CISA Reports 100+ Water OT Systems Targeted in July 2026
In July 2026, CISA observed malicious activity targeting over 100 internet-exposed systems in the water and wastewater sector.

Stock photo for illustration only, not from the actual event
- CISA tracked malicious activity on over 100 water OT systems in July 2026
- Most targets involve PLCs connected directly to cellular modems
- No critical operational disruptions have been reported so far
- SOCs are urged to cross-reference multi-source data for asset management
During July 2026, CISA observed malicious activity targeting more than 100 internet-exposed systems within the water and wastewater sector. Typical examples of these exposed setups include PLCs connected directly to cellular modems. Fortunately, no critical operational disruptions have been reported as a result of these incidents.
Security analysts are advised not to perform a high-confidence MITRE ATT&CK mapping based solely on public information, as doing so can lead to inaccurate threat assessments.

Stock photo for illustration only, not from the actual event
Furthermore, maintenance cellular routers and vendor remote access points can easily become asset management blind spots in industrial OT environments worldwide. Security Operations Centers (SOCs) must cross-reference external scan data with records from facility departments, maintenance vendors, and telecommunications providers rather than relying solely on traditional IT asset inventories.
Additional Context: Operational Technology (OT) in critical infrastructure like water treatment plants traditionally prioritizes uptime over security. Direct cellular modem connections to PLCs bypass corporate firewalls for convenience, inadvertently exposing industrial control logic to external attackers scanning the internet.
Mitigating these risks requires bridging the visibility gap between IT inventories and physical plant maintenance logs to establish a comprehensive security posture.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment