CISA Confirms Over 100 US Water Systems Were Targeted in July: Iran Suspected

CISA has confirmed that more than 100 internet-exposed US water systems were targeted in July 2026, activity widely suspected to be Iran-linked. One expert calls it a test run for something larger. Here is what defenders should verify, and what is still unconfirmed.

Share
White line-art of a water treatment facility and an exposed controller on deep navy, with a single flat red dot marking an internet-facing PLC.

The US government has, for the first time, put a number on this summer’s assault on the water sector: more than 100 internet-exposed water systems were targeted during a wave of cyberattacks in July 2026. That figure comes from the Cybersecurity and Infrastructure Security Agency (CISA), and it turns what had been a scattered set of state-by-state reports into a single, sector-wide campaign.

The scale is the story, but so is the restraint around it. CISA confirmed the activity and issued guidance urging operators to reduce internet exposure, yet it has not attributed the campaign to anyone, even as third-party analysts widely describe it as Iran-linked. This piece does two things the wire coverage runs past: it separates what CISA has actually confirmed from what is still being inferred, and it turns the advisory into a concrete exposure-reduction checklist any water or energy operator can run this week. We do not reconstruct how the intrusions worked, because that is not what defenders need from this disclosure.

What CISA Confirmed

The confirmed core is narrow, and worth quoting exactly. “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” the agency said in its Internet Exposure Reduction guidance, adding that connecting PLCs directly to the internet “can create significant security risks.” As TechCrunch and SecurityWeek both reported, this is the first time federal officials have attached a hard number to the July intrusions.

Two details matter for defenders. First, the common thread CISA names is internet exposure itself: PLCs and other controllers reachable from the open internet, often through cellular modems that an operator, vendor, or integrator installed and never documented, which means they may not appear in a routine attack-surface scan. Second, CISA’s response is not an exotic new control set. It is an instruction to shrink the attack surface: disconnect controllers from the internet, and where remote access is genuinely needed, route it through a VPN or gateway rather than exposing the PLC directly.

The ‘Test Runs’ Warning

What unsettles the analysts quoted around the disclosure is not any single incident but the breadth. “This is very serious. What stands out isn’t any single incident. It’s the scale,” Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber, told The Register. “More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets.”

The sharpest framing came from John Gallagher, vice president at the OT and IoT security firm Viakoo, who told The Register that while 100 systems represent only about 0.5 percent of US water utilities, the “real threat is that these are test runs for a larger-scale attack.” That is an assessment from a private-sector expert, not a government finding, but it captures why a campaign that caused little visible disruption is drawing this much attention. The value of quietly probing a hundred small, mostly rural utilities is what it teaches an attacker about the next hundred.

The pattern also does not stand alone. It extends a summer-long thread, from a five-agency warning that attackers are using AI-generated scripts against internet-exposed Siemens S7 PLCs to a suspected Iran-linked intrusion that knocked a small UK power plant offline for four days. The common denominator across all of it is internet-reachable operational technology in the hands of smaller operators, the ones least likely to have a dedicated security team watching.

What Is Not Confirmed

Read this before briefing anyone upstream, because the gaps are as load-bearing as the number. CISA has not attributed the campaign. “While third-party analysts have largely blamed Iran for the intrusions, the federal government has not attributed the attacks to anyone,” The Register noted, and the Iran-linked framing running through this coverage comes from outside analysts, not from an official US attribution.

Several other specifics remain unconfirmed, and defenders should hold them loosely. No victim utility has been officially named, though state officials have acknowledged targeting in Minnesota, Michigan, Georgia, South Dakota, and New Jersey, among at least a dozen states. No specific Iranian threat cluster has been formally tied to the July campaign; names that have circulated in earlier reporting are suspicion, not confirmation. The precise initial-access vectors have not been detailed publicly beyond the general fact of internet exposure. And whether any utility suffered genuine operational disruption is unsettled: reporting to date describes no significant service impact, even as a parallel FBI alert this summer warned that intrusions into water-sector PLCs could cause operational effects. Treat any claim that fills those blanks as fact at your own risk until an agency says otherwise.

What Water and Energy Operators Should Do Now

None of the following depends on knowing who ran the campaign or how they got in. Each item maps directly to CISA’s exposure-reduction guidance, and each is something an operator can verify this week.

 Reduce Your Internet Attack Surface
Five moves water and energy operators can make now, straight from CISA’s exposure-reduction guidance.
1. Inventory Internet-Facing OT
Check your own public IP ranges against scanning services such as Shodan and Censys, and ask vendors and integrators about any cellular-modem links you are not already tracking.
2. Disconnect or VPN-Gate Remote Access
Take PLCs off the public internet. Where remote access is needed, route it through a VPN or gateway device rather than connecting directly to the controller.
3. Enforce MFA, Kill Default Passwords
Enable password protection, replace every default credential, and allowlist remote access so only known engineering laptops and critical OT assets can connect.
4. Segment OT From IT
Put a monitored boundary between the business network and control systems, so reaching a controller means crossing a controlled chokepoint, not a flat corporate network.
5. Work the CISA Advisories
Check your Siemens and other controllers against CISA’s Internet Exposure Reduction guidance and the joint Siemens S7 advisory (AA26-231A).
 If a Controller Answers the Open Internet
Treat it as an active exposure, not a backlog item. CISA’s core finding is that internet-connected PLCs enabled this activity. Disconnect first, investigate second.
Source: CISA Internet Exposure Reduction Guidance (August 2026). Defender checklist only; no attack detail shown.

The exposure-reduction moves CISA recommends for water and energy operators, distilled into a defender checklist. It describes defensive checks only. Source: The CyberSignal, from CISA guidance.

  • Inventory every internet-facing HMI, PLC, and SCADA node. Check your own public IP ranges against internet scanning services such as Shodan and Censys, and ask vendors and integrators whether they added any cellular-modem connectivity you are not tracking.
  • Remove or VPN-gate remote access. A controller should never answer a request from the open internet. Disconnect PLCs from the internet, and route any necessary remote access through a VPN or gateway device rather than directly to the PLC.
  • Enforce MFA and change default passwords. Enable password protection, replace every default credential, and allowlist remote access so only known engineering laptops and critical OT assets can connect.
  • Segment OT from IT. Put a monitored boundary between the business network and control systems, so reaching a controller means crossing a controlled chokepoint rather than traversing a flat corporate network.
  • Work the CISA advisories into your inventory. Read CISA’s Internet Exposure Reduction guidance and the joint Siemens S7 advisory, and check your controllers against both.

These are the same unglamorous fundamentals that critical infrastructure security has always turned on, and the July campaign is a reminder that exposure, not sophistication, is what made a hundred utilities findable. There is recent proof the discipline works: in a CISA red-team exercise disclosed in August, a water utility detected and isolated a live intrusion in minutes while a government organization running the same tooling never noticed. Detection and fast containment are buildable, and they are what separate a probe from an incident.

My read: the confirmed facts are narrower than the headlines, and that is the point. CISA has told us the scale, more than 100 internet-exposed water systems in a single month, without telling us who, how, or with what effect. The responsible move is to act on the part that is solid. The exposure is real, it is fixable, and it does not require attribution to fix. I would treat Gallagher’s “test runs” line as a planning assumption rather than a prediction: if a hundred small utilities were probed in July, the useful question is not whether your controllers could be found, but whether they already have been. That is an assessment, not a CISA finding, but the sector’s own pattern this summer points hard in that direction.

Updated August 27, 2026: This is a developing story. We will update if CISA formally attributes the campaign, names affected utilities, or confirms operational impact.

Primary Documents

Read more