Water Under Attack: CISA Warns of Escalating Threats to Utility PLCs Amid Suspected Iran-Linked Incidents
The **Cybersecurity and Infrastructure Security Agency (CISA)** has issued a stark warning regarding a "significant increase" in malicious cyber activity targeting water utilities, specifically their **Programmable Logic Controllers (PLCs)**. This alert comes as investigators probe potential Iran-linked disruptions to water systems in Minnesota and other states, highlighting a critical vulnerability in operational technology infrastructure.
# CISA Sounds Alarm on Water Utility Cyberattacks
**CISA** has reported a sharp rise in cyberattacks aimed at water utilities, emphasizing the urgent need for enhanced security measures. The agency's public alert on Thursday urged facilities to "remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." **PLCs** are integral to industrial processes across various sectors, making their compromise a significant threat.
## Suspected Iran-Linked Activity in Minnesota
Simultaneously, state and federal investigators are reportedly examining whether recent disruptions to water systems in Minnesota earlier this month are connected to Iran. Multiple news outlets, including *The New York Times* and *CBS News*, have reported on these investigations. *Wired* magazine further cited a memo from **WaterISAC**, the industry's cybersecurity information-sharing body, linking the attacks to Iran.
Minnesota's state IT agency confirmed that over 30 community water systems in the state were affected by a coordinated cyberattack starting July 26. **CISA** notes that the threat actor is "targeting water entities of all sizes."
## Attack Vector and Impact
According to **CISA**, the intruders have demonstrated sophisticated tactics, including modifying passwords to lock out operators and disconnecting **PLCs** by altering their IP addresses. This malicious activity has led to serious consequences, such as boil water notices and the necessity for sustained manual operations, underscoring the direct impact on public health and safety.
## Multi-Agency Response
**CISA**, the **FBI**, and the **Environmental Protection Agency (EPA)** are all actively involved in the response to these incidents. The **FBI** has indicated that utility companies in at least seven states have reported similar **PLC**-related incidents to the bureau, suggesting a broader pattern of attacks.
## Broader Implications and Recommendations
While Thursday's **CISA** alert does not explicitly mention Iran, it follows earlier warnings from the agency about Iran-linked malicious activity targeting industrial **OT**. The agency stresses that even organizations with mature cybersecurity processes must validate their external connections.
**CISA** specifically highlighted cellular modems installed by operators, vendors, or system integrators as potential overlooked vulnerabilities, as these may not be documented or included in routine attack surface scans. The agency warned, "OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage."