Don’t do SECURITY. Do business SECURELY.
Threat intel

CISA says hackers targeted more than 100 US water systems

CISA confirms attacks on over 100 internet-exposed US water and wastewater systems in July 2026, which US officials believe were likely Iranian.

The US Cybersecurity and Infrastructure Security Agency (CISA) said attackers had targeted more than 100 internet-exposed systems across the US water and wastewater sector during July 2026. US intelligence officials were reported to believe Iran was likely responsible.

What happened

  • The attacks mainly targeted programmable logic controllers from manufacturers including Rockwell, Schneider Electric, and Siemens.
  • Affected utilities were in Michigan, Minnesota, and at least five other states, many of them small or rural.
  • Some intrusions disabled shutdown processes and alarms, potentially creating unsafe conditions, though disruption to water supplies was minimal.
  • The activity was described as largely opportunistic and followed US and Israeli military action against Iran. No formal attribution had been made.

Why it mattered

It showed that poorly secured industrial controls at small utilities remain an easy target for state-linked actors during geopolitical conflict. Many small water providers have limited budgets and few specialist security staff.

Lessons for organisations

Never expose operational technology directly to the internet, change default passwords, and require MFA for remote access. Keep manual operating procedures ready in case control systems cannot be trusted.

Source: TechCrunch

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights