100+ Water Systems Targeted in July OT Cyberattacks
CISA's first public count reveals over 100 internet-exposed water systems were targeted in July 2026, with attackers exploiting PLCs connected directly to cellular modems. The advisory gives OT and ICS defenders a clearer picture of the Iran-linked attack surface and the specific misconfigurations enabling it.
Beat this week
Last 7 days · Threat Intelligence
Impact 6.5/10 (+0.8 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 50 percentage points.
This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- CISA's first public count reveals over 100 internet-exposed water systems were targeted in July 2026, with attackers exploiting PLCs connected directly to cellular modems.
- The advisory gives OT and ICS defenders a clearer picture of the Iran-linked attack surface and the specific misconfigurations enabling it.
- SecurityWeek
- TechCrunch
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1CISA observed malicious cyber activity targeting more than 100 internet-exposed systems in the Water and Wastewater Systems Sector during July 2026.
- 2Programmable logic controllers (PLCs) connected directly to cellular modems were the most common exposure vector.
- 3Hackers targeted PLCs from Rockwell Automation, Schneider Electric, and Siemens; CISA said AI tools using public information helped develop scripts for vulnerable Siemens PLCs.
- 4Some intrusions modified PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without operator notification.
- 5At least 12 states were affected; Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama confirmed targeted systems.
- 6No significant disruption to water supplies occurred, but incidents caused outages and disruptions as responders investigated, especially in rural or isolated areas.
Who's Affected
CISA confirmed the number of internet-exposed WWS systems hit in July 2026
Analysis
For OT and ICS security teams, CISA's confirmation that more than 100 water systems were targeted in July 2026 is a wake-up call: internet-exposed PLCs on cellular modems remain a trivially discoverable entry point. The agency's guidance to inventory and shrink the internet attack surface, replace default credentials, and enforce MFA for remote access should be treated as an operational checklist, not just another advisory.
On August 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) publicly confirmed that it observed malicious cyber activity targeting more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector during July 2026. The disclosure, embedded in updated guidance for reducing the internet exposure of operational technology, offers the first federal quantification of the recent wave of attacks against water and wastewater utilities. CISA singled out programmable logic controllers (PLCs) connected directly to cellular modems as the common attack vector. These devices—often deployed with default credentials and without network segmentation—provide a direct bridge from the open internet to physical processes such as pumps, valves, and chemical dosing. The agency is urging organizations to aggressively shrink that attack surface by identifying all internet-accessible systems, eliminating unnecessary exposures, and securing those that must remain reachable.
The affected devices included PLCs from Rockwell Automation, Schneider Electric, and, more recently, Siemens.
The attacks have been linked by senior U.S. officials to Iranian threat actors and described as largely opportunistic, likely reprisal activity tied to U.S.-Israel military actions against Iran. While the intrusions did not cause significant disruption to water or wastewater supplies, they produced outages and operational interruptions as incident responders investigated affected facilities. CISA has previously noted that hackers were able to modify PLCs to disable shutdown processes and alarms, which could create unsafe operating conditions without alerting operators. The affected devices included PLCs from Rockwell Automation, Schneider Electric, and, more recently, Siemens. CISA also reported that the attackers relied in part on AI tools that use public information to develop scripts capable of targeting vulnerable Siemens PLCs. This use of AI-generated exploitation code is a notable escalation: it lowers the skill barrier for targeting industrial control systems and accelerates the speed at which public vulnerabilities can be weaponized.
At least 12 states have been affected, with Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama among those confirming targeted systems. Many of the affected communities are rural or isolated, where a water system outage can ripple across a substantial population and where local cybersecurity resources are often scarce. This geography matters: small utilities rarely maintain dedicated OT security staff, and their reliance on remote cellular connections for operational convenience makes them particularly exposed. CISA's guidance—recommending internal inventories, external scanning, elimination of unneeded internet-facing assets, changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, and enforcing multifactor authentication—is designed to be actionable for such resource-constrained operators. The challenge is not technical sophistication but operational discipline and sustained funding.
What to Watch
For the broader cybersecurity market and regulatory landscape, the confirmation of 100-plus targeted systems is likely to accelerate scrutiny of OT and ICS security in critical infrastructure. Industrial automation vendors may face pressure to strengthen default configurations and provide clearer secure-deployment guidance for PLCs, especially when devices are connected to cellular and cloud-based remote access solutions. Security service providers offering OT asset discovery, passive monitoring, and network segmentation could see increased demand from water utilities driven by both CISA recommendations and future state or federal mandates. Insurers underwriting cyber policies for municipalities may also adjust risk models, given that successful physical-process manipulation can produce significant bodily-injury or service-disruption claims. However, the advisory alone does not create binding requirements; operators must decide whether to treat it as a compliance exercise or an operational security imperative.
Looking ahead, the July 2026 targeting should be read as a warning shot rather than a culminating event. The combination of exposed legacy PLCs, AI-assisted exploit development, and state-aligned threat actors suggests that similar campaigns will likely expand to other critical infrastructure subsectors using the same playbook. The most important immediate step for defenders is to reduce the addressable internet attack surface, as CISA advises, but that is only the first layer. Sustained resilience will require continuous monitoring of OT networks, segmentation between IT and OT environments, real-time threat intelligence sharing, and clear incident response plans for process-altering intrusions. If the current wave remains opportunistic, the risk is manageable; if adversaries apply the same techniques in a coordinated, targeted fashion, the consequences for water systems—and other life-supporting infrastructure—could be far more severe.
Source cluster
Primary reporting
Cite This Page
"100+ Water Systems Targeted in July OT Cyberattacks." Cyber Intelligence Brief, August 26, 2026. https://getcyberbrief.com/story/cisa-100-water-systems-july-cyberattacks-cyber
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |