The Cybersecurity and Infrastructure Security Agency (CISA) says a coordinated cyber attack, unofficially attributed to Iranian hackers, affected over 100 water systems in July 2026. The agency specifically linked the attacks to internet-exposed programmable logic controllers used in field operations, typically connected via cellular modems.
“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” the agency noted.
CISA also found that many critical infrastructure organizations unknowingly left PLCs exposed to the internet, making them vulnerable to exploitation. It also raised awareness of the risk that threat actors could exploit other security flaws, including device misconfigurations, default credentials, and outdated software, to gain initial access.
Cyber attack affected over 100 water systems
Although the cyber attack likely affected many states, nearly a dozen, including Michigan, Minnesota, South Dakota, Georgia, New Jersey, and Alabama, have confirmed the incident. In Minnesota alone, over 30 community water systems were targeted.
Nevertheless, the coordinated cyber attack posed no risk to water safety, such as contamination, though operational degradation occurred in some utilities, including pressure loss and flooding.
CISA says it observed the malicious cyber actors employing various tactics, including modifying passwords to lock out operators and changing IP addresses to disconnect the devices. These cyber attack forced some water systems to switch to manual operations to reduce disruption.
Additionally, CISA anticipates that malicious cyber actors could employ other tactics, including defacement, configuration changes, and even physical damage. Previous attacks on other critical infrastructure, such as automatic gauge readers at gas stations, disabled shutdown processes and alarms, preventing operators from being notified of critical events, resulting in “unsafe conditions.”
The agency also found that the attackers were indiscriminate and could target water systems of all sizes, including those with mature cybersecurity programs.
“The ongoing targeting and successful exploitation of water systems is shining a light on a longstanding problem in the security of (especially) the small water/wastewater utilities that comprise 81% of all US public water systems. These utilities account for 93% of violations for noncompliance with federal drinking water standards,” said Jim Richberg, Head of Cyber Policy and Global Field CISO at Fortinet.
CISA also noted that most attacks are opportunistic, with threat actors using various scanning tools to identify vulnerable water systems. They also frequently use AI tools to generate malicious scripts for initial access.
So far, authorities have not attributed the cyber attack to any threat group, though some industry experts and senior officials have suggested Iranian involvement. The attacks were also likely in preparation for a larger campaign by Iranian hackers.
“Malicious hackers and nation-state adversaries will often run live stress-tests against operators of critical infrastructure to test their defenses. AI makes these attacks faster and easier to launch, increasing the frequency of such attacks,” said John Gallagher, Vice President at Viakoo.
CISA guidelines on protecting water systems
The cyber attack prompted CISA to direct water systems to implement various security measures, including taking inventory of internet-exposed industrial control systems and disconnecting them from the internet to reduce the attack surface.
“CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” the agency stated.
Other recommendations included using secure VPNs and gateways when remote access was necessary, changing default passwords, applying security updates, enabling multi-factor authentication (MFA), and monitoring and allowlisting internet traffic to allow only recognized devices and IP addresses.
“Recent incidents have exposed risks that have existed across critical infrastructure for years: internet-facing controllers, weak segmentation, legacy systems, third-party access, and limited visibility into operational technology,” said Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint. “Recent attacks on U.S. water systems have exploited those same conditions, sometimes forcing operators to switch to manual processes.”
Critical infrastructure owners, operators, and integrators should also maintain configuration backups in the event they were locked out. Using software and hardware keys to switches should also prevent malicious actors from making configuration changes or altering firmware or logic.
“By following the guidance below, organizations can proactively identify internet exposures, remove those that are unnecessary, and secure those that are necessary, strengthening their cybersecurity posture,” CISA noted.
CISA had previously warned about Iranian hackers targeting more devices, including those manufactured by Rockwell Automation, Siemens, and Schneider Electric. Those attacks increasingly leveraged AI tools to generate malicious scripts and identify vulnerabilities. The attackers also dropped modified project files, allowing them to carry out similar attacks.

