Press play to start listening
CISA (Cybersecurity and Infrastructure Security Agency) says hackers targeted more than 100 internet-exposed systems used by US water and wastewater utilities during July 2026, commonly through programmable logic controllers connected directly to cellular modems.
The figure appeared in exposure-reduction guidance published on August 21, 2026, and provides the first federal count for the recent attacks. It describes targeted systems, not confirmed breaches at more than 100 separate utilities, and CISA did not say how many attempts succeeded.
Internet-Exposed PLCs Provided an Entry Point
In many affected setups, a cellular modem allowed operators to manage a programmable logic controller remotely. PLCs control or monitor physical equipment such as pumps, valves, pressure systems and chemical processes, so direct internet access can allow an attacker to reach operational functions.
A joint FBI and EPA warning said attackers accessed exposed Rockwell Automation MicroLogix 1100 and 1400 controllers before changing IP addresses and passwords. Those changes caused some utilities to lose monitoring or control of connected equipment.
Investigators also found modified PLC project files at one organization. Similar network configurations supplied by third parties appeared at several affected facilities, allowing attackers to repeat the same methods where customers used comparable hardware and settings.
Matt Hartman, chief strategy officer at Merlin Group, told Hackread.com that targeting more than 100 systems in one month points to a sector-wide problem, not separate local events. He urged utilities to identify exposed assets, remove unnecessary access, replace default credentials, patch supported equipment, protect required remote connections with multifactor authentication, and monitor for suspicious activity.
Some Attacks Affected Water Operations
CISA’s alert in July showed that the incidents were not limited to unsuccessful scanning. Authorities said activity reported since July 27 degraded operations at some facilities, with effects including pressure loss and flooding. Officials have not reported contaminated drinking water.
Minnesota confirmed malicious activity involving technology at more than 30 community water systems. State officials explained that not every affected community experienced a water-service disruption and said no residents were being asked to change their drinking-water use when the update was issued.
The federal government has not published a final state count. CBS News reported that incidents had been reported in at least 12 states, including Minnesota, Michigan, Georgia, New Jersey and South Dakota, citing sources familiar with the investigation.
No Final Attribution Announced
Federal agencies have previously warned that Iranian-affiliated actors target internet-connected industrial controllers, but the recent incidents have not received a single public attribution. Minnesota said investigators had not determined that every case involved the same attacker.
David Brumley, chief AI and science officer at Bugcrowd, told Hackread.com that water facilities can be attractive targets because limited staff and budgets may leave them more exposed and slower to recover. He said some attacks may begin as attempts to embarrass the United States, but access to critical infrastructure can create more serious consequences once an attacker gains control.
CISA Calls for Reduced Internet Exposure
CISA’s guidance tells operators to find every system reachable from the internet and decide whether that access is necessary. Unneeded exposure should be removed, while required connections should pass through secure gateways or jump hosts protected by multifactor authentication.
Utilities should also replace default passwords, install available updates, restrict communication through firewalls or access-control lists, and review PLC, modem, and network logs. Operators are advised to maintain tested manual controls and verified offline backups so water services can continue if digital systems become unavailable.