CISA says over 100 US water systems were targeted in July 2026 alone
Hackers are going for internet-connected PLCs, and CISA is urging agencies to take them off the public internet.
The Cybersecurity and Infrastructure Security Agency (CISA) has reported a surge in cyberattacks targeting US water systems in July 2026, with more than 100 exposed Programmable Logic Controllers (PLCs) coming under threat. These attacks have prompted organizations to change passwords, reassign IP addresses, issue boil water notices, and switch to manual operations.
While the source of these attacks remains uncertain, reports suggest a possible Iranian state-sponsored group may be behind them. CISA has urged water and wastewater facilities to remove publicly exposed PLCs and other operational technology (OT) from the internet to prevent further disruption and potential safety hazards to citizens.
The agency emphasizes the importance of strengthening security posture and resilience against these cyber threats.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- More than 100 water systems were hit in July cyberattacks theregister.com
- More Than 100 Water Systems Were Hit In July Cyberattacks it.slashdot.org
- CISA confirms hackers targeted over 100 US water systems during July techcrunch.com
- CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks securityweek.com