More than 100 water systems were hit in July cyberattacks
'These are test runs for a larger-scale attack'
Security
More than 100 water systems were hit in July cyberattacks
'These are test runs for a larger-scale attack'
The US government disclosed that crims targeted more than 100 internet-exposed water systems during July cyberattacks. That's the first time the feds have put a number on the digital intrusions, but they have yet to attribute the campaign, widely suspected to be linked to Iran, to a particular group.
“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” America’s lead cyber-defense agency said, adding that connecting PLCs directly to the internet “can create significant security risks.”
Suspected Iranian attackers targeted water and wastewater facilities across at least a dozen states in July, including internet-exposed PLCs. While neither federal nor state officials have identified all 12, we know that the cyberattacks occurred at mostly small, rural utilities in Minnesota, Michigan, Georgia, South Dakota, and New Jersey.
“This is very serious. What stands out isn't any single incident. It's the scale,” Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber, told The Register.
“More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets,” Hartman said. “Much of this infrastructure runs on operational technology that was built for closed, physical environments. It was never designed with the assumption that it would be reachable from the open internet.”
John Gallagher, VP at Viakoo, an OT and IoT cybersecurity provider, told us that while 100 systems represent a small fraction - only about 0.5 percent - of water utilities in the US, the “real threat is that these are test runs for a larger-scale attack.”
While the 100-plus water incidents occurred in July, just last week five US federal agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities.
“This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register a week ago.
“Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society,” Kaiser, a former FBI cyber division deputy assistant director, added.
While third-party analysts have largely blamed Iran for the intrusions, the federal government has not attributed the attacks to anyone.
“Attribution in cyber incidents is inherently difficult and often takes time. Adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems, so the government needs to be diligent before publicly assigning responsibility,” Hartman said.
“In this case, CISA has done the most important thing: quickly getting actionable information into the hands of water-sector operators so they can defend their systems,” he added. “From a defender’s perspective, the ‘who’ matters less in the immediate term than understanding how the attacks are occurring and taking steps to stop them.”
In its advisory, CISA recommended organizations disconnect PLCs from the internet and ensure any remote access goes through a VPN or gateway device rather than connecting directly to the PLC.
The cyber-defense agency also advised owner-operators to enable password protection (we suggest multi-factor authentication) and change any default passwords. Also: ensure that allowlist IPs only allow remote access from known engineering laptops or other critical OT assets.®
Originally published on The Register


