before.
The attack pattern is simple and effective: intruders find internet-facing PLCs (often through Shodan or similar scans) then modify passwords and IP addresses to sever the controller from the operator. The result is a water system running blind, operators locked out, manual intervention required. CISA says the campaign has already produced boil water notices and sustained manual operations. Minnesota's state IT agency confirmed more than 30 community water systems hit starting July 26; the FBI says utilities in at least seven states have reported PLC incidents.
The attribution gap
Neither CISA's alert nor the FBI's statement names Iran. But the timeline is suggestive. In April, CISA and the FBI issued an advisory attributing PLC-targeting OT attacks to Iranian-affiliated actors. That advisory was updated July 22 to expand manufacturer scope to Schneider Electric and Siemens. Thursday's alert references "activity targeting PLCs" without attribution, but concurrent reporting (including a WaterISAC memo obtained by Wired) ties the Minnesota incidents to Iran. The open question is whether the seven-state campaign is the same actor set or a copycat leveraging the same exposed-attack-surface playbook.
What makes this harder than it sounds for the utilities on the receiving end: CISA flagged that attackers are exploiting cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. So even a utility that thinks it has its external connections mapped may be wrong.
For the practitioner Monday
If you run OT for a water or wastewater utility, the action item isn't "assess exposure." CISA already did that for you. The instruction is deprovisioning. Find every PLC with a public IP or accessible via an undocumented cellular modem and cut the connection. Then validate that nothing came back online through a vendor's remote-access backdoor or an integrator's forgotten LTE dongle. The alert says "as soon as possible." It means hours, not weeks.
Published ·Updated ·Deep Fathom