Water and wastewater utilities across at least seven U.S. states reported cyberattacks targeting industrial control systems, with Minnesota, Michigan, and Georgia among the states disclosing incidents and Minnesota saying more than 30 community water systems were hit during July 26-27. Officials said some utilities switched to manual operations, and the FBI warned that some activity degraded water operations, although states reporting publicly said impacts were limited and drinking water safety was not significantly disrupted. The attacks reportedly focused on older internet-connected operational technology, particularly Rockwell Automation/Allen-Bradley PLCs, while government guidance also warned that Schneider Electric, Siemens, and other PLC brands could be at risk.
U.S. officials have not publicly attributed the campaign, but federal concern has centered on possible Iranian state-linked activity because the intrusions appeared disruptive rather than financially motivated. Reporting and prior threat intelligence have linked the activity to CyberAv3ngers, an IRGC-associated group previously tied to disruptive operations against water, manufacturing, and energy infrastructure, including the Municipal Water Authority of Aliquippa in Pennsylvania and water services in County Mayo, Ireland. OpenAI said it had earlier banned accounts assessed to belong to CyberAv3ngers after observing use of its models for reconnaissance, vulnerability research, code debugging, scripting help, and post-compromise tradecraft involving industrial control systems and PLC-related targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
23 events from the most recent confirmed update back to the earliest known activity.
A new Water Watch Center was launched at DEF CON in Las Vegas as a joint effort between the National Rural Water Association and DEF CON Franklin to provide direct cybersecurity mitigation support to small U.S. water utilities. The initiative initially enlisted five cybersecurity firms to help utilities serving fewer than 10,000 people respond to ongoing water-sector cyber threats.
Forescout reported that an August 3 scan found 4,407 internet-exposed Rockwell controllers worldwide, including 2,844 in the United States, and identified 22 exposed Rockwell PLCs in cities affected by the recent U.S. water utility incidents. It said it could not confirm those devices were compromised, but assessed that the reported attack effects could be achieved by changing IP addresses and setting passwords on already reachable controllers.
Several U.S. officials said U.S. intelligence agencies assessed that Iran was likely behind the coordinated cyberattack targeting more than 30 municipal water systems in Minnesota. The attribution added a new national-security dimension to the late-July water-sector incidents already under FBI investigation.
The FBI and EPA issued a public warning about cyber attacks on internet-exposed water and wastewater PLCs, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 devices. The alert disclosed technical details including changed PLC IP addresses and passwords, modified project files, ladder logic discrepancies, and operational impacts such as pressure loss and flooding.
By July 28, 2026, Minnesota IT Services confirmed that a coordinated cyberattack had affected more than 30 community water systems during July 26-27. The state also said no Minnesota city had an active request for residents to change water use at that time.
SecurityWeek reported that Cape May and Woodbine water systems in New Jersey and the Childersburg Water, Sewer and Gas system in Alabama were targeted on July 27 during the broader U.S. water-sector cyber campaign. New Jersey officials said the attacks disrupted only phone systems, while Alabama said industrial control systems were targeted without disrupting water service.
The FBI said that since 27 July 2026, water and wastewater utilities in at least seven U.S. states had reported cyber incidents to the bureau. The bureau said some of the activity degraded water operations.
Minnesota said more than 30 community water systems were targeted during 26-27 July 2026. State officials said experts identified the vulnerability quickly and worked with local communities to stop the activity.
A CISA advisory was updated on 22 July warning that Schneider Electric, Siemens, and potentially other PLC brands were being targeted by Iran-affiliated actors. The guidance was later referenced amid the 2026 U.S. water utility incidents.
Forescout's analysis said Maple Plain was among the Minnesota municipalities that experienced operational impacts during the coordinated late-July 2026 water-sector cyberattack. The report grouped Maple Plain with Plymouth, South St. Paul, and Braham as confirmed impacted communities.
Braham, Minnesota said a cyberattack shut down the operating controls for its well and water treatment plant, temporarily limiting supply to water stored in the town's water tower. Officials asked residents for a few hours on Monday to minimize water use while the outage was investigated, and said water quality was not affected.
OpenAI's report cited a December 2023 CyberAv3ngers-linked incident that disrupted water services in County Mayo, Ireland for two days. The event was described as another example of the group's attacks on water infrastructure.
OpenAI's report cited a November 2023 incident in which CyberAv3ngers compromised PLCs at the Municipal Water Authority of Aliquippa in Pennsylvania. The incident was presented as part of the group's known disruptive activity against industrial control systems.
Rockwell Automation updated its notice on restoring access to affected internet-exposed PLCs, expanding it from MicroLogix 1400 to also include MicroLogix 1100 controllers and adding hardening guidance to reduce future unauthorized lockouts. WaterISAC said the update responded to ongoing activity in which attackers changed PLC IP addresses and enabled passwords, locking operators out and causing loss of operator view.
OpenAI reported that it banned accounts it assessed as belonging to CyberAv3ngers, an actor publicly linked to Iran's IRGC, for using its models to support cyber research activity. The observed use included reconnaissance, vulnerability research, code debugging, scripting assistance, and post-compromise tradecraft related largely to ICS and PLC environments.
A new report says hackers accessed water controls in Coweta County, Georgia, adding another named victim to the late-July 2026 U.S. water-sector cyber campaign. This is distinct from previously documented Georgia impacts involving Clayton County Water Authority.
Georgia’s Clayton County Water Authority said a cyberattack temporarily disrupted part of its operational systems and water service in parts of north Clayton County. The utility issued a precautionary boil water advisory and later lifted it after completing water quality testing.
Georgia confirmed it was affected by the cyber activity and said the damage was limited. Officials said the activity was consistent with attacks previously reported in Minnesota.
At least one city in South Dakota reported a cyberattack that appeared linked to the same U.S. water-sector PLC tampering campaign affecting other states. The reference does not name the city or provide a more precise incident date.
Michigan said nine water systems notified the Department of Environment, Great Lakes, and Energy about hostile cyber activity consistent with the Minnesota incidents. The state said affected systems continued operating safely with no known public health impacts.
ABC News reported that possible cyber intrusions targeting water and wastewater utilities had been identified in at least a dozen U.S. states, expanding the known scope of the late-July campaign. Sources said the activity could disrupt operator visibility and operations by changing passwords or disabling alarms, though no widespread service disruptions were reported.
South St. Paul said it identified an issue early Monday affecting technology that supports portions of its water utility and moved public works staff to manual operations. The city said water and wastewater service, drinking water treatment, quality, pressure, and delivery were not affected, and it found no indication customer data was accessed.
In Plymouth, Minnesota, attackers compromised PLCs at two water towers and 14 lift stations during the late-July 2026 water-sector campaign. The city disconnected affected cellular network connections and restored normal operations by Tuesday.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
38 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcesecurityweek.com
Open sourcedysruptionhub.com
Open sourcecyberveille.ch
Open sourcefbi.gov
Open sourcewashingtonpost.com
Open sourceopenai.com
Open sourcecdn.openai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.