CISA Says Over 100 U.S. Water Systems Were Targeted in July

Troubled waters.
Lily Morris
Contributing Writer
Dark Ocean Surface With Red Warning Lights
bawan - stock.adobe.com

More than 100 internet-exposed systems in the U.S. water and wastewater sector were targeted by hackers in July 2026, according to CISA.

The campaign focused on programmable logic controllers (PLCs), the computers that operate physical equipment inside water facilities. Attacks reached utilities across at least 12 states, providing the clearest measure yet of the campaign’s reach.

Water supplies have seen limited disruption, though investigations have caused some outages.

The greater concern is the access attackers gained. Previous intrusions allowed hackers to modify PLCs and disable shutdown processes or alarms, potentially creating unsafe conditions without warning operators.

U.S. intelligence reportedly considers Iran the likely source, though officials have yet to make a definitive attribution.

Why It Matters: The campaign exposes a growing security and resilience challenge for organizations that depend on operational technology. Internet-connected industrial systems can extend enterprise risk into physical operations, while AI may lower the effort required to exploit known vulnerabilities, raising the stakes for asset visibility, access controls, and incident preparedness.

  • Internet Exposure Is Expanding the Attack Surface: CISA observed malicious activity against more than 100 internet-exposed water and wastewater systems in July, often involving PLCs connected directly to cellular modems. Reports indicate utilities in at least 12 states were targeted, including facilities serving rural or isolated communities where outages can affect large areas.
  • PLC Compromises Can Reach Physical Operations: The targeted controllers operate equipment and processes inside water facilities, giving attackers a potential path from network access to service disruption and safety systems. CISA previously reported intruders modifying affected PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without notifying operators. Water supplies have experienced limited disruption so far, though some incidents have caused outages while responders investigated compromised systems.
  • AI May Reduce the Work Required to Exploit Industrial Systems: CISA says attackers have used AI tools with publicly available information to develop scripts targeting vulnerable Siemens PLCs. Public documentation and vulnerability research can already provide useful intelligence about industrial equipment. AI can make it easier to process that material and translate it into attack tooling, potentially lowering the expertise and time required to pursue exposed operational technology.
  • CISA Is Calling for Tighter Control of Internet-Connected OT: The agency recommends identifying externally accessible systems through internal inventories and external scanning, then removing connections that are not operationally required. Systems that must remain reachable should receive security updates, stronger credentials and multifactor authentication, with remote access routed through secure gateways or jump hosts. CISA also recommends traffic monitoring and recurring exposure reviews as networks and third-party connections change.
  • The Campaign Adds a Geopolitical Layer to Infrastructure Risk: U.S. intelligence reportedly considers Iran the likely source of the opportunistic attacks, potentially in response to the U.S. and Israel-led war against Iran, though officials have not issued a definitive attribution. The incidents follow U.S. warnings about China-linked hackers preparing destructive capabilities inside American critical infrastructure and Russian activity against European water and energy systems. That history makes resilience and recovery planning relevant alongside efforts to prevent initial access.

Go Deeper -> CISA confirms hackers targeted over 100 US water systems during July – TechCrunch

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks – SecurityWeek

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters