CISA Issues Urgent Alert After 30 Minnesota Water Systems Were Paralyzed — 4,100 Exposed Rockwell PLCs Await the Next Assault
On August 3, 2026, CISA issued an urgent alert after attackers disrupted more than 30 community water systems in Minnesota within 48 hours. The attackers targeted internet-exposed programmable logic controllers (PLCs), changed passwords, and disconnected equipment from the network. Censys counts over 10,000 Rockwell, Siemens, and Schneider PLCs publicly accessible.
Sunday, August 2, 2026. Attackers launched a coordinated wave of attacks against the programmable logic controllers (PLCs) of more than 30 community water systems in Minnesota. By Monday morning, multiple municipalities reported operational disruptions — some were forced to switch to manual operation. By Tuesday, August 4, the Cybersecurity and Infrastructure Security Agency (CISA) published an alert bulletin that leaves no ambiguity: remove your PLCs from the internet immediately.
The incident is exceptionally serious — not because of its technical sophistication, but because it confirms that U.S. critical infrastructure is exposed and exploitable at scale. The attackers did not need a zero-day. They simply scanned the internet, found accessible PLCs, and changed the default password.
What happened
The first alerts date back to Sunday, August 2. The attackers specifically targeted PLCs — the industrial controllers that physically operate pumps, valves, and water treatment systems. Their modus operandi is simple:
- Password changes on the PLC to lock out legitimate operators.
- IP address modifications to disconnect the equipment from the supervision network.
- Configuration parameter alterations causing malfunctions and forcing manual operation.
The Minnesota IT Services (MNIT) agency activated the state’s cybersecurity incident response plan after identifying what it described as “a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems.”
The attack was not limited to small, under-resourced entities. CISA specifies that “organizations of all sizes running water and wastewater systems are being targeted, including some with mature cybersecurity programs.”
The problem: invisible connectivity
CISA’s bulletin highlights a critical blind spot: undocumented cellular modems. These devices, installed by operators, vendors, or system integrators, create direct internet gateways into the OT (operational technology) network without the security team’s knowledge.
Censys, the cybersecurity research company, quantified the exposure in a report published on August 3:
- Over 4,100 Rockwell Automation/Allen-Bradley hosts exposed on the internet.
- Over 4,100 Siemens hosts publicly accessible.
- Over 2,000 Schneider Electric hosts directly connected.
That totals over 10,000 industrial controllers that any attacker with a search engine like Shodan or Censys can discover in seconds.
More concerning: nearly half of the exposed Rockwell devices are reachable via consumer networks — Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink — confirming the rogue cellular modem hypothesis.
Regarding the MicroLogix 1400 controllers specifically mentioned in CISA’s bulletin, Censys notes that a significant proportion are running end-of-sale (EoS) firmware versions, meaning no further patches are available.
What CISA recommends
The U.S. agency does not mince words. Its recommendations are:
- Immediately remove PLCs and all OT equipment from the public internet. No delay, no exceptions.
- If removal is impossible, use a VPN or dedicated gateway for remote access — never direct exposure.
- Change all default passwords and restrict access to an IP address allow-list.
- For Rockwell Automation MicroLogix 1400 owners, follow the vendor’s access recovery guide if passwords have been changed by the attacker.
CISA emphasizes: exposed equipment is vulnerable to defacement, configuration changes, operational disruptions, and — in the worst case — physical damage. A pump that fails to stop at the right moment means a burst pipe.
The chilling table
| Vendor | Exposed Hosts | Primary Access Networks |
|---|---|---|
| Rockwell Automation / Allen-Bradley | 4,100+ | Verizon, AT&T, T-Mobile, Starlink |
| Siemens | 4,100+ | Not detailed |
| Schneider Electric | 2,000+ | Not detailed |
This table represents 10,000 entry points into critical infrastructure. Each row is an attack surface that contradicts the European NIS 2 Directive and the NIST CSF 2.0 framework — both of which require network segmentation and attack surface reduction as prerequisites for any cybersecurity strategy.
Why water systems are the weak link
Water infrastructure suffers from three structural vulnerabilities:
- Low cybersecurity budgets. A municipal water treatment plant does not have a bank’s security budget. PLCs are often installed by integrators who prioritize easy remote access over security.
- Long lifecycle. A PLC installed in 2005 can remain in production for twenty years. Its firmware is no longer maintained, but the equipment continues to operate — and to be exposed.
- Poorly managed IT/OT convergence. The digitization of critical infrastructure has connected OT networks to the internet without OT security teams — where they exist — having the network skills to control this exposure.
Verdict
CISA issued an alert that should have been unnecessary. In 2026, exposing a PLC to the internet without a VPN or strong authentication is not a configuration error — it is structural negligence. The 10,000 controllers counted by Censys are 10,000 incidents waiting to happen.
For critical infrastructure managers: if you do not know how many of your PLCs are reachable from the internet, run the scan today. The attackers already did it on Sunday. The only difference between you and Minnesota is that they went first.
References
- CISA warns of cyberattacks disrupting U.S. water utilities — BleepingComputer, August 3, 2026
- Censys — Internet-exposed PLCs in water and wastewater systems, August 3, 2026
- CISA Alert AA26-xyz — Internet-Exposed OT Assets in Water and Wastewater Systems, August 4, 2026
- Minnesota IT Services — Coordinated cyberattack incident response activation, August 2026