← BACK TO FEED
water infrastructureICS securityCISAOT securityIran

100+ Water Systems Hit in July Cyberattacks — CISA Finally Puts a Number On It

In July 2026, CISA identified cyberattacks targeting over 100 internet-exposed water and wastewater systems across at least 12 U.S. states, linked to Iranian threat actors who exploited programmable logic controllers (PLCs) connected directly to cellular modems. While the attacks caused no significant disruption, they have raised serious concerns about the vulnerability of critical infrastructure. In response, CISA has issued updated guidance urging organizations to reduce their internet attack surface by auditing exposed systems, enforcing strong authentication, applying security updates, and securing remote access through protected gateways.

CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks last month, making this the first time a federal agency has actually quantified the scale of what's been a quietly alarming campaign against US water infrastructure.

The figure appeared in updated guidance the agency published to help organisations shrink their internet-facing attack surface. The attacks, attributed to Iranian threat actors, went after operational technology systems — specifically programmable logic controllers plugged directly into cellular modems. Which is, frankly, the kind of network architecture that should make any security professional wince.

At least 12 states appear to have been caught up in this, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. The full list remains unclear. No significant disruption was caused, but that's a fairly thin silver lining when you consider what these systems actually control.

CISA's guidance doesn't break new ground so much as it restates the obvious with increasing urgency. Organisations are told to audit what they have exposed to the internet, cut anything that doesn't need to be there, change default credentials, patch systems, funnel remote access through proper gateways, enforce multi-factor authentication, and actually monitor their traffic. The fact that this still needs saying in 2026, for systems managing drinking water, is its own kind of indictment.

The agency is particularly pointed about PLCs and other industrial control systems sitting naked on the public internet via cellular modems — precisely the setup that gave attackers their way in. These aren't obscure edge cases. This is how a lot of smaller water utilities are still running.

The guidance lands shortly after CISA raised separate alarms about Iranian-linked activity targeting ICS hardware from Siemens, Schneider Electric, and Rockwell Automation. There's a pattern developing here that's hard to ignore.

For defenders wanting more technical detail on the specific systems involved, the Infracritical website is tracking known technical information on affected infrastructure.

READ NEXT
AI-Assisted Hacking Puts Siemens PLCs in US Critical Infrastructure Squarely in the CrosshairsAI-Assisted PLC Attacks on Critical Infrastructure Are No Longer HypotheticalPLCs on the public internet are an open goal for attackers, says ex-NSA chief