US Discloses Over 100 Water Systems Hit in July Cyberattack Blitz

CISA warns of systemic vulnerability as suspected Iranian hackers target internet-exposed programmable logic controllers at small, rural utilities

edit
By LineZotpaper
Published
Read Time3 min
The U.S. government has disclosed that malicious cyber activity struck more than 100 internet-exposed water and wastewater systems in July 2026, marking the first time federal officials have quantified the scope of a campaign widely attributed to Iranian-backed hackers. The Cybersecurity and Infrastructure Security Agency (CISA) linked the intrusions to programmable logic controllers (PLCs) connected directly to the internet, a configuration that creates significant security risks.

In an advisory issued last week, CISA reported that the July attacks targeted systems across at least a dozen states, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey, predominantly at small, rural utilities. While federal and state authorities have not publicly identified all affected states, the agency stressed that connecting PLCs—industrial control devices that manage pumps, valves, and other equipment—directly to cellular modems leaves critical infrastructure dangerously exposed.

“This is very serious,” said Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber. “More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets.”

The United States has not formally attributed the attacks to any specific group, though third-party analysts widely suspect Iranian involvement. The lack of official attribution, Hartman explained, is due to the difficulty of tracing cyber operations. “Adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems,” he said. “CISA has done the most important thing: quickly getting actionable information into the hands of water-sector operators so they can defend their systems.”

The July campaign represents about 0.5 percent of the roughly 16,000 water utilities in the U.S., but cybersecurity experts warn the real danger lies in what the intrusions portend. “These are test runs for a larger-scale attack,” said John Gallagher, vice president at Viakoo, an OT and IoT cybersecurity provider. The concern is amplified by a separate warning issued last week by five federal agencies, which noted that attackers are now using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, and energy facilities.

Cynthia Kaiser, senior vice president at Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, linked the latest activity to the earlier campaign. “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” she said. “Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society.”

In response, CISA recommended that water utilities disconnect PLCs from the internet, enforce password protection and multi-factor authentication, and restrict remote access to authorized engineering devices via VPNs or gateway systems. The agency urged owner-operators to change default passwords and implement allowlists for IP addresses.

The disclosures come amid rising concerns over the security of U.S. critical infrastructure, much of which relies on operational technology designed decades ago for closed, physical environments. “It was never built with the assumption that it would be reachable from the open internet,” Hartman noted.

§

Analysis

Why This Matters

  • The attacks directly threaten public health and safety: compromised water systems could lead to contamination, service disruptions, or loss of operational control.
  • The sheer scale—over 100 systems in one month—reveals a systemic vulnerability in the nation's water infrastructure, particularly at small, rural utilities with limited cybersecurity resources.
  • These intrusions are likely probes for larger, more destructive attacks, raising the stakes for federal investment in hardening critical infrastructure.

Background

Water and wastewater systems have long been considered a soft target for cyberattacks. In 2021, a hacker attempted to poison the water supply in Oldsmar, Florida, by remotely altering chemical levels. In 2023, Iranian-linked actors compromised a Pennsylvania water utility, exploiting a Unitronics PLC left exposed online. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly warned about the risks of internet-connected industrial control systems.

The July 2026 campaign marks a significant escalation in both frequency and coordination. CISA’s advisory is the first to provide a concrete figure of affected systems, suggesting improved detection but also a widening attack surface. The involvement of AI-generated exploitation scripts in subsequent attacks indicates adversaries are rapidly advancing their capabilities.

Key Perspectives

CISA and federal agencies: Their priority is to get actionable guidance to operators while avoiding premature attribution that could undermine legal or diplomatic responses. They emphasize that immediate security fixes—disconnecting PLCs, enforcing access controls—are more critical than identifying perpetrators. Water utilities (especially small, rural): Many lack dedicated cybersecurity staff and budgets. They face a tension between operational efficiency (remote monitoring) and security. The attacks highlight the need for federal assistance and sector-specific resources. Critics/Skeptics: Some cybersecurity experts argue that the lack of formal attribution and the relatively low percentage of affected utilities (0.5%) may downplay the threat. Others caution that overreaction could lead to costly, clumsy regulations that burden small utilities without addressing root causes. There is also concern that the AI-generated scripts indicate a growing automation of attacks, exceeding the defense capabilities of many operators.

What to Watch

  • Actions by CISA and other federal agencies to mandate security standards for water-sector PLCs.
  • Any formal attribution by the U.S. government, which could trigger sanctions or retaliatory cyber operations.
  • Reports of follow-on attacks, especially those using AI-generated exploits, targeting other critical infrastructure sectors such as energy and manufacturing.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.