Full Breakdown
Wave of Cyberattacks Targets U.S. Water Systems
8/8/2026, 4:19:30 AM
Core Incident Overview
In late July 2026 a coordinated wave of cyber intrusions struck municipal water and wastewater utilities in at least a dozen U.S. states. Hackers accessed internet-exposed programmable logic controllers (PLCs)—the small computers that operate pumps, valves and chemical-dosing equipment. No drinking-water contamination was reported, and service was restored within hours.
Background & Context
PLCs were originally designed for isolated, on-site operation and many remain unsecured when connected to the public internet. Because there is no federal mandate requiring utilities to disclose cyber incidents, many breaches go unreported, leaving “low-hanging fruit” for adversaries, according to security analysts. Similar tactics were used in a 2023 campaign attributed to the Iran-aligned CyberAv3ngers, highlighting a persistent vulnerability in the nation’s water-infrastructure supply chain.
Data & Statistics
- The FBI logged attempts in seven states and confirmed intrusions in at least a dozen.
- Minnesota reported attacks on more than 30 community systems; Georgia’s Clayton County Water Authority, serving 300,000 customers, experienced a pressure drop that triggered a boil-water advisory.
- New Jersey utilities in Cape May County were offline for roughly 12 hours each.
- The EPA estimates ?150,000 public water systems nationwide, the majority small, locally run entities.
Official Statements & Responses
Federal agencies have urged utilities to remove direct internet connections from PLCs, implement strong passwords and firewalls, and be prepared to operate manually. The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) confirmed it is working with the affected utilities and federal partners to secure the systems. Local officials emphasized that water quality remained safe and that rapid manual response prevented service disruption.
Criticism & Opposition
- Governor Tim Walz said the attacks illustrate “what modern warfare looks like” and noted the lack of a plan to counter Iran-backed threats.
- Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition, warned that utilities are not required to disclose detailed breach information.
On-the-Ground Reports
- In Clayton County, the hack caused a temporary pressure loss and a boil-water advisory that was lifted within hours.
- Cape May and Woodbine officials reported that their largely non-automated systems allowed staff to react manually and restore service without water-quality impacts.
- No personal data or customer information was accessed.
Conflicting Reports & Gaps
Attribution remains disputed. Federal investigators have suspected Iran-backed actors but have not issued a definitive attribution. Some analysts link the tactics to the Iranian Revolutionary Guard’s CyberAv3ngers, while others caution that the methods could be mimicked by unrelated actors. The exact number of affected states varies across reports, with some outlets citing seven and others noting “a dozen.”
Verbatim Quote
- “We are taking every effort to protect and defend our water supply and production,” — Zach Mullock, Cape May mayor
What’s Next
The FBI continues to advise all critical-infrastructure operators to disconnect PLCs from the internet where feasible and to adopt hardened access controls. CISA has issued recommended upgrades, and the NJCCIC says it will keep working with utilities statewide to reduce risk. Ongoing investigations aim to clarify the source of the attacks and assess whether additional states will experience similar intrusions.
