Widespread Cyberattacks Target US Water Systems

CISA: Over 100 U.S. Water Systems Targeted in July Cyber Campaign

CRITICAL
August 30, 2026
September 4, 2026
4m read
Industrial Control SystemsCyberattackThreat Actor

Related Entities(initial)

Products & Tech

Programmable Logic Controller

Other

Iran

Full Report(when first published)

Executive Summary

In a stark warning to the nation's critical infrastructure operators, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that a coordinated cyber campaign in July 2026 targeted more than 100 systems at U.S. water and wastewater utilities. The attackers, suspected to be linked to Iran, focused on exploiting internet-exposed Programmable Logic Controllers (PLCs), the core components of industrial automation. By compromising these devices, the actors caused tangible physical consequences, including flooding and loss of water pressure, impacting communities in at least 12 states. The campaign exposes a persistent and dangerous vulnerability: the insecure connection of sensitive Operational Technology (OT) to the internet.

Threat Overview

The threat actors systematically scanned the internet for exposed PLCs and other OT assets belonging to water utilities. Upon finding devices with weak or default credentials, they gained access and manipulated their settings. The primary tactic involved changing passwords and IP address configurations, which effectively locked local operators out of their own equipment and disrupted automated processes like pumps and valves. The consequences were immediate and physical, with some utilities experiencing flooding or pressure drops that necessitated boil-water advisories as a precaution.

The campaign has been observed in states including Minnesota, Michigan, Georgia, South Dakota, New Jersey, and Alabama. While federal agencies have not made a formal attribution, the tactics, techniques, and procedures (TTPs) are consistent with previously identified Iranian state-sponsored or state-aligned hacking groups. This marks a significant and aggressive effort to disrupt a vital U.S. critical infrastructure sector.

Technical Analysis

The core of this campaign is the exploitation of insecure remote access to industrial control systems. This is a fundamental failure of cybersecurity best practices for OT environments.

Analyst-assessed MITRE ATT&CK for ICS techniques include:

Impact Assessment

The attacks have a direct and severe impact on public health and safety. Disrupting water treatment and distribution can lead to contamination, service outages, and property damage from flooding. These incidents erode public trust in the reliability of essential services. For the small, often under-resourced utilities that were targeted, the cost of remediation, equipment replacement, and security upgrades can be prohibitive. The campaign demonstrates that even unsophisticated attacks against soft targets in the critical infrastructure sector can have significant real-world consequences.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) were provided in the source articles.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised OT systems:

Type
port
Value
502, 20000, 44818
Description
Common ICS/SCADA protocol ports (Modbus, DNP3, EtherNet/IP) exposed to the internet.
Type
log_source
Value
Firewall Logs
Description
Inbound connections to OT network segments from unexpected external IP addresses.
Type
command_line_pattern
Value
nmap, masscan
Description
Evidence of external scanning tools targeting the organization's IP space.
Type
other
Value
Shodan/Censys search
Description
Proactively search for your organization's assets to find unintentionally exposed devices.

Detection & Response

  1. OT Network Monitoring: Deploy network monitoring solutions specifically designed for OT environments to detect anomalous commands or traffic patterns involving industrial protocols. This aligns with D3FEND's D3-NTA - Network Traffic Analysis.
  2. Asset Inventory: Maintain a comprehensive and up-to-date inventory of all OT assets, including their network connectivity status. This is crucial for identifying exposed devices.
  3. Log Correlation: Correlate logs from IT and OT environments. An alert from an IT system could be an early warning of an attack pivoting towards the OT network.

Mitigation

CISA and the FBI have provided clear guidance for the WWS sector:

  1. Network Isolation: The most critical step is to remove all OT assets, especially PLCs, from direct internet exposure. Use a VPN with multi-factor authentication for any necessary remote access. This is a form of D3FEND's D3-NI - Network Isolation.
  2. Credential Hardening: Immediately change all default passwords on PLCs, HMIs, and other OT devices. Enforce a strong, unique password policy.
  3. Network Segmentation: Implement robust segmentation between IT and OT networks to prevent attackers from moving from a compromised corporate system to the industrial control environment.
  4. Firmware Updates: Regularly update firmware on OT devices to patch known vulnerabilities.

Timeline of Events

1
July 1, 2026
Start of a month-long cyber campaign targeting over 100 U.S. water and wastewater systems.
2
August 26, 2026
CISA publicly confirms the extent of the July campaign against the WWS sector.
3
August 30, 2026
This article was published

Article Updates

September 4, 2026

Iranian state-sponsored groups have expanded their cyber campaign from water systems to target U.S. telecommunications and energy sectors, signaling broader reconnaissance and access intent.

MITRE ATT&CK Mitigations

Isolate OT networks from IT networks and the internet to prevent unauthorized access to critical control systems.

Change default passwords on all ICS/OT devices and enforce strong, unique credentials.

Use firewalls to strictly control traffic between IT and OT networks, only allowing necessary communication.

Regularly scan for and remediate vulnerabilities in OT assets, especially those with any network connectivity.

Timeline of Events

1
July 1, 2026

Start of a month-long cyber campaign targeting over 100 U.S. water and wastewater systems.

2
August 26, 2026

CISA publicly confirms the extent of the July campaign against the WWS sector.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

icsot securitycritical infrastructurewater systemsplcirancisa

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.