The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed in August 2026 that cyberattacks targeted more than 100 internet-exposed systems across the U.S. water and wastewater sector during July, offering new detail on the scale of an ongoing campaign against American critical infrastructure.
The attacks have affected water providers in Michigan, Minnesota, and at least five other states, with many of the targeted communities located in rural or isolated areas where infrastructure disruptions can impact large populations. CISA said the intrusions have largely focused on programmable logic controllers (PLCs) — devices that manage physical systems and machinery at water providers, energy facilities, and other critical infrastructure sites.
Hackers targeted PLCs manufactured by Rockwell, Schneider Electric, and Siemens, among others. CISA noted that some attacks used AI tools drawing on publicly available information to develop scripts capable of exploiting vulnerable Siemens PLCs. In certain cases, the intrusions allowed hackers to modify PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without alerting operators.
While the attacks have had little effect on water or wastewater supplies to local communities, they have caused outages and disruption as incident responders investigate the breaches.
U.S. intelligence officials believe Iran is likely responsible for the largely opportunistic attacks, possibly in response to the U.S. and Israel-led war against Iran, though officials have stopped short of a formal attribution.
The incidents have intensified broader concerns about the cybersecurity resilience of U.S. critical infrastructure. Officials have also previously warned that Chinese hackers have been placing destructive malware on critical infrastructure systems, and Russia has been linked to cyberattacks on water providers and power grids across Europe.
Source: TechCrunch