CISA: Attacks on 100+ US Water Systems via Internet-Exposed PLCs
In July 2026, CISA reported malicious activity against over 100 internet-connected water and wastewater systems in the US. Attackers reached PLCs via cellular modems using default passwords, changed admin passwords and IP addresses, blocking operators.
- Over 100 systems affected in at least 12 US states
- Attacks via PLCs directly connected to cellular modems
- Default or weak passwords used, no complex exploits
- Consequences: loss of remote control, pressure drops, local flooding
Read next
Security