A coordinated campaign against internet-exposed industrial controllers has disrupted water and wastewater utilities across the United States, prompting a joint FBI and EPA public service announcement on July 30, 2026. The FBI confirmed that utilities in at least seven states had reported incidents since July 27, and that some of the activity "degraded water operations." Independent reporting puts the footprint higher: ABC News, cited by both Tenable and SecurityWeek, counts at least 12 states, and CyberScoop describes the federal advisory as covering 12. The widely repeated "30 systems" figure refers specifically to Minnesota, where state officials say more than 30 community water systems were targeted on July 26 and 27. Attribution to Iran remains unofficial: the Trump administration initially pointed to Iran-aligned hackers, but no US agency has formally attributed the campaign, and at least one vendor investigating it says the evidence points toward opportunistic mass exploitation rather than a state-run intrusion set.
What Happened
The first public signal came from Minnesota in late July, when state authorities described a "coordinated cyberattack" affecting more than 30 municipal water systems. BleepingComputer dates the Minnesota activity to a Sunday-through-Monday window; SecurityWeek pins it to July 26 and 27. Within days the pattern replicated elsewhere.
The FBI and EPA issued their joint PSA on July 30, confirming reports from utilities in at least seven states beginning July 27. CISA followed with an urgent sector alert warning of a significant increase in attacks on internet-exposed programmable logic controllers, noting that organizations of all sizes were affected, "including some with mature cybersecurity programs."
Publicly confirmed victims and jurisdictions accumulated through early August:
- Minnesota: more than 30 community water systems targeted (state officials).
- Michigan: officially confirmed a "small number" of affected communities; CyberScoop reports nine systems were hit.
- South Dakota: at least one city affected; CyberScoop specifies one wastewater lift station.
- Georgia: Clayton County Water Authority confirmed "a temporary disruption affecting a portion of its operational systems and water service," with reduced pressure in some areas and service restored within hours. Tenable added Columbus Water Works as a second confirmed Georgia victim on August 10.
- New Jersey: reported by Times Now as having disclosed a similar incident, though it is unclear whether it falls inside the FBI's seven-state count.
- Wisconsin: named in press coverage but has not confirmed any intrusions; several major utilities there said they were unaffected.
Accounts genuinely differ on scope. The FBI's own floor is seven states as of July 30; the 12-state figure originates with ABC News and is echoed by Tenable, Nextgov/FCW, SecurityWeek and CyberScoop. Only a handful of the affected states have been named publicly. Treat seven as the confirmed federal minimum and 12 as the press-reported upper bound.
One incident that should not be folded into this campaign: SecurityWeek notes a hacker attack on industrial control systems at a Utah oilfield saltwater disposal facility, but that intrusion was detected in March and appears unrelated.
What Was Taken
Nothing, in the conventional sense. This was not a data breach and no source describes exfiltration of customer records, billing data, or personal information. There is no record count to reconcile here because the campaign targeted availability and control, not confidentiality.
What the attackers took was operational authority over physical process equipment. Per the FBI PSA, after remotely accessing internet-facing devices the actors changed IP addresses and passwords, "resulting in a loss of monitoring and control functionality." CISA's bulletin describes the same pattern: passwords changed to lock operators out, IP addresses modified to disconnect devices, and configuration changes that disrupted operations.
The downstream physical impacts reported across sources include:
- Boil-water notices issued by affected utilities (CNN, CISA).
- Water pressure problems, including reduced pressure in parts of Clayton County, Georgia (Nextgov/FCW, SecurityWeek).
- Extended periods of manual operation, with some utilities switching to manual mode and taking systems offline (CNN, Nextgov/FCW).
- Flooding at affected sites, per Tenable's summary of reported operational impacts.
SecurityWeek notes that as of its reporting there had been no official reports of significant disruption to drinking water supply, and Nextgov/FCW reports state officials saying systems continued operating safely. CNN, citing analysts, nonetheless characterizes this as one of the most serious cyberattacks on US water systems in years. Both framings can be true: the safety envelope held, but only because operators fell back to manual control.
Why It Matters
The US water sector is structurally the softest critical infrastructure target in the country. Federal data cited by Times Now counts roughly 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities, the overwhelming majority of them small municipal operations with no dedicated security staff and no budget for one. A campaign that requires only a Shodan query and a default password scales across that population trivially.
The exposure numbers make the point. Censys, cited by BleepingComputer, estimated more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley controllers. Forescout's Vedere Labs, scanning via Shodan and publishing August 5, found over 4,000 exposed Rockwell and Allen-Bradley controllers, with 2,844 (65%) located in the United States and 22 sitting in cities already impacted by the water attacks. The two counts are broadly consistent and both were taken after federal warnings had already gone out.
CISA acting director Nick Andersen, speaking to Nextgov/FCW at Black Hat on August 6, said the agency was still finding controllers "open and accessible on the internet with either no password set or default password set." His assessment: "We're not making ourselves hardened targets."
The attribution question matters strategically. Tenable notes that while attribution remains pending federal investigation, the timing aligns closely with escalating Iranian-affiliated PLC exploitation documented in CISA Advisory AA26-097A. But Sai Molige, senior manager of threat hunting at Forescout, told CyberScoop the company has not attributed the activity to any actor: "The evidence supports opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices. The scale and speed of the activity are more consistent with mass scanning and enumeration than with zero-day exploitation, a months-long intrusion campaign, or custom malware." Times Now raises a third possibility that officials are reportedly weighing: another actor deliberately mimicking Iranian tradecraft.
For defenders, the practical implication is the same regardless of who is behind it. If a nation-state proxy and a bored opportunist can both reach your pumps with the same technique, the attribution debate is a policy problem, not a security one.
The Attack Technique
The FBI and EPA advisory is specific about the targeting. Malicious cyber actors are going after internet-exposed Rockwell Automation/Allen-Bradley MicroLogix PLCs, specifically the 1100 and 1400 series. The FBI cautions that while it has only observed this behavior against the referenced Rockwell devices, "similar considerations should also be made with other branded PLCs."
The sequence, as described across the federal advisory and CISA's bulletin:
- Discovery. Mass scanning and enumeration of internet-facing OT. CyberScoop notes the exposed devices speak EtherNet/IP, an industrial protocol that, when its port is open to the public internet, lets outside users fingerprint the device and, depending on configuration, change settings or write new configurations.
- Access. No exploit chain is described. Access came via devices with no password or default credentials still in place, per Andersen's direct observation.
- Lockout and disruption. Attackers changed device passwords and altered IP addresses, severing operator monitoring and control. CyberScoop reports that in at least one case attackers reached controllers remotely in this manner.
- Physical consequence. Loss of control translated into pressure loss, flooding, boil-water advisories, and forced manual operation.
CISA's bulletin flags an under-appreciated exposure path: internet-facing OT may include undocumented cellular modems installed by operators, vendors, or system integrators, meaning an asset inventory built only from the corporate network view will miss live attack surface entirely.
Notably absent from every source: any claim of zero-day exploitation, custom malware, or persistent implants. This was configuration abuse against devices that were never meant to face the internet.
What Organizations Should Do
- Remove PLCs and other OT from direct internet exposure now. This is the unified federal recommendation. CISA's phrasing to utilities was blunt: "Get your operational technology off the internet, set a password." Where full removal is not immediately possible, place access behind a VPN or secure gateway device and front it with a firewall.
- Inventory for shadow connectivity, not just known assets. Hunt specifically for undocumented cellular modems added by operators, vendors, or integrators, plus any EtherNet/IP service reachable from outside. Validate externally using Shodan or Censys against your own IP ranges and known facility locations rather than trusting internal documentation.
- Set strong, unique passwords on every controller. Default and blank credentials were the primary access vector. Rotate anything vendor-supplied and eliminate shared credentials across sites.
- Enforce access control lists. The FBI and EPA recommend an ACL permitting only authorized communication between expected control system devices, paired with IP allow-listing for any remaining remote access.
- Prioritize MicroLogix 1100 and 1400 series devices, then generalize. Treat these as the confirmed target set, but apply the same hardening to all vendors' PLCs given the FBI's explicit caveat. Owners of MicroLogix 1400 units whose passwords have already been changed should follow Rockwell's vendor guidance for recovering access.
- Rehearse manual operation and pressure-loss response. The utilities that avoided a safety event did so by dropping to manual mode. Confirm that procedure is documented, staffed, and exercised, and that boil-water notification workflows can be triggered without the affected control systems.
- Pursue available funding if you are a small system. New York announced more than $9 million in grants to help 153 water systems improve cybersecurity, per SecurityWeek. Comparable state programs are worth checking for utilities that cannot self-fund segmentation work.
Sources: Iran Behind US Water Hacks? 30 Systems Hit, FBI Warns Of Attacks Ac... | Malicious Cyber Actors Targeting Water and Wastewater ... | Minnesota Water Cyber Attack and CISA Advisory AA26-097A | CISA still finds water system controls exposed online amid multista... | CISA warns of cyberattacks disrupting U.S. water utilities | Water Sector Cyberattacks Reportedly Hit at Least 12 States - Secur... | Despite federal warnings, thousands of U.S. industrial controllers... | Sweeping cyberattack on water systems in multiple states has US off...