In a sobering disclosure that underscores the vulnerability of the nation’s critical infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA) has officially confirmed that over 100 internet-exposed water and wastewater systems were targeted in a sophisticated campaign of malicious cyber activity throughout July 2026. This revelation marks the first time federal authorities have provided a concrete numerical scope to the recent wave of digital incursions that have plagued utility providers across the United States.
The attacks, which federal officials have linked to Iranian-affiliated threat actors, primarily exploited Programmable Logic Controllers (PLCs)—the industrial computers that manage physical processes like water pressure, chemical dosing, and flow regulation. By targeting devices connected directly to cellular modems, attackers bypassed traditional perimeter defenses, exposing a glaring weakness in the digital architecture of America’s essential services.
The Anatomy of the Threat: A Chronology of Escalation
The incidents observed in July 2026 represent the culmination of a months-long pattern of aggressive reconnaissance and exploitation targeting the Water and Wastewater Systems (WWS) sector. While the July wave is the most quantified to date, it follows a steady drumbeat of activity that has forced federal regulators to scramble.
Early Warning Signs and Initial Probes
The escalation began in early 2026, when security researchers and intelligence agencies noted an uptick in scanning activity targeting Industrial Control Systems (ICS). Threat actors were specifically searching for devices—often made by manufacturers such as Siemens, Schneider Electric, and Rockwell Automation—that were reachable via the public internet. By late spring, CISA had begun issuing urgent warnings, noting that hackers were using both automated scripts and, increasingly, artificial intelligence to probe for vulnerabilities in these OT (Operational Technology) environments.
The July 2026 Surge
Throughout July, the frequency and precision of these attacks intensified. According to CISA’s recent advisory, the attackers focused on the “low-hanging fruit” of the WWS sector: systems that lacked robust authentication or were inadvertently exposed through cellular modems. While the adversaries did not achieve widespread service disruption, the intent was clear—to gain unauthorized access to the heartbeat of water utilities.
Geographic Spread and State-Level Impacts
While federal agencies have remained tight-lipped regarding the total count of affected states, investigative reporting and state-level disclosures have confirmed that the campaign was broad in scope. At least 12 states have been identified as targets, with public confirmations coming from agencies in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. The disparate nature of these targets suggests that the attackers were not focusing on a single geographical region, but rather casting a wide net to identify utilities with the weakest security posture.
Supporting Data: Why Water Systems are Vulnerable
The targeting of the WWS sector is not accidental; it is a strategic choice born of the sector’s unique technical challenges. Unlike the IT networks of a corporate office, which are often fortified with modern cybersecurity stacks, OT environments are frequently composed of legacy hardware that was never designed to be connected to the public internet.
The PLC and Cellular Modem Vulnerability
At the center of the July attacks were PLCs connected via cellular modems. In many small-to-mid-sized water districts, these modems are used to provide remote telemetry, allowing operators to monitor water levels or pump status from off-site. However, if these modems are not configured with a Virtual Private Network (VPN) or if they rely on default, factory-set credentials, they become an open door for any threat actor scanning the internet.
CISA’s data suggests that the attackers were not performing complex zero-day exploits. Instead, they were performing “credential stuffing” and brute-force attacks against devices that were essentially “sitting ducks” on the public web.
The "Exposure Reduction" Imperative
The sheer volume of exposed systems—over 100 in a single month—highlights a failure in digital hygiene across the sector. Many of these systems were exposed because operators believed that “security by obscurity” (i.e., that no one would find their specific device) was sufficient. The events of July have decisively debunked that myth.

Official Responses and Strategic Guidance
In response to the identified threats, CISA has released comprehensive guidance aimed at reducing the internet attack surface of critical infrastructure. The agency is moving away from passive warnings toward an aggressive stance of "exposure reduction."
The CISA Mandate
CISA’s latest directive to the WWS sector includes a multi-step roadmap for remediation:
- Comprehensive Inventory: Organizations must immediately identify all systems accessible via the internet. This includes not just primary servers, but every remote sensor, pump controller, and cellular modem.
- Strict Perimeter Control: Any system found to be unnecessarily exposed must be taken offline or hidden behind secure gateways.
- Modern Authentication: For systems that must remain accessible, CISA mandates the enforcement of Multi-Factor Authentication (MFA) and the immediate removal of all default passwords.
- Continuous Monitoring: Utilities are encouraged to deploy traffic-monitoring tools that can alert operators to anomalous behavior, such as unauthorized commands sent to a PLC.
Congressional Action and Policy Shifts
Beyond agency guidance, the federal government is attempting to codify these protections. The recent introduction of Senate bills aimed at providing a "cyber boost" to water systems underscores the growing political appetite for stricter regulation. Initiatives like the proposed "Water Watch Center" are intended to provide real-time threat intelligence to utilities that may lack the internal resources to monitor global cyber threats.
Implications for National Security
The targeting of water infrastructure carries implications that go far beyond simple data breaches. When the target is a water utility, the potential for kinetic harm—such as the manipulation of water chemistry or the disabling of pressure systems—is a significant concern for national security experts.
The Threat of "Hacktivism" and State-Sponsored Sabotage
The link to Iranian actors suggests that these attacks are part of a broader geopolitical struggle. By probing the resilience of U.S. water systems, these actors are not just looking for immediate disruption; they are conducting a "mapping" exercise. They are identifying which utilities are vulnerable, how long it takes to detect an intrusion, and how quickly those systems can be restored. This is a classic hallmark of cyber-warfare preparation.
The Burden on Small Utilities
A recurring theme in the July attacks is that small-to-medium-sized utilities are the most frequent victims. These entities often operate with razor-thin budgets and may have only one or two IT staff members—or, in some cases, no dedicated cybersecurity personnel at all. The shift toward requiring these organizations to implement enterprise-grade security controls poses a massive financial and operational burden. Without federal subsidies or significant technical assistance, many of these utilities remain dangerously exposed.
The Future of Critical Infrastructure Security
The July incidents serve as a turning point for the sector. We are entering an era where cybersecurity is no longer a peripheral concern for water utility managers; it is an core component of water safety. The reliance on AI by attackers, as noted in recent reports, means that the window for manual defense is closing. Utilities must transition to automated, hardened systems that can survive in a hostile digital environment.
Conclusion: A Call to Action
The disclosure by CISA is a stark reminder that the nation’s critical infrastructure is engaged in a digital conflict that does not sleep. While the July attacks did not result in widespread failure, the fact that over 100 systems were successfully reached by adversaries is a metric that the industry must aggressively drive toward zero.
As CISA continues its push for increased visibility and reduced exposure, the onus falls on both the federal government to provide the necessary resources and the utility operators to prioritize the hardening of their OT environments. The security of the nation’s water supply depends not on the sophistication of the attacker, but on the resolve of the defenders to close the doors they have left open. The era of the "unmonitored modem" must end, and in its place, a culture of proactive, relentless security must take hold. Only through this rigorous approach can the WWS sector ensure that it remains a reliable provider of one of life’s most essential resources.
