The FBI has confirmed that hackers struck water and wastewater systems in at least seven U.S. states, following a coordinated intrusion that disrupted more than 30 community water systems in Minnesota on July 26 and 27, 2026. State counts diverge sharply depending on when and by whom they were given: the FBI and EPA joint statement in late July cited at least seven states, while acting CISA Director Nick Andersen told Nextgov/FCW on August 6 that CISA and the FBI were assisting utilities across at least 12 states, a figure Tenable's incident FAQ attributes to an ABC News report. Federal agencies have described the underlying campaign as Iranian-affiliated in CISA Advisory AA26-097A, but CISA has pointedly declined to attribute the Minnesota and multistate water incidents to any group.
What Happened
The visible incident began in Minnesota. State officials said technology used by more than 30 community water systems was targeted across a two-day window, Sunday July 26 into Monday July 27. Nextgov/FCW reported that some utilities were forced to operate equipment manually, and that an intrusion in the city of Braham briefly knocked out controls for the municipal well and water treatment plant. Officials said they found no evidence that drinking water quality was affected.
The pattern then propagated. Route Fifty reports Michigan and Georgia among the latest states to say at least some of their water systems had been compromised. The BBC notes that local authorities in New Jersey, South Dakota and Georgia have said they were similarly attacked, while cautioning that it is not clear whether those states are among the seven the FBI cited. The FBI's warning specified that "some of that activity degraded water operations."
CISA issued an urgent water and wastewater sector alert on July 30 and 31, warning of a significant increase in attacks against internet-exposed programmable logic controllers. Per BleepingComputer, the alert described attackers changing PLC passwords to lock operators out and modifying IP addresses to disconnect devices, with follow-on effects including water pressure problems, boil-water notices and extended periods of manual operation. CISA stressed that organizations of all sizes are being targeted, including some with mature cybersecurity programs.
Attribution is where the sources genuinely part ways, and defenders should treat it as unresolved. The federal advisory language quoted by Security Affairs is explicit about "ongoing Iranian-affiliated cyber targeting." A memo to Water ISAC members obtained by Nextgov/FCW cites the Minnesota Fusion Center's finding that the water attacks are "aligned" with the CISA-described campaign, but presents no direct evidence tying the Minnesota incident to Iran. Two people familiar with the matter told Nextgov/FCW that some officials believe an Iran-aligned group is responsible, while noting investigations remain open. Tenable states plainly that attribution remains pending federal investigation. The BBC reports that US investigators are examining whether the actors posed as Iran-based as a ruse, per CBS, and that President Trump has not blamed Iran. Andersen, speaking for CISA on August 6, is not attributing the intrusions to any group.
What Was Taken
This is not a data breach in the conventional sense, and no source reports theft of customer or personal records. The stolen material is industrial, and arguably more consequential.
The July 22 update to CISA Advisory AA26-097A documented PLC project file exfiltration for the first time, a point both Tenable and Trend Micro flag as newly confirmed rather than merely suspected. Security Affairs details the mechanism: attackers pull project files using legitimate vendor engineering software including Rockwell Studio 5000, Schneider Electric EcoStruxure Control Expert and Siemens TIA Portal. Those files are the blueprints of a plant's physical process logic, describing pumps, valves, setpoints and safety interlocks.
Beyond exfiltration, the advisory describes destructive and manipulative changes: modification or deletion of project logic including Add-On Instructions, manipulation of HMI and SCADA display data so operators saw nothing wrong on their screens, and disabling of shutdown and alarm functions. Trend Micro contrasts this directly with a similar but largely disruption-free campaign in 2023, noting that the current activity has caused confirmed operational disruption and financial loss at some affected organizations.
Why It Matters
The attack surface is enormous and largely unmanaged. The BBC puts the U.S. footprint at 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities, most of them small municipal operators without dedicated OT security staff. Censys, cited by BleepingComputer, estimated more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley devices reachable at the time of publication.
More telling is that exposure persists a week after a national alert. Andersen told Nextgov/FCW that CISA is still finding PLCs "open and accessible on the internet with either no password set or default password set," adding: "We're not making ourselves hardened targets." That is not a sophistication problem. It is a hygiene problem at national scale.
Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition, called the attacks a "wake up call for OT security." Adam Ford, CTO for state and local government and education at Zscaler, framed the stakes for Route Fifty: "The willingness of malicious actors to interfere with systems that support the water we drink underscores how quickly a cyber incident can become a public safety issue." Morgan Wright, a former State Department anti-terror adviser, told the BBC he expects the affected-state count to grow and that "no state is immune." The reported jump from seven states to roughly 12 inside a week is consistent with that.
The Attack Technique
The tradecraft described across the federal advisory and vendor analyses is notable for how unexotic it is. Trend Micro summarizes it as scanning the internet for exposed PLCs and connecting using legitimate engineering software, the same way an authorized technician would. There is no novel malware in the public reporting.
Per Security Affairs, access occurs over standard OT protocol ports 44818 (EtherNet/IP), 2222, 102 (Siemens S7) and 502 (Modbus), plus cellular modems reachable over SSH on port 22. CISA's sector alert specifically warned that exposed OT may include undocumented cellular modems installed by operators, vendors or system integrators, assets many utilities do not know they own.
The vulnerability that anchors the campaign is CVE-2021-22681, a CVSS 9.8 authentication bypass in Rockwell Automation Logix controllers with no available vendor patch. Tenable notes it was added to CISA's Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors. The April 2026 advisory scoped the activity to Rockwell Automation/Allen-Bradley equipment; the July 22 revision, issued by six federal agencies including CISA, FBI, NSA and the Department of Energy, widened it to Schneider Electric and Siemens and added detection guidance for malicious changes hidden inside shared, reusable code modules. That last detail matters: logic tampering buried in a reused Add-On Instruction propagates to every routine that calls it and is easy to miss on visual inspection.
What Organizations Should Do
- Remove publicly exposed PLCs and other OT from the internet immediately. This is CISA's primary and repeated instruction. Where full removal is not feasible, place access behind a VPN or gateway device and restrict it to an IP allow-list.
- Inventory undocumented remote access paths, specifically cellular modems installed by operators, vendors or integrators, and audit exposure on ports 44818, 2222, 102, 502 and 22.
- Change all default and blank PLC passwords. CISA is still finding controllers online with no password set. For Rockwell MicroLogix 1400 devices already locked out by attacker password changes, follow the vendor's documented recovery guidance.
- Compare current PLC project logic against known-good offline baselines, paying particular attention to Add-On Instructions and other shared, reusable code modules per the July 22 detection guidance. Assume project files that were exfiltrated give the actor working knowledge of your process.
- Validate HMI and SCADA displays independently of the control network. Because this campaign manipulates operator-facing data, screen readings alone are not evidence that the process is healthy. Confirm against field instrumentation and physical checks.
- Verify that shutdown, alarm and safety-instrumented functions are enabled and untampered, then rehearse manual operation. Multiple Minnesota utilities ran manually for extended periods; that capability should be tested, not assumed.
- Treat CISA Advisory AA26-097A as a living document. It was issued in April 2026 and materially revised on July 22, and both Tenable and Trend Micro have tracked further updates since.
Sources: More US water systems struck by hackers | Federal Agencies Warn of Ongoing PLC Exploitation Against Critical... | Minnesota Water Cyber Attack and CISA Advisory AA26-097A | Did Iran hack water systems in seven US states? | CISA warns of cyberattacks disrupting U.S. water utilities | CISA urges water utilities to take exposed systems down after Minne... | CISA still finds water system controls exposed online amid multista... | Iran-Linked Actors Breach Are Targeting US Water and Energy Control...