Nora
Blake

CISA Water Sector PLC Warning: What the Minnesota OT Attacks Reveal

Nora Blake

Jul 31, 2026

7 min read

CISA Water Sector PLC Warning

TL; DR

The CISA water sector PLC warning follows coordinated cyberattacks targeting more than 30 Minnesota water systems that disrupted automated control functions at affected utilities.

  • CISA issued the warning on July 30, 2026, following the Minnesota water utility incidents and broader ongoing threats targeting internet-exposed PLCs.
  • Attackers reportedly changed passwords and altered IP addresses; no actor has been confirmed.
  • The warning follows a separate advisory on Iran-linked PLC targeting, though investigators have not connected the two.

Why Did CISA Issue a Water Sector PLC Warning in July 2026?

CISA published its water sector PLC warning on July 30, warning that internet-exposed programmable logic controllers continue to be actively targeted at water and wastewater utilities. As a result, CISA now urges operators to remove exposed PLCs from the internet immediately. Even mature security programs should recheck their external connections, the agency added.

The alert came days after coordinated cyberattacks affected water utilities across Minnesota. CISA noted that organizations of all sizes should assess their exposure, as internet-accessible PLCs remain attractive targets regardless of the utility’s size.

What Happened in Minnesota on July 26 and 27?

More than 30 Minnesota water systems experienced OT disruptions over two days. Minnesota IT Services confirmed the incident affected automated control functions. Several cities, including Maple Plain, Braham, South St. Paul, and Plymouth, reported interruptions.

However, contingency procedures kept operations running in most cases. Officials said drinking water remained safe throughout the incident. State and federal agencies are still investigating. So far, no formal attribution has been made.

How Did Attackers Lock Operators Out of Their Own PLCs?

CISA described two tactics used against exposed controllers. First, attackers changed operator passwords to lock out legitimate staff. Second, they altered PLC IP addresses to cut off normal network communication.

It also says similar attacks have resulted in boil-water notices and sustained manual operations at affected utilities. Some impacts reported during the Minnesota incidents are consistent with this pattern, although investigators have not publicly linked every operational consequence to the Minnesota attacks.

What is a PLC?

A programmable logic controller (PLC) is an industrial computer used to automate equipment and processes in critical infrastructure such as water treatment facilities, manufacturing plants, and power systems.

What’s the Cellular Modem Blind Spot CISA Flagged?

CISA flagged one exposure path directly: cellular modems installed by operators, vendors, or integrators. These modems often escape routine attack surface inventories because they can create undocumented remote access paths that operate outside an organization’s primary monitored network. As a result, security teams may overlook them during standard external exposure assessments.

A utility might believe its OT environment sits safely behind a firewall. Meanwhile, an undocumented vendor-installed cellular link can expose a controller through an alternate remote access path that the organization’s security team does not routinely monitor. In many cases, this reflects a shadow IT or unauthorized vendor access problem rather than a firewall failure. In other words, maintaining an accurate inventory of remote access paths is just as important as securing the PLCs themselves.

Is the Minnesota Attack Linked to Iran-Backed Hackers?

No actor has been confirmed for the Minnesota attacks. However, the timing raises questions. The incidents followed a July 22 update to CISA advisory AA26-097A. That advisory, first published in April, warned of Iran-linked activity against industrial control systems.

The update expanded the list of targeted vendors. Specifically, it expanded observed targeting beyond Rockwell Automation PLCs to include Schneider Electric and Siemens programmable logic controllers. Investigators have observed activity against Rockwell CompactLogix, Micro850, Schneider Modicon M340, and Siemens S7-1200 controllers.

Iranian-linked groups such as CyberAv3ngers and Handala have targeted small water utilities before. For example, Iranian-linked actors attempted to compromise Israeli water facilities in 2020 by targeting internet-connected industrial control systems. Therefore, these groups fit the general profile for this type of attack. Still, no evidence ties them to Minnesota specifically.

So far, CISA and Minnesota officials have made no such link.

What Does the CISA Water Sector PLC Warning Recommend?

CISA recommends removing internet-exposed PLCs from direct internet access, securing remote access through a VPN or gateway device, replacing default credentials, allowlisting trusted IP addresses where appropriate, and maintaining clean backups of PLC project files to support recovery.

CISA’s July 30 alert lists three immediate steps for OT operators:

  • Disconnect PLCs from the internet. Route remote access through a VPN or gateway device instead.
  • Enable password protection and change default credentials. Do this immediately, not on a routine patch cycle.
  • Allowlist IP addresses. Permit remote connections only from known engineering laptops or approved OT assets.

CISA also recommends keeping a clean backup of each PLC’s image. As a result, utilities can recover quickly if attackers change a password and lock them out. Rockwell Automation MicroLogix 1400 owners can use Rockwell’s dedicated guidance to regain access without original credentials.

Beyond these immediate fixes, CISA asks utilities to review the tactics listed in AA26-097A. This helps teams check for signs of current or historical activity. In short, the goal extends past prevention into detection as well.

Why XDR Is Stronger With UEM
Featured resource

Why XDR Is Stronger With UEM

Learn how combining unified endpoint management with XDR improves endpoint visibility, strengthens security context, and accelerates threat response across enterprise environments.

Download the whitepaper

Where Does Hexnode Fit in Securing the Access Layer Around OT?

Hexnode helps organizations secure managed endpoints, identities, and business applications that administrators use to access enterprise resources.

Hexnode UEM enforces compliance policies on managed engineering laptops and vendor devices used for remote administration, allowing IT teams to verify that managed devices satisfy defined security requirements.

Depending on the identity provider, organizations can use Hexnode device compliance alongside supported identity integrations when implementing conditional access policies.

For identity-layer protection, Hexnode IdP supports multi-factor authentication and role-based access control for supported applications and identity workflows.

MFA helps reduce the risk of unauthorized access through compromised credentials, although it does not prevent attackers from changing PLC credentials after they have already gained access to an exposed controller.

On the endpoint side, Hexnode XDR provides detection, investigation, and response capabilities for supported managed engineering workstations, helping security teams investigate suspicious endpoint activity and respond according to their organization’s security workflows. This applies to the IT-side systems that sit closest to OT, not to the PLCs themselves.

Key takeaway:

Internet-exposed PLCs remain one of the easiest attack paths into water utilities. CISA’s latest guidance focuses on removing direct internet exposure, strengthening authentication, and improving asset visibility.

FAQs

No. State and federal agencies are still investigating, and no formal attribution has been made.

No. Contingency procedures kept operations running, and officials confirmed drinking water remained safe throughout.

No. CISA’s advisory expands confirmed targeting to Rockwell, Schneider Electric, and Siemens PLCs while noting that other branded PLCs may also be susceptible to similar activity if they are internet exposed or otherwise insecurely configured.

Disconnect any internet-exposed PLC first, then route remote access through a VPN or gateway device instead.

What the CISA Water Sector PLC Warning Means Going Forward

The Minnesota incident and CISA’s water sector PLC warning point to the same root problem. Attackers do not need sophisticated exploits when a PLC sits exposed on the open internet. Because of this, exposure management now matters as much as detection.

Utilities should treat CISA’s three immediate recommendations as a starting point rather than a complete solution. Disconnect internet-exposed PLCs, replace default credentials, and strengthen OT security and asset management practices to significantly reduce risk.

However, undocumented access paths like cellular modems will keep resurfacing until inventories improve. IT and OT teams need to coordinate on this rather than treat it as a separate problem.

For enterprise teams supporting water utilities, the access layer offers a practical place to start. Hexnode cannot secure a PLC directly. Instead, it can help organizations secure the managed endpoints and identity workflows that administrators use to access IT systems associated with OT environments.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.