The US Cybersecurity and Infrastructure Security Agency (CISA) said attackers had targeted more than 100 internet-exposed systems across the US water and wastewater sector during July 2026. US intelligence officials were reported to believe Iran was likely responsible.
What happened
- The attacks mainly targeted programmable logic controllers from manufacturers including Rockwell, Schneider Electric, and Siemens.
- Affected utilities were in Michigan, Minnesota, and at least five other states, many of them small or rural.
- Some intrusions disabled shutdown processes and alarms, potentially creating unsafe conditions, though disruption to water supplies was minimal.
- The activity was described as largely opportunistic and followed US and Israeli military action against Iran. No formal attribution had been made.
Why it mattered
It showed that poorly secured industrial controls at small utilities remain an easy target for state-linked actors during geopolitical conflict. Many small water providers have limited budgets and few specialist security staff.
Lessons for organisations
Never expose operational technology directly to the internet, change default passwords, and require MFA for remote access. Keep manual operating procedures ready in case control systems cannot be trusted.
Source: TechCrunch
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.