A Campaign Spanning State to State
What began in late July 2026 with coordinated attacks against over 30 community water systems in Minnesota has transformed into a large-scale multistate campaign. According to ABC News, federal sources are now mentioning possible intrusions affecting at least twelve states, with public confirmations coming from Minnesota, Michigan, Georgia, South Dakota, as well as more recently from Alabama and New Jersey. The FBI, CISA, and the Environmental Protection Agency (EPA) are coordinating the investigation, and Iran is identified as the "primary suspect," with no official attribution as of yet.
The technical analysis published by LevelBlue (SpiderLabs) clarifies the timeline: on July 26 and 27, operators of over 30 community systems in Minnesota reported malicious activity targeting their operational technology (OT). By August 1, Michigan had identified activity affecting nine additional water systems, all maintained in secure service according to local authorities. On July 30, CISA issued an alert describing a "significant increase" in cyberattacks against the programmable logic controllers (PLC) in the water and sanitation sector.
Exposed PLCs Locked Remotely
The modus operandi is remarkably straightforward. According to CISA and the FBI, the attackers gain access to PLCs exposed directly to the Internet — primarily Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 — and then modify passwords to lock out operators and change IP addresses to disconnect the controllers. This manipulation deprives local teams of visibility and remote control.
The operational consequences have been varied but real. In Braham (Minnesota), the attackers disabled the computerized controls of the well and treatment plant, forcing the municipality to temporarily rely on water stored in its water tower and asking residents to reduce their consumption. In Plymouth (Minnesota), the attack disrupted cellular communications with two water towers and several pump stations. The most serious incident known to date involves Clayton County, Georgia, where the cyber activity caused a drop in pressure requiring a boil water advisory.
The FBI emphasizes that the loss of pressure can create conditions where untreated groundwater enters damaged pipelines — turning a simple manipulation of a small field controller into a potential public health risk. No confirmed contamination of drinking water, however, has been reported.
Iran, "Primary Suspect" in a Gray Zone Strategy
Attribution remains cautious. Several firms (LevelBlue, Blackswan Cybersecurity) note technical similarities with a campaign documented by federal agencies in the Joint Cybersecurity Advisory AA26-097A from July 22, 2026, which describes actors affiliated with Iran targeting Rockwell CompactLogix, Micro850, Schneider Modicon M340, and Siemens S7-1200 PLCs. The pro-Iran group CyberAv3ngers, already responsible for attacks against U.S. water infrastructure in 2023 (notably in Aliquippa, Pennsylvania), is cited as a possible candidate, along with the Handala group and the IRGC Cyber Electronic Command.
The Soufan Center places these strikes within a gray zone logic: the Iranian objective may not be to permanently incapacitate the U.S. — Tehran knows that American recovery capacity is strong — but to remind that American power does not immunize against Iran. The context involves the regional war of February 2026 and the ongoing escalation between the two countries. The attacks occur just days after the update of the federal advisory from July 22, suggesting either an extension of the targeted equipment, another actor using similar methods, or a broader opportunistic sweep of exposed industrial equipment.
An important point highlighted by researchers: the apparent low sophistication of the TTP does not exclude superior capability. As Markus Mueller (Nozomi Networks) notes, the adversary "deploys the necessary tactics to achieve their objective"; the lack of public claim differentiates it from the classic hacktivist playbook and could indicate an objective of mass disruption rather than propaganda.
Why the Water Sector Remains a "Low-Hanging Fruit"
The targeted industrial controllers have historically been designed for physical isolation and reliability, not for Internet exposure. Many lack multifactor authentication or encrypted communications, and their networking is often enabled by default, according to John Gallagher (Viakoo). Maintenance is frequently handled by field technicians or third-party integrators who install cellular modems, satellite links, or port redirections without informing the central IT/OT teams.
The figures expose the magnitude of the problem. The U.S. has about 170,000 drinking water and sanitation systems, largely small and decentralized, operating on OT installed by third parties with minimal security budgets. An operator serving 5,000 residents often has only one IT generalist to manage everything. The Canadian newspaper Cybersecurity Journal points out that Canada — with about 6,500 systems — shares the same exposure, and the Canadian Center for Cybersecurity issued a warning as early as April 2026 about the active recognition of state actors against critical infrastructure.
Federal Recommendations and Political Context
CISA recommends operators to:
- Disconnect PLCs from the Internet and require a VPN or gateway for remote access;
- Change default passwords and enable password protection;
- Whitelist IP addresses allowed to access remotely;
- Keep a clean backup of the PLC image in case of a lockout;
- Implement segmentation between IT and OT (Purdue model, industrial DMZ).
The EPA had proposed a rule that, according to experts cited by the Washington Post, "would have eliminated most low-hanging fruit," but it faced strong Republican opposition. The Soufan Center also points to budget cuts and personnel reductions at CISA during Donald Trump's second term, set against the backdrop of the 2020 election security controversy, which limited the implementation of the recommendations.
On the ground, voices are calling for concrete federal action. The Operational Technology Cybersecurity Coalition urges Congress to reauthorize and fund the State and Local Cybersecurity Grant Program, arguing that "without this extension, Congress is leaving small towns to fend for themselves against state actors like Iran."
A Signal That Exceeds Water
The water sector is not an anecdotal target. As Adam Ford (Zscaler) points out, "the willingness of malicious actors to interfere with the systems that support the water we drink underscores how quickly a cyber incident can become a public safety issue." Documented Iranian actors also targeted energy, government services, and municipalities, and disabled security alarms and shutdown logic on at least one victim, according to Blackswan Cybersecurity — an escalation beyond mere hacktivism.
The moment is interpreted as a capacity test. If the campaign remains unanswered at a significant cost to the attacker, analysts warn to expect escalation to a larger state, a different sector — energy, hospitals, transportation — or both. The window to harden these systems and raise the cost of the attack, concludes the Soufan Center, "is closing."