More Than 100 Water Systems Were Hit by Hackers in July. Here's What CISA Found.

U.S. cybersecurity officials have put a number on the recent wave of attacks on drinking water and wastewater facilities: over 100 internet-connected systems targeted in a single month, most of them left exposed by a simple modem.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A water treatment facility control room with SCADA systems and network-connected monitoring equipment, many accessed through exposed modems visible on facility
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that more than 100 internet-exposed water and wastewater systems were targeted by hackers in July 2026.
  • Attacks were linked to Iranian hackers and focused on programmable logic controllers, the small computers that run pumps and treatment equipment.
  • Six states have publicly confirmed they were targeted; CISA believes the total reaches at least 12.
  • CISA has published new guidance urging water utilities to take their control equipment off the public internet immediately.
  • The attacks followed earlier warnings about Iranian hackers targeting industrial systems made by Siemens and Rockwell Automation.

For most of us, water just comes out of the tap. Behind that tap sits a surprisingly fragile chain of industrial computers, and in July hackers probed more than 100 of them in a single month.

CISA disclosed the figure this week alongside new guidance for water utilities. It's the first time federal officials have put a concrete number on the recent wave of attacks targeting the water sector.

How did the hackers get in?

Most of the targeted systems were reachable directly over the public internet because they were plugged into cellular modems. That gave hackers a straight path to programmable logic controllers, or PLCs, the small industrial computers that physically control pumps and chemical dosing equipment at water and wastewater plants.

Think of a PLC as the brain of a water treatment plant. It follows instructions automatically and can't question whether those instructions came from an authorized engineer or an attacker overseas.

CISA linked the attacks to Iranian-backed hackers. We reported on 19 August 2026 that the same group had been targeting exposed Siemens controllers using AI-written scripts.

Should customers be worried?

For now, no. The attacks didn't cause any significant disruption to water supplies. Taps kept running and treatment kept working.

Officials are clearly rattled by how many systems were reachable in the first place. Six states have publicly confirmed they were targeted: Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA believes the total reaches at least 12 states.

State confirmed targeted Publicly acknowledged
Minnesota Yes
Michigan Yes
South Dakota Yes
Georgia Yes
New Jersey Yes
Alabama Yes

What is CISA telling utilities to do?

The new guidance, reported earlier by SecurityWeek, is blunt: take your industrial systems off the internet wherever possible, and do it now.

For systems that genuinely need remote access, CISA recommends four concrete steps. First, identify every internet-accessible system through internal inventories and external scanning, then remove or restrict anything that doesn't need to be online. For what remains: change every factory-default password, which are often identical across thousands of devices. Apply all available software updates. Route remote connections through a secure gateway, basically a locked door between the internet and the control system, rather than a direct modem link. Turn on multifactor authentication, a login requiring both a password and a second check such as a text code.

Regular audits matter too, because third-party contractors often add new connections nobody tracks.

The guidance is worth reading alongside the Senate bill and monitoring centre we covered on 11 August 2026. Legislative backing and a federal number to point to are new; the underlying exposure has been there for years.

Common questions

Were any water supplies actually contaminated or cut off?

No. CISA said none of the July attacks caused significant disruption. Hackers reached the systems but didn't manage to alter treatment processes or shut down service.

Why are water systems connected to the internet at all?

Remote monitoring lets engineers check equipment from a distance, cutting costs for small utilities with limited staff. A direct modem connection with a default password offers almost no resistance to a determined attacker. That's the gap CISA wants closed.

© 2026 Threat Vectr