site-logo
site-logo
site-logo

Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology

Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology

Threat intelligence update: Multistate cyber campaign targeting US water and wastewater sector Operational Technology

blog-details-image
author

Prayukth K V

Campaign overview

Beginning on July 26, 2026, a coordinated cyber campaign targeted various Operational Technology (OT) and Industrial Control Systems (ICS) across the U.S. Water and Wastewater Systems (WWS) sector. Initial intrusions compromised over 30 municipal water utilities in Minnesota. As of late July and early August 2026, the threat actors expanded the campaign to encompass water and wastewater facilities in at least seven U.S. states, including Michigan and Minnesota.



This is no ordinary campaign. Instead this is an attempt by the threat actor to demonstrate that it can breach critical systems in US critical infrastructure.

The persistence, coordination, and geographic expansion of this campaign indicate a potentially significant shift in the global threat landscape surrounding critical infrastructure. Rather than isolated disruptive events, these operations increasingly resemble strategic multi-phased campaigns designed to achieve both operational disruption and long-term access to OT environments. If this trend continues, attacks against critical infrastructure are likely to become an increasingly common instrument of statecraft, with nation-state and state-aligned actors leveraging cyber operations to shape geopolitical outcomes before, during, and after periods of international tension. This evolution underscores the need for critical infrastructure operators to assume that cyber reconnaissance, pre-positioning, and operational disruption are no longer isolated risks, but integral components of modern geopolitical competition.

The primary tactical objective observed in these intrusions is the direct exploitation and manipulation of internet-facing Programmable Logic Controllers (PLCs) specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers in addition to CompactLogix, Micro850, and residual legacy devices. Threat actors remotely accessed exposed industrial interfaces, systematically altered device administrative passwords, modified IP configurations, and downloaded tampered ladder logic project files.

These actions resulted in a simultaneous Loss of View and Loss of Control for plant operators, forcing multiple municipalities to immediately disconnect automated SCADA links, trigger physical safety cutoffs, and transition to emergency manual operations.

Significance of this incident

The WWS sector represents one of the most structurally vulnerable components of U.S. critical infrastructure. Unlike energy or defense industrial sectors, municipal water infrastructure in the U.S. is highly decentralized, comprising over 50,000 community water systems. Most are managed by small local utility districts operating under tight municipal budgets with limited dedicated cybersecurity staff.

This campaign underscores three key systemic risks:

  • Pervasive direct internet exposure of Level 1/Level 2 OT Devices: Unshielded PLCs running legacy industrial protocols (e.g., EtherNet/IP, CIP, Modbus TCP) without native cryptographic authentication remain accessible via public scanning engines like Shodan and Censys.

  • Low-complexity/high-impact tradecraft: Adversaries achieved operational disruption across dozens of physical plants without deploying sophisticated zero-day exploits or custom OT-tailored malware modules.

  • Cascading public safety and operational risks: Disruption of automated dosing pumps, wellhead controls, and lift station telemetry directly threatens hydraulic line pressure. Loss of pressure risks inducing back-siphonage and groundwater infiltration into distribution networks, necessitating boil-water advisories and physical intervention.

Key findings

  • Primary Target Vector: Internet-accessible industrial controllers lacking Multi-Factor Authentication (MFA), relying on default or weak administrative credentials, or susceptible to unpatched vulnerabilities (e.g., CVE-2021-22681).

  • Attacker Methodology: The actors execute direct industrial protocol sessions (EtherNet/IP on TCP port 44818) to reconfigure network parameters, lock out legitimate operators by changing PLC access passwords, and upload altered project files to halt well pumps and water treatment processes.

  • Attribution Status: Joint warnings from CISA, the FBI, the EPA, and state fusion centers highlight strong tactical alignment with Iranian state-sponsored threat actors—specifically groups operating under the banner of CyberAv3ngers (affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command - IRGC-CEC). However, formal federal attribution remains under active investigation without conclusive forensic finality.

  • Public Health Impact: Prompt physical fail-safes and operator interventions prevented chemical imbalance or public water contamination. Operational impacts were restricted to localized pressure loss, well shutdowns, and forced manual control workarounds.

Evolution from early Minnesota incidents to multi-state campaign

The July 26–27 intrusions in Minnesota marked the initial phase of a broader, systematically executed campaign across the U.S. heartland.

Operational Metric

Initial Minnesota Incidents (July 26–27, 2026)

Multistate Campaign Expansion (Late July–August 2026)

Geographic Scope

Localized to Minnesota (Plymouth, Braham, Maple Plain, South St. Paul).

At least 7 states (including Minnesota, Michigan, and midwestern/central facilities).

Target Volume

~30 public water systems.

Dozens of distinct water and wastewater facilities across multiple state jurisdictions.

Hardware Focus

Primarily Rockwell Allen-Bradley MicroLogix 1100/1400 PLCs.

Expanded target set including Rockwell CompactLogix, Micro850, Schneider Electric, and Siemens PLCs.

Primary TTPs

Password resetting, IP address tampering, turning off well pump logic.

Automated network scanning, ladder logic modifications, HMI display vandalism/blackouts.

Operational Impact

Isolated wellhead shutdowns (~1.5 hours in Braham, MN), local telemetry disruptions.

Widespread loss of view/control, lift station overrides, boil-water notices, extended manual operation shifts.

Defensive Coordination

Local public works response & Minnesota IT Services triage.

Federal interagency mobilization (FBI, CISA, EPA Joint PSAs), WaterISAC alerts, CISA Emergency Directives.

 

Strategic shift in attacker objectives

The progression from isolated incidents in rural Minnesota to a multistate campaign reveals a deliberate shift from opportunistic targeting to opportunistic mass-exploitation. Initial attacks in towns like Braham, MN (pop. ~1,700) appeared to be validation testing for automated script sets designed to lock out controllers. Once validated, the threat actor scaled the tradecraft across all exposed devices discoverable via Shodan or Censys queries filtering for port 44818 (EtherNet/IP) and specific vendor hardware strings.

The attacker's goal was not catastrophic physical destruction (e.g., over-pressurizing mains or altering chemical balances to cause acute toxicity), but rather widespread operational friction, psychological distress, and resource depletion across U.S. municipal public works departments.

Evidence-based attribution analysis: Iranian suspicions

Federal investigative bodies (FBI, CISA, EPA) and private threat intelligence firms have highlighted potential links to Iranian state-backed actors. However, analytical rigor demands a clear distinction between technical indicators, circumstantial intelligence, and confirmed forensic facts.

 

 

Confirmed forensic facts

  • Targeting vector: The attacks leverage internet-facing PLCs running unauthenticated industrial protocols.

  • Advisory timing: CISA updated Security Advisory AA26-097A on July 22, 2026, specifically warning of Iranian cyber threats actively targeting U.S. critical infrastructure PLCs. Intrusions commenced four days later on July 26.

  • Official interagency stance: The FBI, CISA, and the EPA issued a Joint Public Service Announcement on July 31, 2026, confirming ongoing intrusions against Rockwell MicroLogix controllers across seven states without assigning definitive, named nation-state attribution.

Intelligence assessments

  • State fusion Center and WaterISAC Directives: Leaked intelligence briefs and WaterISAC advisories indicate that the Minnesota Fusion Center identified operational TTPs matching historical IRGC-affiliated campaigns.

  • Tenable and Claroty analysis: Private OT security vendors noted that the operational tradecraft mirrors the playbook of CyberAv3ngers—an IRGC-CEC proxy group responsible for the November 2023 attacks on Israeli-made Unitronics Vision350 PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania.

  • Expanding target matrix: In 2023, CyberAv3ngers focused on anti-Israel messaging by targeting Unitronics devices. The 2026 campaign reflects a broader, platform-agnostic expansion targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment.

Geopolitical timing

The campaign coincides with heightened geopolitical friction between the United States and Iran in the Middle East. Historically, Iranian cyber operations function as an asymmetric retaliatory instrument, leveraging critical infrastructure intrusions to signal capability and impose economic costs without crossing the threshold of direct military conflict.

Counter-evidence and attribution ambiguity

  • Lack of Unique Custom Malware: The attacks rely entirely on native protocol interactions (EtherNet/IP commands, default password logins, unauthenticated web/telnet management interfaces). Because these techniques require low technical capability, any sophisticated actor, rogue hacktivist, or criminal syndicate could execute them using public scanning tools and Metasploit modules.

  • Conflicting Official Statements: On July 31, 2026, U.S. President Donald Trump publicly expressed skepticism regarding Iranian involvement, stating, "I don't think there was an Iranian cyberattack,"highlighting a disparity between preliminary executive intelligence briefings and ongoing forensic field investigations.

  • False-Flag Potential: Prominent hacktivist personas (such as Handala) frequently co-opt or exaggerate affiliations with nation-state cyber units to gain media visibility or cover commercial extortion operations.

Overall attribution confidence Level: MEDIUM

While the victimology, tradecraft, timing, and targeted technology strongly align with IRGC-affiliated operating patterns, direct forensic artifacts (such as unique threat-actor-controlled C2 infrastructure or digitally signed state-backed tools) have not been publicly released by law enforcement.

Threat actor profile and capability matrix

To evaluate all plausible threat vectors, the following table compares candidate groups using the MITRE ATT&CK for ICS framework.

Threat Actor Group

Affiliation / Background

Known Historical Attacks

Primary TTPs (ATT&CK for ICS)

Capability Assessment

Estimated Likelihood of Involvement

CyberAv3ngers

IRGC Cyber-Electronic Command (IRGC-CEC) proxy.

Municipal Water Authority of Aliquippa (2023); Israeli WWS infrastructure (2020–2023).

Direct Internet Access (T0886), Modify Parameter (T0836), Defacement (T0827), Default Credentials (T0812).

Medium:Skilled at script-driven exploitation of exposed field devices; limited native industrial protocol development.

HIGH

Handala Hack

Pro-Iranian Hacktivist / IRGC Front.

Israeli infrastructure, nuclear research centers, regional transport systems.

Data Exfiltration (T0803), Unauthorized Command Message (T0855), Remote System Discovery (T0846).

Low–Medium:Primarily web site defacements, wiper deployments in IT environments, opportunistic OT scanning.

MEDIUM

APT33 / Elfin

Iranian State-Sponsored (IRGC Aerospace Force).

Global aviation, energy, petrochemical sectors in US & Saudi Arabia.

Spearphishing (T0865), Exploitation of Remote Services (T0886), Software Packing (T0857).

High:Sophisticated IT/OT initial access broker; capability to deploy custom wipers (Shamoon variants).

LOW(Tradecraft lacks typical APT33 IT enterprise entry vectors)

Cyber Crime / False-Flag Actors

Independent cybercriminals / extortionists.

Opportunistic ransomware campaigns against municipal IT/OT networks.

Brute Force (T0809), Data Destruction (T0826), Impact Architecture (T0881).

Low–Medium:Rely on off-the-shelf exploit kits, automated botnets, access broker credentials.

LOW–MEDIUM

 

Technical reconstruction of the attack lifecycle

Because full forensic disk images and network packet captures (PCAPs) from all impacted municipal sites are restricted under active federal investigation, portions of this reconstruction represent an analytical hypothesis based on previous campaigns, CISA advisories, and FBI PSAs.

 

 

Initial access (observed)

Threat actors conducted automated reconnaissance targeting internet-connected IP ranges associated with rural and municipal ISPs. Queries searched for open TCP Port 44818 (EtherNet/IP - Common Industrial Protocol / CIP), TCP Port 502 (Modbus TCP), and TCP Port 80/443 (Embedded Web Servers).

Initial entry was gained via two primary vectors:

  • Unauthenticated / default credential login: Leveraging default administrative logins (e.g., admin/password or vendor-set defaults) on exposed MicroLogix 1100/1400 web and Telnet configuration interfaces.

  • Exploitation of known vulnerabilities: Exploiting legacy vulnerabilities such as CVE-2021-22681(CVSS 9.8)—an unauthenticated protocol-level flaw in Rockwell Logix controllers allowing remote attackers to send malicious CIP commands to modify device configurations and alter control logic without authentication.

Persistence and privilege escalation (observed)

The actors did not need to deploy local privilege escalation exploits or establish persistent web shells. Instead, persistence was achieved natively within the OT hardware:

  • Administrative Lockout: The attackers enabled password protection on previously unauthenticated controllers or changed existing administrative passwords.

  • IP Address Reconfiguration: Threat actors altered the local IPv4 parameters (IP address, subnet mask, default gateway) of the Ethernet network interface modules. This effectively severed communication between the PLC and the plant’s local SCADA Human-Machine Interface (HMI), locking local engineering staff out of their own field hardware.

Discovery and lateral movement (Analytical Hypothesis)

This is an analytical hypothesis based on previous campaigns.

In environments where the targeted PLC acted as an entry point to a dual-homed engineering workstation or gateway router, the attackers likely issued broadcast discovery frames (e.g., EtherNet/IP ListIdentitycommands) across internal subnet ranges (192.168.x.x / 10.x.x.x). This allowed them to identify adjacent field devices, lift station Remote Terminal Units (RTUs), and HMI nodes connected to the same flat Layer 2 network.

OT network access and SCADA Interaction (Observed)

Once direct CIP session communications were established, the attackers interacted directly with the controller's run-time memory:

  • Ladder Logic Modification: Attackers uploaded modified project files or directly overwrote bit memory addresses controlling output relays.

  • Forcing I/O Bits: By forcing Discrete Output bits connected to interlock relays, the attackers opened valve actuators and commanded high-capacity well pumps to shut down or run dry.

 

Telemetry disruption and manual recovery (observed)

The alteration of network settings created an immediate Loss of View on operator HMI displays. Standard alarm notifications failed to route to remote duty operators over cellular telemetry channels. Local utility personnel only became aware of the incident when physical water tower telemetry indicated dropping water levels or low pressure in municipal mains.

Recovery sequence:

  • Operators dispatched physical maintenance crews to remote wellheads and lift stations.

  • Engineers manually isolated the impacted PLCs by pulling Ethernet communication cables.

  • Hardware hard resets (factory dip-switch toggles / battery disconnects) were performed to clear corrupted memory and override updated passwords.

  • Backup ladder logic project files were reflashed onto the PLCs via direct serial connections (RS-232 / DF1 protocol) using local engineering laptops.

  • Operators maintained system operation using manual hand-off-auto (HOA) physical switches while network gateways were secured.

 

Detailed operational impact analysis

 

 

Loss of visibility and control

The primary operational impact across all seven affected states was the immediate loss of remote supervisory control. Modern WWS facilities rely on HMI screens (e.g., FactoryTalk View, VTScada, Ignition) to visualize tank levels, flow rates, chlorine residual levels, and pressure gradients across miles of piping. Severing PLC communication blinded operators, turning HMI displays gray or freezing dynamic process parameters.

Hydraulic and mechanical I=impacts

  • Pump shutdowns and Cavitation Risks: In Braham, Minnesota, the attack forced the primary municipal well and water treatment plant offline for approximately 90 minutes. Abrupt, unscheduled pump shutdowns induce hydraulic water hammer—a pressure surge capable of rupturing aging water mains.

  • System pressure drops: In several impacted utilities, pump halts caused distribution system pressures to drop below regulatory thresholds (typically 20 PSI). Low line pressure creates negative pressure zones, drawing untreated groundwater, soil contaminants, or agricultural runoff into supply pipes through sub-surface leaks.

  • Boil-water advisories: As a regulatory safeguard, utilities experiencing sustained pressure loss were required by state departments of health to issue mandatory boil-water notices.

Financial, regulatory, and public health consequences

  • Public Health: Due to fail-safe physical designs and rapid operator intervention, no chemical contamination or water poisoning occurred.

  • Financial Burden: Small municipal utilities face severe financial strain from emergency responder overtime, third-party forensic incident response retainers, hardware replacement costs, and mandatory water quality sampling campaigns.

  • Regulatory Compliance: Under the Safe Drinking Water Act (SDWA) and EPA Emergency Response Authorities, utilities face increased regulatory oversight, mandatory cybersecurity risk assessments, and potential civil liabilities for failing to address basic cyber hygiene.

Comparative analysis: Water Sector Threat Landscape

To understand how tradecraft is evolving, the 2026 multistate campaign is compared below against historical water sector cybersecurity incidents.

Incident

Primary Target

Vector / TTPs

Operational Impact

Threat Actor Attribution

Oldsmar, FL (2021)

Water Treatment HMI

Unsecured TeamViewer remote access; weak password protection.

Attacker attempted to increase sodium hydroxide (

) concentration to dangerous levels; manually corrected by operator.

Undetermined (Likely domestic opportunistic actor / insider).

Aliquippa, PA (2023)

Municipal Water Authority (Unitronics PLC)

Internet-exposed PLC; default password (1111); defacement screen deployed.

Booster station pump disabled; loss of telemetry; operator switched to manual control.

CyberAv3ngers(IRGC-CEC affiliated).

Volt Typhoon Campaign (2023–2025)

IT/OT Gateways, Routers, Firewalls

Living-off-the-Land (LotL), custom webshells, zero-day appliance exploits.

Pre-positioning within critical infrastructure networks for latent operational disruption.

Volt Typhoon(PRC State-Sponsored).

Multistate WWS Campaign (July–August 2026)

Rockwell Allen-Bradley PLCs across 7+ States

Protocol-level exploitation (CVE-2021-22681), direct CIP logic modifications, network lockout.

Multi-utility loss of view/control, wellhead shutdowns, hydraulic pressure drops, boil-water notices.

Suspected Iranian State / CyberAv3ngers(Under Active Investigation).

Key tradecraft evolution

  • Shift from HMI to Low-Level Controllers: Older incidents (such as, Oldsmar) relied on compromising the human interface layer (IT/HMI). The 2026 campaign bypasses HMIs entirely, interacting directly with Level 1 embedded PLCs via low-level industrial protocols.

  • Platform Expansion: Iranian threat actors have transitioned from targeting niche controllers (Unitronics) to mainstream global automation brands (Rockwell MicroLogix, CompactLogix, Schneider, Siemens), significantly broadening their blast radius.

  • Automated Scale: The transition from targeting individual utilities to launching automated, simultaneous multi-state scans demonstrates an increase in operational efficiency and coordination.

Comprehensive MITRE ATT&CK Mapping

Enterprise ATT&CK Mapping

Technique ID

Technique Name

Context / Observed Activity

T1190

Exploit Public-Facing Application

Exploitation of unpatched web modules or EtherNet/IP protocol flaws (e.g., CVE-2021-22681) on exposed PLCs.

T1078

Valid Accounts

Use of default administrative credentials to log into PLC management interfaces.

T1595

Active Scanning

Automated internet-wide scanning (Shodan/Censys) searching for exposed industrial ports (44818, 502, 80).

T1090

Proxy

Routing malicious traffic through commercial VPNs and compromised home routers to obfuscate source infrastructure.

ATT&CK for ICS Mapping

Technique ID

Technique Name

Context / Observed Activity

T0886

Remote Services

Remote connection directly to industrial field controllers over TCP port 44818.

T0812

Default Credentials

Exploitation of unverified default passwords on Rockwell MicroLogix controllers.

T0889

Modify Program

Uploading altered project files or corrupting ladder logic memory routines.

T0836

Modify Parameter

Changing local IPv4 configuration parameters and system clocks on PLCs.

T0827

Defacement

Overwriting HMI displays or LCD screen parameters on field controllers.

T0815

Control Network Architecture

Disruption of network boundaries by locking out legitimately configured SCADA channels.

T0829

Loss of Control

Disabling manual/automatic pump routines, freezing physical operational loops.

T0828

Loss of View

Severing telemetry paths between field PLCs and central operator HMIs.

 

Detection opportunities and threat hunting indicators

Expected technical indicators (IOC Indicators)

Note: Consistent with strict intelligence standards, the following indicators represent expected technical signatures, protocol signatures, and event IDs rather than fabricated hash values or disposable IP addresses.

 

 

Network and Protocol Signatures

  • EtherNet/IP Traffic Anomalies: Inbound TCP port 44818 traffic originating from external, routable internet IP addresses directly destined for internal OT subnets.

  • Unusual CIP Service Codes: High volume of Common Industrial Protocol (CIP) explicit messaging requests, specifically Service Codes associated with project downloads (0x4C), parameter modifications (0x4E), or identity reset requests.

  • HTTP/Telnet Access to OT Interfaces: Inbound HTTP (Port 80/443) or Telnet (Port 23) connections to MicroLogix 1100/1400 embedded web servers from non-engineering IP addresses.

Windows Event IDs (Engineering Workstation & SCADA Servers)

  • Event ID 4625: Failed logon attempts on SCADA HMI servers or Jump Boxes (indicates brute-force activity prior to PLC access).

  • Event ID 7045: A new service was installed on a SCADA host (indicates potential lateral movement or persistence tools).

  • Event ID 1102: Security audit log cleared on engineering workstations.

OT IDS & Network Security Monitoring (NSM) Rules

  • Suricata / Snort Rule Example:

Code snippet

alert tcp $EXTERNAL_NET any -> $HOME_NET 44818 (msg:"OT-POLICY Exposed Rockwell CIP Explicit Connection Attempt from Internet"; flow:to_server,established; content:"|6f 00|"; offset:0; depth:2; reference:cve,2021-22681; classtype:attempted-admin; sid:10002026; rev:1;)

  • Zeek / Bro Script Detection: Monitor for sudden changes in CIP device identity attributes (e.g., vendor name, serial number, or device IP configuration changing dynamically over wire capture).

 Multi-layered defensive recommendations

Recommendations are aligned with IEC 62443, NIST SP 800-82 Rev. 3, CISA Cross-Sector Cybersecurity Performance Goals (CPGs), and EPA/AWWA Guidance.

 

 

Urgent mitigation checklist for water utilities

Immediate Architecture Hardening (0–48 Hours)

  1. Eliminate Direct Internet Exposure: Verify through external attack surface management (EASM) scans that no PLCs, HMIs, or RTUs have public IPv4 addresses listening on TCP ports 44818, 502, 102, 23, or 80/443.

  2. Implement Secure Access Gateways: Place all remote access behind an industrial VPN gateway enforcing Multi-Factor Authentication (MFA) and granular Access Control Lists (ACLs).

  3. Change Default Credentials: Enforce unique, complex administrative passwords across all embedded PLC interfaces and SCADA software accounts.

  4. Physical Keyswitch Management: Set physical keyswitches on Allen-Bradley PLCs to RUN mode rather than REMOTE (REM) or PROGRAM (PROG) mode. This physically blocks unauthorized remote logic downloads or mode changes over the network.


 

 

OT Security architecture and SOC guidance (30–90 Days)

  • Network Segmentation (IEC 62443 / NIST SP 800-82): Enforce strict Purdue Model architecture. Firewall and isolate Enterprise IT (Level 3) from SCADA Supervisory Control (Level 2) and Field Process Controllers (Level 1).

  • Out-of-Band Backup Maintenance: Maintain offline, air-gapped gold-image backups of all PLC ladder logic project files (.ACD, .L5X formats) and HMI runtime configurations.

  • Fail-Safe Operational Continuity: Ensure mechanical relief valves, pressure switches, and manual Hand-Off-Auto (HOA) switches are physically wired independently of digital PLC outputs to preserve basic plant operations during cyber lockouts.

Strategic and geopolitical implications

Escalation of Asymmetric Geopolitical Conflict

The targeting of municipal water systems signals a continuing shift in state-sponsored cyber strategy. Rather than reserving capabilities for high-value military or defense targets, state-backed actors and proxy entities leverage low-complexity attacks against vulnerable public utilities to generate disproportionate psychological impact. These operations demonstrate capability, test crisis response mechanics, and create public concern without crossing thresholds that trigger direct military retaliation.

Systemic Risks Across Critical Infrastructure

The vulnerabilities exploited in this campaign—internet-exposed controllers, default credentials, and unpatched operational software—are not unique to the water sector. Identical hardware and network configurations exist across:

  • Energy and Natural Gas: Remote metering stations, pipeline valve actuators, and wellhead controllers.

  • Transportation: Traffic signal controllers, rail switching networks, and tunnel ventilation systems.

  • Manufacturing and Food/Agriculture: Environmental controls, pasteurization lines, and automated packaging systems.

Policy and governance mandates

The failure of voluntary cybersecurity guidelines to prevent widespread intrusions across small utilities will likely accelerate regulatory shifts. Expect federal regulatory bodies (EPA, CISA, TSA) to pursue binding cybersecurity mandates for water utilities, similar to the mandatory NERC-CIP standards enforced in the electric power sector. Achieving compliance, however, will require dedicated federal funding mechanisms to support resource-constrained municipal utilities.

References  

  1. TIME Magazine: What to Know About the U.S. Water Systems Cyberattacks (Published Aug 2, 2026).

Link: TIME Article

  1. Federal Bureau of Investigation (FBI) / EPA Joint PSA: Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions(Published July 31, 2026).

Link: FBI PSA Alert

  1. CISA Security Advisory AA26-097A: Iranian-Affiliated Cyber Threat Actors Targeting Internet-Facing Programmable Logic Controllers Across U.S. Critical Infrastructure (Updated July 22, 2026).

  2. CBS News / Associated Press: U.S. Investigating Cyberattack on Water Systems in 7 States, Including Minnesota and Michigan (Aug 1–2, 2026).

Link: CBS News Reporting

  1. Cybernews / WIRED Reporting: Iran Hackers Hit 30 Minnesota Public Water Systems in Coordinated Cyberattack (July 30, 2026).

Link: Cybernews Coverage

  1. National Vulnerability Database (NVD): CVE-2021-22681 Detail – Rockwell Automation Logix Controllers Unauthenticated Protocol Flaw.

  2. NIST Special Publication 800-82 Rev. 3: Guide to Operational Technology (OT) Security.

  3. ISA/IEC 62443 Standard Series: Security for Industrial Automation and Control Systems.


Key definitions

Confidence

Meaning

Confirmed

Supported by official statements or forensic evidence

High Confidence Assessment

Multiple independent sources align

Moderate Confidence Assessment

Strong analytical inference but incomplete evidence

Analytical Hypothesis

Based on previous campaigns and tradecraft, not confirmed

 

The persistence, coordination, and geographic expansion of this campaign indicate a potentially significant shift in the global threat landscape surrounding critical infrastructure. Rather than isolated disruptive events, these operations increasingly resemble strategic multi-phased campaigns designed to achieve both operational disruption and long-term access to OT environments.

Get Weekly

Resources & News

See How Our Industry-Leading OT Security Solutions Address Critical Security Challenges

You may also like

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.