More Than 100 Water Systems Were Hit by Hackers in July. Here's What CISA Found.
U.S. cybersecurity officials have put a number on the recent wave of attacks on drinking water and wastewater facilities: over 100 internet-connected systems targeted in a single month, most of them left exposed by a simple modem.

Key points
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that more than 100 internet-exposed water and wastewater systems were targeted by hackers in July 2026.
- Attacks were linked to Iranian hackers and focused on programmable logic controllers, the small computers that run pumps, valves, and treatment equipment.
- At least 12 states were affected, including Minnesota, Michigan, Georgia, and New Jersey, though no significant disruption to water supplies was reported.
- CISA has published new guidance urging water utilities to take their control equipment off the public internet immediately.
- The attacks followed earlier warnings about Iranian hackers targeting industrial systems made by Siemens, Schneider Electric, and Rockwell Automation.
For most of us, water just comes out of the tap. Behind that tap sits a surprisingly fragile chain of industrial computers, and in July hackers probed more than 100 of them in a single month.
The U.S. Cybersecurity and Infrastructure Security Agency, known as CISA, disclosed the figure this week as part of new guidance for water utilities. It is the first time federal officials have put a concrete number on the recent wave of attacks targeting the water sector.
How did the hackers get in?
Most of the targeted systems were reachable directly over the public internet because they were plugged into cellular modems. That gave the hackers a straight path to programmable logic controllers, or PLCs, the small industrial computers that physically control pumps, chemical dosing equipment, and valves at water and wastewater plants.
Think of a PLC as the brain of a water treatment plant. It follows instructions automatically and has little ability to question whether those instructions came from an authorized engineer or a criminal in another country.
CISA linked the attacks to Iranian-backed hackers. The same group had previously targeted industrial control equipment sold by Siemens, Schneider Electric, and Rockwell Automation.
Should customers be worried?
For now, no. The attacks did not cause any significant disruption to water supplies. Taps kept running, treatment kept working.
That said, officials are clearly shaken by how many systems were reachable in the first place. Six states have publicly confirmed they were targeted: Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA believes the total reaches at least 12 states.
| State confirmed targeted | Publicly acknowledged |
|---|---|
| Minnesota | Yes |
| Michigan | Yes |
| South Dakota | Yes |
| Georgia | Yes |
| New Jersey | Yes |
| Alabama | Yes |
What is CISA telling utilities to do?
The new guidance, reported earlier by SecurityWeek, is blunt: take your industrial systems off the internet wherever possible, and do it now.
For systems that genuinely need remote access, CISA recommends four concrete steps. Change every factory-default password, which are often the same across thousands of devices. Apply all available software updates. Route remote connections through a secure gateway, basically a locked door between the internet and the control system, rather than a direct modem link. Finally, turn on multifactor authentication, meaning a login that requires both a password and a second check such as a text code.
Regular audits matter too, because third-party contractors often add new connections that nobody tracks.
For residents served by local utilities, the most useful thing right now is to stay calm and stay informed. If your water provider issues any notices about service changes or safety advisories, follow them. The infrastructure held this time. The question officials are asking is whether it will hold next time.
Common questions
Were any water supplies actually contaminated or cut off?
No. CISA said none of the July attacks caused significant disruption. Hackers reached the systems but did not manage to alter treatment processes or shut down service.
Why are water systems connected to the internet at all?
Remote monitoring lets engineers check equipment from a distance, which saves cost and time for small utilities with limited staff. The problem is that a direct modem connection with a default password offers almost no resistance to a determined attacker.



