CISA has warned utilities to remove internet-exposed Programmable Logic Controllers (PLCs) following coordinated cyberattacks on over 30 Minnesota water systems from July 26-27, 2026. The attacks temporarily knocked out controls, particularly affecting Braham's water plant. Although no attackers have been officially named, activity patterns suggest involvement from the Iranian group CyberAv3ngers.
As a response, CISA advises against using publicly accessible PLCs due to increased targeting in the Water and Wastewater Systems sector. The agency urges utilities to implement security measures, including network isolation, changing default passwords, and validation of external connections to protect against potential disruptions.