Over 100 U.S. Water Systems Struck by Cyberattacks in July, CISA Confirms

In July 2026, more than 100 water and wastewater systems across the United States were hit by cyberattacks, according to a warning issued by the Cybersecurity and Infrastructure Security Agency (CISA). The attacks targeted systems that are exposed to the internet and have raised alarms among federal agencies and local operators alike.

What Was Targeted and How

The primary target of the attacks has been programmable logic controllers (PLCs), which are widely used to control machinery and essential operations in water treatment and wastewater management facilities. CISA noted manufacturers such as Rockwell, Schneider Electric, and more recently Siemens among those whose PLCs came under attack. In a notable development, hackers leveraged AI tools—drawing on publicly available information—to identify and exploit vulnerabilities in Siemens PLCs.

While the assaults have not disrupted water supply or sanitation services in communities, they have led to operational outages and disruptions while authorities responded. One particularly dangerous capability reported involved attackers modifying PLC programming to disable shutdown processes and alarms—changes that could lead to unsafe conditions without warning operators.

Geographical Spread and Attribution Concerns

Communities affected are largely rural or remote, where water system disruptions can have a more severe impact. The incidents include infrastructure in Michigan, Minnesota, and at least five other states, bringing the scale of the issue into sharp focus.

Attribution remains under investigation, though U.S. intelligence points toward cyber actors linked to Iran’s Islamic Revolutionary Guard Corps. The operational style has been largely opportunistic, taken as possible retaliation related to ongoing U.S. and Israel-led conflicts with Iran. Other foreign actors—including those linked to China and Russia—have also been previously implicated in attacks against water, energy, and critical infrastructure in both the U.S. and abroad.

The situation has amplified broader concerns about the fragility of U.S. critical infrastructure, especially as threat actors increasingly target systems that combine physical operations with digital controls.

Mitigation and guidance are ongoing. CISA has emphasized the need for water utilities to assess their exposure to the internet, strengthen their security settings, and monitor for offensive activity. Emergency alerts from federal agencies to states have urged vigilance, risk assessments, and rapid response planning.

This wave of cyberattacks reflects an evolving threat landscape where critical infrastructure operators—especially those in remote or understaffed areas—are especially at risk. As water and wastewater systems adapt to modern control technologies, the convergence of physical utilities and remote exposure demands new levels of cybersecurity maturity.

### What This Means and What to Watch

The recent surge in cyber intrusions into water systems underscores a growing pattern: threat actors exploiting unattended remote access and lax cyber hygiene in critical infrastructure. Moving forward, water utilities will need to adopt zero-trust models, improve inventories of internet-facing assets, and embrace stronger authentication and monitoring practices. For policymakers, this episode should fuel not just warnings, but legislative and regulatory action to enforce standards for all system operators—urban and rural alike. The health, safety, and safety of public water depend on it.