WASHINGTON

The U.S. cybersecurity agency CISA confirmed over 100 internet-exposed water and wastewater systems were targeted in cyberattacks during July 2026, part of a broader campaign against American critical infrastructure.

The attacks focused on programmable logic controllers—industrial systems that manage physical processes in water treatment plants, power grids and other essential services. Hackers leveraged AI tools to generate scripts targeting known vulnerabilities in PLCs from manufacturers including Siemens, Rockwell and Schneider Electric.

While the intrusions caused operational outages and disruptions, they resulted in minimal direct impact on water supplies to affected communities. However, CISA warned that prior related intrusions enabled attackers to modify PLCs in ways that could disable critical shutdown processes and alarms—potentially creating unsafe operating conditions without alerting operators.

Many targeted systems were in rural or isolated regions, where infrastructure disruptions can affect large populations with fewer redundant systems.

U.S. intelligence officials assessed that Iran was likely behind the attacks, characterizing them as probable retaliation for U.S. and Israeli military actions. Officials have not issued formal attribution.

The campaign underscores a pattern of nation-state actors using critical infrastructure as a testing ground. Chinese hackers have been documented planting destructive malware on U.S. infrastructure positioned for activation during geopolitical crises. Russia has conducted similar operations against European water and power systems, viewed as probes of NATO defenses.