The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers targeted over 100 internet-exposed systems across the American water and wastewater sector, providing the first official count of a sweeping campaign that has disrupted operations in at least 12 states since late July.
The August 26 disclosure from CISA, reported by TechCrunch, provides new context to the scale of cyberattacks that initially emerged between July 26 and 27, when Minnesota authorities discovered that more than 30 water communities in their state had been hit in a coordinated wave. The federal agency said the attacks have largely targeted programmable logic controllers (PLCs) manufactured by Rockwell Automation, Schneider Electric and Siemens, the industrial devices that control physical machinery in water treatment plants and distribution networks.
A Growing Victim Count
The initial FBI alert on July 30 reported incidents in at least seven states. By early August, ABC News and CBS News had independently confirmed the number had risen to 12. Michigan’s Department of Environment, Great Lakes and Energy confirmed on August 1 that nine municipal water systems in the state reported activity consistent with the federal warnings. Georgia’s Clayton County Water Authority experienced a pressure drop that prompted a boil-water advisory for 300,000 customers in the Atlanta area, though service was restored within hours. Columbus Water Works in Georgia also confirmed a cyber intrusion on August 5. South Dakota and New Jersey have been identified as additional affected states, though specific facilities have not been publicly named. Many of the affected communities are in rural or isolated areas where disruption to critical water systems can affect large populations.
AI-Assisted Attacks on Industrial Controllers
CISA revealed that the attackers are relying in part on artificial intelligence tools to develop scripts targeting vulnerable PLCs. A separate advisory on August 20 said hackers were using AI-powered tools to parse publicly available technical documentation for Siemens PLCs, generating exploit code capable of disabling safety shutdowns and alarms without notifying operators. The agency warned that such modifications could create “unsafe conditions” at affected facilities. The FBI identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as specific targets, while the July 22 update to CISA Advisory AA26-097A expanded the scope to include Schneider Electric and Siemens devices alongside Rockwell. The advisory also documented, for the first time, the exfiltration of PLC project files, indicating attackers are stealing configuration data that could be reused against similar installations elsewhere.
Iran Likely Behind Campaign
US intelligence believes Iran is likely behind the attacks, which officials describe as largely opportunistic and possibly connected to the ongoing US and Israel-led military campaign against Iran. The operational pattern is consistent with the CyberAv3ngers threat ecosystem, a group the US government has formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. In February 2024, the Treasury Department sanctioned six IRGC-CEC officials for directing CyberAv3ngers operations, and the State Department offered up to 10 million dollars for information on the group. However, federal agencies have stopped short of a formal attribution, referring to the perpetrators only as “malicious cyber actors.”
No Contamination, But Real Operational Risk
No incidents of water contamination have been reported, and drinking water safety has not been compromised. However, several utilities were forced to revert to manual operations and switch to manual control while investigating the breaches. Some facilities issued boil-water advisories as a precautionary measure. CISA has urged critical infrastructure owners and operators to remove all publicly exposed PLCs and other operational technology from the internet immediately, describing internet-facing industrial controllers as an unacceptable security risk. The agency also recommended disabling default passwords on PLCs, implementing network segmentation between IT and OT environments and monitoring for unauthorized PLC configuration changes.
Broader Infrastructure Concerns
The water system attacks have raised alarm across the critical infrastructure community, which has faced an escalating pattern of state-sponsored cyber activity in recent years. US officials have previously warned that Chinese state hackers have been planting destructive malware in US energy, water and transportation systems in preparation for potential conflict. The water sector has been particularly vulnerable because many smaller utilities operate with limited cybersecurity budgets and aging industrial control systems. The Waterfall Threat Report 2026 found that publicly recorded cyber breaches with physical consequences across heavy industry and critical infrastructure fell by 25% in 2025, but that nation-state and hacktivist attacks doubled during the same period, with the majority targeting critical infrastructure systems. Experts warn that without significant investment in OT security, the gap between attacker capability and defender readiness will continue to widen.
discussion