Skip to main content
Emerging ThreatsMalware & Ransomware

US Cyber Defenses Targeted in 100-Plus Water System Attacks

Water treatment plant control room with industrial systems and equipment.

"In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem," the agency said.

CISA’s tally: more than 100 internet-exposed water systems hit in July

For the first time, America’s lead cyber‑defense agency, CISA, put a number on a recent assault: more than 100 water and wastewater systems were targeted during July 2026. CISA said the attacks commonly involved programmable logic controllers (PLCs) that were connected directly to a cellular modem and warned that connecting PLCs directly to the internet “can create significant security risks.”

Technique and tooling: PLC exposure, cellular modems, and AI-generated exploitation scripts

CISA described a recurring attack pattern that centered on internet‑exposed operational technology. Separately, five US federal agencies warned that attackers are using AI‑generated exploitation scripts to break into internet‑exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities. Cynthia Kaiser, senior vice president at Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, told The Register that “this appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs.” Kaiser added that “Iran‑affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society.”

Geography and targets: small, rural utilities across at least a dozen states

Federal and state officials have not publicly identified all affected jurisdictions, but third‑party analysts said the incidents struck mostly small, rural utilities across at least a dozen states. The Register reported confirmed incidents in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. Experts emphasized the scale over any single compromise: Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber, told The Register, “This is very serious. What stands out isn't any single incident. It's the scale.”

Attribution and response: caution from the federal side, urgency from practitioners

Third‑party analysts have largely blamed Iran for the intrusions, but the federal government has not attributed the campaign to a specific actor. Hartman told The Register that “Attribution in cyber incidents is inherently difficult and often takes time. Adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems, so the government needs to be diligent before publicly assigning responsibility.” He also praised the immediate defensive posture: “In this case, CISA has done the most important thing: quickly getting actionable information into the hands of water‑sector operators so they can defend their systems.”

What this means for water operators, federal agencies, and security vendors

  • Water operators: CISA’s advisory urged practical, immediate changes—disconnect PLCs from the internet, ensure any remote access goes through a VPN or a gateway device rather than connecting directly to the PLC, enable password protection (the advisory suggested multi‑factor authentication), change default passwords, and ensure allowlist IPs only permit remote access from known engineering laptops or other critical OT assets.
  • Federal agencies and incident responders: The federal warning about AI‑generated exploitation scripts for Siemens S7 Series PLCs widens the remit for coordinated response and intelligence sharing, reinforcing CISA’s emphasis on rapidly distributing actionable indicators to owner‑operators.
  • Security vendors and OT specialists: John Gallagher, vice president at Viakoo, told The Register that while the 100 systems represent “a small fraction - only about 0.5 percent - of water utilities in the US,” the “real threat is that these are test runs for a larger‑scale attack.” Vendors will watch for shifts in tooling—especially AI‑assisted exploit code—and for repeat patterns that could be blocked or mitigated at scale.

Experts and agencies landed on shared, concrete steps: reduce internet exposure of PLCs, centralize and harden remote access, replace default credentials, and restrict remote connections to known engineering assets. Those recommendations are not subtle; they are CISA’s immediate playbook for the sector.

Whether small, rural utilities—many of which operate with limited IT and OT staff—can apply those mitigations quickly will determine whether July’s breaches are isolated probes or the prelude to more destructive operations. CISA has prioritized getting corrective guidance into the field; the next measure of success will be whether owners and operators act on it before adversaries iterate further.

Original story — The Register