Hackers Target Over 100 U.S. Water Systems in a Single Month, Federal Agency Confirms

CISA says hackers targeted more than 100 internet-exposed U.S. water systems in July, exploiting PLC access and causing some operational disruptions.

Aug 27, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

America’s water utilities faced a concentrated wave of cyberattacks in July, with exposed industrial control systems providing attackers a direct path into operational technology.

The Cybersecurity and Infrastructure Security Agency said malicious actors targeted more than 100 internet-exposed systems in the U.S. Water and Wastewater Systems sector during July 2026. In several cases, attackers remotely accessed programmable logic controllers, changed device settings and disrupted utilities’ ability to monitor or control equipment.

CISA said attackers remotely accessed exposed PLCs, changed device IP addresses and passwords, and in some cases caused utilities to lose monitoring and control capabilities. Some incidents also led to operational disruptions, although no confirmed widespread drinking-water contamination.

The campaign affected utilities in at least a dozen states, according to reports, including Minnesota, Michigan, Georgia, South Dakota and New Jersey. Minnesota alone confirmed malicious activity involving more than 30 community water systems.

CISA’s warning focuses heavily on a problem that can be easy to overlook: remote access that was added for convenience but left exposed.

“Directly connecting PLCs to the internet through cellular modems can create significant security risks,” CISA said in its guidance.

The agency recommends removing unnecessary remote access and routing legitimate connections through a secure gateway, firewall, VPN or centrally managed solution rather than connecting directly to a PLC, human-machine interface or remote terminal unit.

Utilities should also change default passwords, apply security patches, replace unsupported equipment and use multifactor authentication where possible. The guidance also encourages organizations to check vendor and contractor connections. That matters because third parties can introduce internet-facing equipment that may not appear in a utility’s own asset inventory.

Advertisement

Attribution remains unclear

The U.S. government has not publicly attributed the July campaign to a specific threat actor.

CISA’s count measures systems targeted, not necessarily successful breaches or separate utilities compromised. It also does not establish that every incident came from the same attacker.

The July campaign also highlights a difficult reality for smaller water providers: cybersecurity has to compete with operational demands and limited resources.

For water utilities, the immediate lesson is less about eliminating remote access than knowing exactly what is exposed.

CISA recommends that operators inventory internet-facing equipment, remove unnecessary direct connections, and verify systems installed or maintained by vendors and contractors. Exposure-discovery services such as Shodan, Censys and Shadowserver can also help utilities identify systems that may be reachable from the public internet.

For smaller providers with limited cybersecurity staff, that visibility may be the most important first step: a PLC cannot be secured if the utility does not know it is exposed.

More News: A cyberattack on medical device maker Boston Scientific disrupted global operations and its ability to process and ship customer orders, with no timeline yet for a full recovery.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.