Cyberattack on America's Water: Hackers Strike Utilities in Seven States
- Oludare Ogunlana

- 5 days ago
- 4 min read

Hackers breached water systems in at least seven US states in late July 2026. The coordinated campaign forced utilities to issue boil-water notices, locked operators out of their own equipment, and pushed treatment plants into manual operation. Federal investigators are examining whether Iran-linked actors are responsible. No contamination has been reported. Nevertheless, the attack exposes a hard truth. America's water sector remains the softest target in the nation's critical infrastructure, and adversaries know it.
This article explains what happened, how the attackers got in, who may be behind the campaign, and what every utility, policymaker, and security leader must do now.
What Happened: A Coordinated Strike Across State Lines
The first public warning came from Minnesota. State officials reported that hackers targeted roughly 30 water systems across the state on the night of July 26 and into the morning of July 27. A memo from the
Minnesota Bureau of Criminal Apprehension assessed that the attackers likely intended to cause a loss of system pressure and potential contamination of the water supply.
Minnesota was not alone. The FBI and the Environmental Protection Agency issued a joint public service announcement confirming that water and wastewater utilities in at least seven states have reported incidents since July 27. Some of that activity degraded water operations. The Cybersecurity and Infrastructure Security Agency, known as CISA, described the campaign as a significant escalation in threat activity against the water sector.
The victims share a profile. Most are small and midsize utilities that serve local communities. These systems run on thin budgets, small staffs, and aging equipment. They rarely employ a single dedicated cybersecurity professional. In my opinion, that is precisely why the attackers chose them.
"The attackers did not need advanced tools. They walked through doors left open on the public internet."
How the Attackers Broke In
The attack method was simple. Water plants rely on small industrial computers called programmable logic controllers, or PLCs. Think of a PLC as the plant's automated operator. It controls pumps, monitors water pressure, and manages chemical dosing. When a PLC fails or falls into hostile hands, the plant loses its eyes and hands.
According to the FBI and EPA, the attackers targeted internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers. Many utilities connect these devices directly to the internet for remote monitoring convenience. The attackers found them, logged in, and took control. They then changed device passwords and altered IP address settings. Operators lost monitoring and control of their own systems.
CISA issued an urgent alert on July 30 directing utilities to remove exposed PLCs and other operational technology from the internet immediately. The agency added a critical warning. Even utilities with mature security programs should audit their external connections, because vendors and system integrators often install cellular modems that never appear in official asset inventories. You cannot defend a connection you do not know exists.
Who Is Behind the Campaign
Attribution remains unconfirmed, and precision matters here. However, the evidence points in a familiar direction. Security researchers at Tenable assessed that the operational pattern matches CyberAv3ngers, a hacking group linked to Iran's Islamic Revolutionary Guard Corps. The group's fingerprints include small water utilities, cellular-connected equipment, and opportunistic timing.
CyberAv3ngers has a history in this sector. In late 2023, the group compromised Unitronics controllers at US water utilities, including a water authority near Pittsburgh, and defaced devices with anti-Israel messaging. Moreover, a CISA advisory updated on July 22, 2026, documented Iranian-affiliated actors exploiting PLCs across US critical infrastructure since at least March 2026, including the theft of PLC project files and manipulation of embedded safety logic.
Minnesota investigators noted similarities in timing and targeted technology across incidents but have not confirmed that one actor carried out every intrusion. Therefore, leaders should treat attribution as probable but unproven. The defensive playbook does not change either way.
Five Actions Every Utility Must Take Now
The response framework is clear and achievable. Water utilities of every size should act on these five steps immediately:
Disconnect exposed devices. Remove every PLC and operational technology asset from direct internet access. If remote access is essential, place it behind a virtual private network with strong authentication.
Audit every external connection. Inventory all cellular modems and vendor-installed remote access points, including undocumented ones. Trust nothing you have not verified.
Eliminate default credentials. Change every factory password. Require strong, unique passwords and multifactor authentication for all remote access.
Prepare for manual operations. Train staff to run the plant without automation. The utilities that recovered fastest this week were the ones that could switch to manual mode.
Report incidents fast. Contact the FBI and CISA at the first sign of intrusion. Early reporting protects your neighbors, because these campaigns move from one utility to the next.
"Water is a national security asset. The nation must defend it like one."
The Bottom Line
The July 2026 water sector attacks were not sophisticated. That is the most alarming part. Adversaries achieved real operational disruption in seven states using exposed devices and weak credentials. The perception effect matters as much as the physical effect. When citizens question whether their tap water is safe, trust in government erodes. That erosion is often the true objective.
Policymakers must treat water security as national security. Utilities must close the open doors today. Business leaders who depend on reliable water service must ask hard questions of their local providers.
OSRS helps organizations meet this moment. Our team delivers critical infrastructure threat assessments, operational technology security reviews, incident response planning, and executive advisory services for utilities, government agencies, and private sector leaders. Contact OGUN Security Research and Strategic Consulting LLC at www.ogunsecurity.com to schedule a consultation before the next campaign finds your open door.
Found this analysis valuable? Share it with your network and help strengthen the defense of America's critical infrastructure. Subscribe to the OSRS email list for expert intelligence and security analysis delivered directly to your inbox.
Enjoyed this article? Stay informed by following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.
AUTHOR BIO
Dr. Sunday Oludare Ogunlana, Founder and CEO of OSRS, Professor of Cybersecurity. He advises intelligence, policy, and national security bodies globally and serves as a television commentator on national security affairs. Intelligence.




What are the six other states? Stop sensationalizing headlines.