Attacks on Water System PLCs: CISA Issues Alert After 30 Breaches in Minnesota

CISA alerts of 30 water PLC breaches in Minnesota. Discover how attackers targeted OT devices via cellular modems and how to secure your infrastructure.

Attacks on Water System PLCs: CISA Issues Alert After 30 Breaches in Minnesota
Vulnerabilities

Illustrative image generated with AI

July 31, 2026 – CISA issued an urgent alert following a surge in attacks against programmable logic controllers (PLCs) exposed to the Internet. The hardest-hit area is Minnesota, where more than 30 community water systems were compromised within days. Attackers took control of the devices, changed credentials and IP addresses, and disrupted treatment processes. Several utilities were forced to switch to manual operations. The state's MNIT agency activated its incident response plan.

What Happened in Minnesota

The malicious actions directly targeted PLCs installed at distribution and treatment plants. In many cases, operators were locked out because access passwords had been altered. Elsewhere, network addresses were changed to disconnect the devices from the supervisory system, making remote control impossible. The immediate effect was a shift to manual procedures to keep water service running.

The alert does not report a CVSS score, but rates the severity as high due to the risk of prolonged operational disruptions and physical damage to infrastructure. Some of the affected organizations had cybersecurity programs considered mature, demonstrating that the industrial attack surface remains vastly underestimated.

Targeted Devices

Vulnerable products include Rockwell Automation/Allen‑Bradley PLCs, particularly MicroLogix 1400 units, many running end-of-sale firmware. Siemens and Schneider Electric hosts were also affected, often directly reachable from the public internet. According to Censys, exposed hosts number over 4,100 for Rockwell/Allen‑Bradley, 4,100 for Siemens, and 2,000 for Schneider Electric.

A critical element that emerged from the investigation involves undocumented cellular modems. These are devices connected to carrier networks like Verizon Business, AT&T, T‑Mobile, Comcast, Charter, and Starlink. They escaped corporate inventories and created an invisible channel through which attackers reached the PLCs. These modems represent a blind spot for many operators.

Countermeasures to Adopt Immediately

CISA’s first recommendation is absolute: remove all OT equipment from direct Internet exposure. If that is not possible, remote access must be routed exclusively through VPNs or dedicated gateways. All default credentials must be changed, and access should be restricted using allow-listed IP addresses.

For Rockwell MicroLogix 1400 units with altered passwords, Rockwell Automation has published an official guide for access recovery. It is also essential to inventory and isolate unregistered cellular modems. Censys has released indicators of compromise and threat hunting guidelines that every utility should integrate into its monitoring activities.

Why Even a Mature Program Can Fail

The Minnesota attack confirms that adopting cybersecurity frameworks is not enough without complete visibility of OT assets. Invisible modems, default credentials, and outdated PLCs gave attackers a direct entry path, bypassing all perimeter defenses. Without segmentation and continuous inventory, even a well-prepared organization can find itself handling a real operational emergency.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →