Key Takeaways

  • Threat actors targeted over 100 internet-exposed water-sector systems in July 2026, including PLCs that control physical processes.
  • Incidents across at least a dozen states caused operational disruption, boil-water notices, and temporary manual operations, but no confirmed drinking-water contamination.
  • Utilities face pressure to remove direct internet exposure, segment operational technology, improve monitoring, and prepare for manual recovery.

The scale of the campaign is becoming clearer. CISA observed cyberattacks against over 100 internet-exposed systems in the U.S. Water and Wastewater Systems sector during July 2026. The activity spanned at least a dozen states and largely focused on programmable logic controllers, or PLCs, that were reachable directly from the internet.

That distinction matters. PLCs do not simply store customer records or run office applications. They control pumps, valves, alarms, chemical processes, and other physical equipment. CISA previously reported that attackers had modified some affected PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without alerting operators. Even where water quality remains unaffected, interference can force facilities into manual operation while responders investigate.

The campaign followed coordinated incidents affecting more than 30 community water systems in Minnesota, as well as systems in Michigan. According to a Cloud Security Alliance research note, the Minnesota activity disrupted operational technology across numerous utilities. The broader wave resulted in boil-water notices and temporary manual operations, although authorities had identified no confirmed drinking-water contamination as of August 26.

An attacker may not need a sophisticated, custom-built industrial implant when a controller is publicly reachable and poorly protected. The recent activity targeted equipment from Rockwell, Schneider Electric, and Siemens. CISA also said threat actors were using AI tools and public information to help create scripts capable of targeting vulnerable Siemens PLCs. That can lower the effort required to identify exposed equipment and automate opportunistic attacks.

Attribution remains less settled. Reports citing senior American officials say U.S. intelligence considers Iran likely responsible for much of the activity, potentially in response to the U.S. and Israel-led war against Iran. Officials have stopped short of a concrete attribution, however. An April 2026 joint advisory from EPA, FBI, CISA and NSA separately warned that Iranian-affiliated actors were exploiting commonly used operational technology in drinking-water and wastewater environments.

Why are relatively small water providers attractive targets? Many serve rural or geographically isolated communities, operate aging equipment, and have limited cybersecurity staffing. They may also depend on remote access for maintenance. Those operational realities can leave internet-facing controllers, default credentials, unsupported devices, and loosely separated business and plant networks in place longer than security teams would prefer.

The exposure is not confined to the July campaign. EPA’s Office of Inspector General found in 2024 that 97 large drinking-water systems serving 26.6 million people had critical or high-risk cyber vulnerabilities. Another 211 systems had medium or low-risk issues. A WaterISAC summary of GAO’s 2026 work also highlighted persistent weaknesses associated with aging infrastructure, constrained resources, and largely voluntary controls across roughly 170,000 U.S. water and wastewater systems.

For utility leaders, the immediate priorities are fairly concrete: identify every internet-exposed operational asset, remove direct PLC access where feasible, enforce stronger authentication for remote connections, and separate information-technology networks from operational systems. Passive monitoring can also help detect unauthorized PLC changes and unusual traffic without disrupting sensitive plant equipment. Dragos, Nozomi Networks, and Tenable are among the vendors offering industrial monitoring and threat-detection capabilities for this purpose.

Technology alone will not resolve the resilience gap. Utilities can also test manual operating procedures, maintain offline configuration backups, document safe controller states, and clarify who can authorize shutdowns during an incident. Procurement teams may need to treat remote-access design and security support as lifecycle requirements rather than optional add-ons. The July attacks showed that even limited intrusions can trigger outages, public warnings, and expensive response work. For water operators, reducing exposure now can narrow the path from an opportunistic scan to a physical disruption.