Threats

Water Sector Cyberattacks Hit 12 US States

August 6, 2026 04:25 · 12 min read
Water Sector Cyberattacks Hit 12 US States

The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. At least 12 states have been hit, according to reports, but the names of only a handful of the affected states are currently known.

Confirmed Attacks in Multiple States

Minnesota was the first to report attacks, with more than 30 community water systems targeted on July 26 and 27. Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity. At least one city in South Dakota has also reported a cyberattack that appears to be part of the same campaign.

The latest to provide official confirmation of attacks is the Clayton County Water Authority in Georgia, which said it “experienced a temporary disruption affecting a portion of its operational systems and water service”. The incident resulted in reduced water pressure in some areas, but water service was restored within hours.

FBI Investigation and Impact

As of July 30, the FBI had officially confirmed that at least seven states had been affected. The agency said in a cyber alert that the attackers had targeted Micrologix programmable logic controllers (PLCs) made by Rockwell Automation. There have been no official reports of significant disruption, and drinking water has remained safe.

However, the FBI has shared some details on the attackers’ actions and the potential impact. The agency explained: “MCAs [malicious cyber actors] are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities.

Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.

Potential Attribution and Mitigation Efforts

The US has yet to officially say who is behind the attacks, but Iran immediately emerged as the primary suspect as its hackers have been known to target ICS/OT, including in the water sector. Federal investigators have been reportedly looking into Iran’s potential involvement, and a non-public report from WaterISAC, which serves as the information-sharing organization for the water sector, reportedly cited evidence that the attacks were “aligned” with hacking campaigns previously linked to Iran.

CISA urged the water sector to protect OT systems, specifically PLCs. In addition, federal agencies have updated an April advisory on Iranian attacks aimed at OT devices, warning that ICS devices made by Siemens, Schneider Electric, and Rockwell Automation have been targeted.

Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, but it’s unclear how many are actually vulnerable to attacks. Infracritical has made available a report that summarizes all of the currently known technical information for the OT security community and defenders.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free