Cyber Resilience
← All news
Reported

Feds Issue Warning About Hackers Targeting Water Systems

Our takeCISA counts 100+ internet-exposed water systems targeted in July's Iran-linked attacks. The fix is unglamorous: get PLCs and HMIs off the public internet, kill default passwords, put remote access behind a VPN. Most water utilities are small shops — this guidance is written for you.
Sources (2)
What this means for you — Security leader:CISA reports that over 100 US water systems with internet-exposed OT devices were probed in July by Iran-linked actors. This is a confirmed uptick in scanning and exploitation attempts against poorly segmented ICS environments; the advisory itself is the actionable artifact—download it and map your internet-facing assets today.
What this means for you — Lean IT orgs:If you run a small water or wastewater system, check whether any control devices are reachable from the internet and disconnect them immediately. Use the free CISA guidance to lock down remote access and add basic network separation; most lean teams can do this without outside help.
What this means for you — MSP:Review every water-utility client for internet-exposed OT/ICS assets; the July campaign hit more than 100 systems, so treat any exposed S7, Modbus or BACnet services as urgent. Push segmentation, remove direct internet paths, and enable logging on edge devices across your managed base.
What this means for you — Researcher:CISA's July data shows a sharp rise in probes against internet-exposed water-system OT, attributed to Iran-linked groups. The advisory adds new indicators and reminds operators that basic exposure reduction still stops most of these attempts; the missing piece in coverage is how many of those 100+ systems were actually compromised versus merely scanned.