CISA reports more than 100 water systems targeted in July cyber campaign
The US Cybersecurity and Infrastructure Security Agency (CISA) says attackers targeted more than 100 internet-exposed systems used by water and wastewater utilities during July 2026. The disclosure is...
The US Cybersecurity and Infrastructure Security Agency (CISA) says attackers targeted more than 100 internet-exposed systems used by water and wastewater utilities during July 2026. The disclosure is the first time federal officials have publicly quantified the campaign, although they have not attributed it to a specific threat group.
According to CISA, many of the affected systems involved programmable logic controllers (PLCs) connected directly to cellular modems. These devices help control industrial processes, but exposing them directly to the internet can create opportunities for unauthorized access. The activity affected facilities in at least 12 states, with reported incidents involving mostly small or rural utilities in Minnesota, Michigan, Georgia, South Dakota and New Jersey.
Security experts said the number of affected systems points to a broader weakness in the water sector rather than a collection of unrelated incidents. Much water infrastructure relies on operational technology designed for isolated, physical environments, some of which now has remote connectivity that was not part of the original design.
Although more than 100 systems represent a small share of US water utilities, researchers warned that the activity could serve as reconnaissance or preparation for more damaging operations. Separate federal warnings issued in August said attackers had used AI-generated scripts to target internet-accessible Siemens S7 PLCs at water, manufacturing, energy and other critical-infrastructure organizations. Analysts have associated that activity with Iran-linked operators, but the US government has not confirmed the attribution.
CISA urges utilities to remove direct exposure
CISA said utilities should disconnect PLCs from the public internet wherever possible. Organizations that require remote administration should place access behind a virtual private network or secure gateway instead of connecting directly to control devices.
The agency also recommended enabling device authentication, replacing default credentials and restricting remote connections through IP allowlists. Those allowlists should limit access to recognized engineering workstations or other approved operational-technology assets. Multifactor authentication should be used where supported, particularly for remote access infrastructure.
Officials and security specialists emphasized that defensive action should not wait for a final determination about who conducted the campaign. Attackers commonly conceal their origins by routing activity through compromised systems and reusing tools, making attribution difficult and time-consuming.
