Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.

August 10, 2026

Cyberattacks against water and wastewater systems reportedly have reached at least a dozen states, with threat actors exploiting low-complexity attacks against industrial controllers. The intrusions, possibly linked to the Iranian government, prove the US's water infrastructure remains dangerously exposed.

In recent weeks, water and wastewater organizations associated with a number of different US states have disclosed cyberattacks against their systems. Minnesota was the first to confirm such attacks late last month, saying that cyberattackers targeted operational technology (OT) systems for more than 30 water systems. Around the same time on July 30, the Cybersecurity and Infrastructure Security Agency (CISA) updated an earlier advisory warning of "a significant increase in cyber-threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector."

Related:Minnesota Water Utility Attacks Expose Sector's Cyber-Risks