CISA Confirms Hackers Targeted Over 100 US Water Systems in July
CISA says hackers targeted over 100 U.S. water systems in July, disrupting operations and exposing PLC risks involving Siemens, Rockwell and Schneider Electric.
Summary
On August 26, 2026, CISA confirmed hackers targeted more than 100 internet exposed U.S. water and wastewater systems during July, including providers in Michigan, Minnesota and at least five other states. The largely opportunistic attacks focused on programmable logic controllers, which operate physical machinery across water, energy and other critical infrastructure. Targeted equipment came from Rockwell, Schneider Electric and Siemens; some attacks used AI tools and public information to create scripts for vulnerable Siemens PLCs.
Water and wastewater supplies experienced little impact, but incident investigations caused outages and disruption. Hackers modified some PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without warning operators. Failures could have outsized effects in rural and isolated communities. U.S. intelligence considers Iran the likely perpetrator, possibly responding to the war against Iran led by the U.S. and Israel, but attribution remains unconfirmed. The campaign compounds concerns about Chinese malware planted in U.S. infrastructure for activation during a possible Taiwan invasion and Russian attacks on European water and energy systems viewed as testing NATO.
Positives
- Water and wastewater supplies experienced little impact despite the intrusions.
- Incident responders are investigating affected systems following outages and operational disruption.
- CISA identified more than 100 targets, affected PLC manufacturers and the use of AI assisted attack scripts.
Risks & concerns
- More than 100 internet exposed systems were targeted across Michigan, Minnesota and at least five other states.
- Modified PLCs could disable shutdown processes and alarms, creating unsafe conditions without notifying operators.
- AI tools used public information to develop attack scripts targeting vulnerable Siemens controllers.
- Rural and isolated communities could face widespread consequences from disruption to critical infrastructure.
- Iran is considered the likely perpetrator, but U.S. intelligence has not reached concrete attribution.