Validated Containment Architectures are here. →Explore

Executive Summary

In late July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) within the water and wastewater systems sector. These attacks, which began on July 26, 2026, involved hackers altering PLC configurations, changing passwords to lock operators out, and modifying IP addresses to disconnect devices from the internet, leading to operational disruptions. Over 30 community water systems in Minnesota were affected, with some utilities forced to switch to manual operations due to equipment malfunctions.

This incident underscores the escalating cyber threats facing critical infrastructure, particularly in the water sector. The attackers' focus on internet-exposed PLCs highlights the urgent need for enhanced cybersecurity measures to protect operational technology from unauthorized access and potential sabotage.

Why This Matters Now

The recent cyberattacks on U.S. water utilities demonstrate a growing trend of targeting critical infrastructure, emphasizing the immediate need for organizations to secure internet-exposed operational technology to prevent operational disruptions and ensure public safety.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers targeted internet-exposed programmable logic controllers (PLCs), exploiting their accessibility to alter configurations, change passwords, and modify IP addresses, leading to operational disruptions.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit attackers' ability to exploit internet-exposed PLCs, escalate privileges, and move laterally within the network, thereby reducing the operational disruption of water services.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit internet-exposed PLCs would likely be constrained, reducing the risk of unauthorized access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges by altering device configurations would likely be constrained, reducing unauthorized control.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the spread of the attack.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to maintain persistent access to compromised devices would likely be constrained, reducing command and control capabilities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing unauthorized data extraction.

Impact (Mitigations)

The operational disruption of water services would likely be limited, reducing the overall impact of the attack.

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • Water Distribution Management
  • System Monitoring and Control
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Operational data related to water treatment processes and system configurations.

Recommended Actions

  • Remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.
  • Implement Zero Trust Segmentation to enforce least privilege access and prevent lateral movement.
  • Utilize Encrypted Traffic (HPE) to secure data in transit and prevent unauthorized access.
  • Deploy East-West Traffic Security to monitor and control internal network communications.
  • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image