CISA Confirms Hackers Targeted Over 100 U.S. Water Systems in July 2026

CISA has confirmed that cyberattacks struck more than 100 internet-exposed systems across the U.S. water and wastewater sector during July 2026, the agency's most expansive accounting of a campaign that has drawn urgent federal response across multiple states and agencies. The attacks largely targeted programmable logic controllers, or PLCs — the industrial devices that govern physical machinery across water providers, energy systems, and other critical infrastructure. (TechCrunch, 2026-08-26)
The affected PLCs were manufactured by Rockwell, Schneider Electric, and Siemens. CISA had previously reported that the intrusions allowed attackers to modify affected PLCs in ways that disabled shutdown processes and alarms, potentially creating unsafe operating conditions without alerting the operators responsible for those systems. In at least some cases, the attackers used AI tools that absorb publicly available information to develop scripts capable of targeting vulnerable Siemens PLCs. (TechCrunch, 2026-08-26)
The intrusions had little effect on actual water or wastewater supplies delivered to local communities. They did, however, cause outages and disruption as incident responders investigated the breaches and worked to secure affected systems. Many of the communities hit are in rural or isolated areas, where water utilities typically operate with smaller staffs and leaner cybersecurity budgets than their counterparts in metropolitan districts. (TechCrunch, 2026-08-26)
Affected providers span Michigan, Minnesota, and at least five other states. The FBI issued an alert on July 30, 2026 titled "Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers Causing Operational Disruptions," stating that since July 27, 2026, water and wastewater utility companies in at least seven states had reported incidents to the Bureau. (FBI, 2026-07-30)
CISA's response escalated across the summer. On July 22, 2026, the agency published cybersecurity advisory AA26-097A, stating that Iranian-affiliated cyber actors had exploited PLCs and compromised at least 75 devices, including U.S.-based Unitronics PLC devices with an HMI — a human-machine interface, the screen or panel operators use to interact with the controller — used across multiple critical sectors. That same day, CISA, the FBI, the EPA, and other U.S. government partners updated a joint warning that Iranian-affiliated threat actors are targeting internet-connected operational technology. The advisory noted that the actors used several foreign-based IP addresses to access internet-facing systems. (CISA, 2026-07-22) (CISA, 2026-07-22)
Following the attacks in Minnesota, CISA urged water utilities to take exposed systems offline entirely. Nextgov reported that some U.S. officials believe an Iran-aligned cyber group is behind the campaign, citing two people familiar with the matter. (Nextgov, 2026-07-31)
Senior American officials say U.S. intelligence assesses that Iran is likely behind the largely opportunistic attacks, likely in response to the U.S. and Israel-led war against Iran, though officials have fallen short of concrete attribution. The campaign's opportunistic character means it was not a precisely planned operation against pre-selected targets; rather, the attackers appear to have scanned for internet-exposed PLCs and exploited whichever ones they could reach. (TechCrunch, 2026-08-26)
This is not the first time Iranian-affiliated actors have been linked to PLC exploitation in the U.S. water sector. CISA's advisory AA23-335A, updated as recently as December 2024, documented IRGC-affiliated cyber actors exploiting PLCs across multiple sectors including U.S. water and wastewater facilities. And in 2026, CISA released an updated advisory titled "Iranian-Affiliated Cyber Actors," highlighting continued targeting that includes the water and wastewater sector. (CISA, 2024-12-18) (CISA)
The pattern is familiar to anyone who has tracked operational technology security over the past decade. Internet-facing PLCs with default or weak credentials have been a known exposure since at least the mid-2010s, when researchers began routinely demonstrating remote access to Schneider and Siemens controllers through Shodan, a search engine that indexes internet-connected devices. What has changed is the addition of AI-assisted script development, which lowers the barrier to producing working exploit code for specific PLC families, and the geopolitical context, which provides motivation for a state-affiliated actor to cast a wide net rather than carefully select high-value targets.
The operational impact here matters less than the trajectory. No community lost water service. But the ability to disable shutdown processes and alarms on industrial controllers, even opportunistically, means the attackers reached a level of access where physical consequences were possible, not merely theoretical. For rural utilities that may lack a dedicated OT security practitioner on staff, the gap between a successful PLC compromise and a safety incident is narrow and depends heavily on the presence of mechanical failsafes downstream of the digital control layer.
CISA's recommendation that utilities take exposed systems offline is straightforward remediation guidance, but it raises a structural problem. Many of these PLCs were designed to be accessed remotely for legitimate operational reasons, often by third-party integrators or vendors providing maintenance support. Taking them offline removes the attack surface but also removes the remote management capability that smaller utilities may depend on. The longer-term fix — segmenting OT networks from internet exposure and implementing proper authentication on PLC interfaces — requires capital expenditure and expertise that rural water districts are not uniformly equipped to provide.
The federal coordination across CISA, FBI, and EPA reflects an understanding that the water sector's fragmentation, with tens of thousands of mostly small utilities operating independently, makes it structurally vulnerable to exactly this kind of broad, opportunistic scanning campaign. Whether that coordination translates into durable funding for OT security improvements at the local level is a separate question, and one that previous federal water-sector cybersecurity initiatives have not fully answered.
The broader context here is that AI-assisted exploit development has moved from a research demonstration to a factor in active, state-attributed campaigns against U.S. infrastructure. That is a meaningful threshold, even if the immediate operational damage in this case was contained.


