100+ Water Systems Hit in July Cyberattacks — CISA Finally Puts a Number On It
CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks last month, making this the first time a federal agency has actually quantified the scale of what's been a quietly alarming campaign against US water infrastructure.
The figure appeared in updated guidance the agency published to help organisations shrink their internet-facing attack surface. The attacks, attributed to Iranian threat actors, went after operational technology systems — specifically programmable logic controllers plugged directly into cellular modems. Which is, frankly, the kind of network architecture that should make any security professional wince.
At least 12 states appear to have been caught up in this, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. The full list remains unclear. No significant disruption was caused, but that's a fairly thin silver lining when you consider what these systems actually control.
CISA's guidance doesn't break new ground so much as it restates the obvious with increasing urgency. Organisations are told to audit what they have exposed to the internet, cut anything that doesn't need to be there, change default credentials, patch systems, funnel remote access through proper gateways, enforce multi-factor authentication, and actually monitor their traffic. The fact that this still needs saying in 2026, for systems managing drinking water, is its own kind of indictment.
The agency is particularly pointed about PLCs and other industrial control systems sitting naked on the public internet via cellular modems — precisely the setup that gave attackers their way in. These aren't obscure edge cases. This is how a lot of smaller water utilities are still running.
The guidance lands shortly after CISA raised separate alarms about Iranian-linked activity targeting ICS hardware from Siemens, Schneider Electric, and Rockwell Automation. There's a pattern developing here that's hard to ignore.
For defenders wanting more technical detail on the specific systems involved, the Infracritical website is tracking known technical information on affected infrastructure.