CISA Confirms 100+ US Water Systems Hacked in July Amid Iran-Backed Cyberattacks

TL;DR
- CISA confirmed in late August 2026 that more than 100 U.S. water and wastewater systems were targeted by cyberattacks in July, marking one of the largest coordinated campaigns against water infrastructure to date.
- The wave of intrusions has been linked to suspected Iran-backed threat actors exploiting known vulnerabilities in internet-exposed industrial control systems, though investigations into attribution are ongoing.
- In response, CISA and federal partners have issued emergency directives, deployed incident response teams, and are pushing for mandatory cybersecurity standards for water utilities nationwide.
A Record-Breaking Month for Water System Intrusions
In a stark warning about the fragility of American critical infrastructure, the Cybersecurity and Infrastructure Security Agency confirmed this week that hackers targeted over 100 water systems across the United States during July 2026. The disclosure, made in an advisory released on August 22, represents a dramatic escalation in both scale and frequency compared to previous years, where water utility attacks were typically isolated incidents.
According to CISA, the campaign affected municipal water authorities, rural water districts, and wastewater treatment facilities in multiple states. While officials said there is no evidence that any attack resulted in unsafe drinking water reaching the public, several utilities reported operational disruptions, including forced manual operation of treatment processes, temporary loss of remote monitoring capabilities, and defacement of human-machine interfaces.
CISA Director Madhu Gottumukkala described the July wave as a "concerted and persistent effort" to probe and disrupt systems that directly impact public health and safety, adding that the agency is working around the clock with affected utilities to contain the intrusions and restore secure operations.
The Suspected Iran Connection
Federal officials and private-sector threat intelligence firms have linked the surge to heightened geopolitical tensions and retaliatory cyber activity suspected to originate from Iran-affiliated hacking groups. The timing coincides with escalating conflict in the Middle East in June and July, which cybersecurity analysts say has historically triggered a spike in state-sponsored attacks on U.S. critical infrastructure.
CISA noted that many of the July incidents share tactics, techniques, and procedures consistent with known Iranian state-sponsored actors, including the exploitation of default credentials and known vulnerabilities in programmable logic controllers and other operational technology equipment. Groups previously associated with targeting Israeli and U.S. water systems, such as CyberAv3ngers, have been named in independent analyses, though CISA has not publicly attributed the campaign to a specific group.
Analysts caution that attribution remains complex and ongoing, with the FBI and intelligence community still investigating. However, the pattern mirrors a well-documented playbook: targeting under-resourced, internet-exposed industrial control systems as a low-cost, high-visibility way to signal capability and intent.
Why Water Utilities Are So Vulnerable
The attacks have once again exposed the long-standing cybersecurity gaps plaguing the nation's approximately 150,000 public water systems. Unlike the energy or financial sectors, the water sector is highly fragmented, dominated by small and medium-sized utilities that often operate with limited budgets, aging equipment, and few dedicated cybersecurity personnel.
Investigators found that many of the compromised systems shared common weaknesses. These included operational technology devices directly exposed to the public internet without a firewall, unpatched software with known vulnerabilities, factory-default passwords that were never changed, and a lack of multi-factor authentication for remote access.
Many water plants still rely on legacy control systems designed decades ago for reliability and availability, not for security in an internet-connected environment. When these systems were later connected for remote monitoring and efficiency, they inadvertently created entry points for attackers. CISA's advisory stressed that in numerous July incidents, basic cyber hygiene measures could have prevented the initial breach.
Federal Response Shifts Into High Gear
In the wake of the disclosures, the federal response has been swift and multi-pronged. CISA issued an emergency directive requiring federal agencies and urging all water and wastewater systems to immediately disconnect vulnerable operational technology from the internet, audit remote access configurations, and apply available patches.
The agency has also deployed its Hunt and Incident Response Teams to assist the hardest-hit utilities, released new Indicators of Compromise and detection signatures, and added free vulnerability scanning services specifically for water utilities through its Critical Infrastructure program.
On Capitol Hill, the attacks have reignited calls for enforceable cybersecurity regulations for the water sector. Currently, water utilities follow voluntary guidelines, unlike electric utilities which face mandatory standards. Lawmakers from both parties have introduced proposals to empower the Environmental Protection Agency to set baseline requirements, a move supported by CISA but opposed by some industry groups citing cost concerns.
The White House National Security Council confirmed it is coordinating with CISA, the EPA, and the FBI on a longer-term resilience strategy, which is expected to include increased funding for cybersecurity grants to small utilities and accelerated deployment of sensors to improve early threat detection across the sector.
What Happens Next for Water Security
CISA warns that the threat is far from over. Even as July's intrusions are being remediated, the agency says it continues to see active scanning and attempted exploitation of water system infrastructure in August.
For utility operators, the message is clear: assume compromise and act now. CISA is urging all water systems — regardless of size — to immediately implement its recommended mitigations, enroll in its free monitoring services, and report any suspicious activity.
For the broader public, officials emphasize that while the July campaign did not compromise water safety, it served as a powerful proof-of-concept for adversaries. Securing the nation's water supply will require sustained investment, modernization of control systems, and a shift from voluntary best practices to a more robust, mandatory security posture before a disruptive attack succeeds.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!