Cyberattacks Target Over 100 Water Systems in July

In July 2026, more than 100 internet-exposed water systems were compromised in a series of cyberattacks, raising concerns about systemic vulnerabilities in critical infrastructure.

In July 2026, the U.S. government reported that cybercriminals targeted over 100 water systems that were exposed to the internet. This marks the first time federal authorities have quantified the extent of these digital intrusions, although they have not yet attributed the attacks to a specific group, despite suspicions of Iranian involvement.

Details of the Cyberattacks

The Cybersecurity and Infrastructure Security Agency (CISA) noted that the attacks primarily involved programmable logic controllers (PLCs) connected directly to cellular modems. CISA highlighted that such direct internet connections pose significant security risks. The attacks affected water and wastewater facilities across at least a dozen states, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey, with a focus on smaller, rural utilities.

Implications of the Incidents

Experts emphasize the seriousness of the situation, pointing out that the scale of the attacks indicates a systemic vulnerability rather than isolated incidents. Matt Hartman, a former acting head of cyber at CISA, remarked that the number of affected systems in a single month is alarming and reflects broader weaknesses within the sector. Many of these systems were originally designed for closed environments and were not intended to be accessible via the open internet.

Potential for Future Threats

John Gallagher, a cybersecurity provider, noted that while the impacted systems represent only about 0.5 percent of U.S. water utilities, the incidents may serve as test runs for larger-scale attacks. Recent warnings from five U.S. federal agencies indicated that attackers are employing AI-generated exploitation scripts to breach internet-exposed Siemens S7 Series PLCs, which are critical to various sectors, including water and energy.

Recommendations for Water Utilities

In response to these incidents, CISA has advised organizations to disconnect PLCs from the internet and to ensure that any remote access is conducted through a VPN or gateway device. Additional recommendations include enabling password protection—preferably with multi-factor authentication—and changing default passwords. CISA also suggested that organizations implement allowlist IPs to restrict remote access to known engineering devices.

While third-party analysts have largely attributed the attacks to Iranian actors, the federal government has refrained from making a formal attribution, citing the complexities involved in identifying cyber adversaries. As the situation develops, the focus remains on understanding the methods of attack and enhancing defenses to protect critical infrastructure.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 362