"The fact that more than 100 internet-exposed water systems were targeted in a single month underscores that this is a systemic risk, not a series of isolated incidents." — Matt Hartman, Chief Strategy Officer at Merlin Group.
CISA: more than 100 water systems targeted in July
The Cybersecurity & Infrastructure Security Agency (CISA) reported that, in July, more than 100 water systems that were internet-exposed were targeted with cyberattacks. The agency’s tally follows a recent wave of incidents affecting water and wastewater facilities across the United States. While CISA’s notice says the attacks did not result in significant disruption, the volume of targets has raised broad concern about the security posture of the water sector.
Confirmed incidents spanned at least 12 states; the Aliquippa Water Plant described in detail
Public reporting has linked confirmed attacks to facilities in Alabama, Minnesota, Michigan, New Jersey, South Dakota, and Georgia. The source material states that at least 12 states were impacted overall.
Christopher Hills, Chief Security Strategist at BeyondTrust, described a concrete sequence used by attackers at one plant: threat actors targeted a programmable logic controller (PLC) that was broadcasting Modbus on the public internet (Port 502), used that foothold to pivot to a Human Machine Interface (HMI) with default credentials, installed a lightweight web shell for persistence, defaced the HMI screen, and attempted to shut down pumps and disrupt water pressure. That chain—exposed PLC, default HMI credentials, persistence via web shell—illustrates how simple misconfigurations can provide a path into operational systems.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOperational Technology (OT) weaknesses and basic security hygiene
Multiple security leaders emphasized that many OT systems were never designed for internet exposure or modern cyberthreats. Louis Eichenbaum, Federal CTO at ColorTokens, said OT systems were built for reliability and availability, not to withstand modern nation-state threats, and that many remain internet-facing, poorly segmented, and inadequately monitored.
Christopher Hills stressed foundational practices: default admin passwords should be turned off, managed, or rotated from their shipped state. Matt Hartman echoed CISA’s priorities—identify internet-exposed assets, remove unnecessary exposure, change default credentials, patch supported systems, secure required remote access with controls such as multi‑factor authentication, and continuously monitor for anomalous activity. Those basic steps recur across the expert commentary as immediate, concrete mitigations.
AI, scale, and the changing attack dynamics
Experts in the source material warned that artificial intelligence is changing how adversaries find and exploit weaknesses. Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint, wrote that AI "expands existing attack paths by helping adversaries identify exposed assets, generate exploit code, chain vulnerabilities, and operate at greater speed and scale." John Gallagher, Vice President at Viakoo, added that AI makes live "stress-tests" against critical infrastructure faster and easier to launch, increasing attack frequency.
David Brumley, Chief AI and Science Officer at Bugcrowd, noted attackers prize targets that lack resources, because they are both more vulnerable and slower to respond—sometimes with the immediate motive of political embarrassment, and with the longer-term risk that an attacker gains a foothold inside critical infrastructure.
What this means for technologists, policymakers, and small utilities
- Technologists and security teams: multiple speakers urged removal of direct internet exposure, enforcement of least‑privilege access, monitoring of controller logic, offline backups of configurations, and building incident response plans around physical operations. Louis Eichenbaum and others recommended granular microsegmentation and zero trust architecture to contain breaches and reduce the blast radius.
- Policymakers and regulators: Dana Simberkoff pointed to regulatory shifts such as DORA and NIS2 that move cybersecurity from an organization-centric model to an ecosystem and supply-chain model—relevant as operators increasingly depend on AI systems, cloud providers, and third-party vendors.
- Small and rural utilities: Jim Richberg, Head of Cyber Policy and Global Field CISO at Fortinet, highlighted that small water/wastewater utilities make up 81% of all U.S. public water systems and account for 93% of violations for noncompliance with federal drinking water standards. He argued that setting requirements must be paired with resources—short‑term assistance from state or federal levels and sustainable funding built into utility rates—and noted volunteer efforts such as DEF CON Franklin as additional support.
The incidents CISA flagged did not produce major outages in July, but the expert chorus in this reporting is clear: these are probing attacks and "warning shots" that exploit long‑standing OT weaknesses. The remedies named by multiple specialists are concrete—remove unnecessary internet exposure, eliminate default credentials, patch supported systems, adopt microsegmentation and zero trust, and invest resources into small utilities—but implementing them at scale requires funding and coordination. The immediate question left by the record is whether those operational and funding steps will follow quickly enough to make the next wave of probes less effective.
Source: Security Magazine — 100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month




