The U.S. government has revealed that criminals targeted more than 100 internet-exposed water systems during July cyberattacks, marking the first time federal officials have quantified the scope of the digital intrusions. The campaign, widely suspected to have Iranian links, remains officially unattributed, though the Cybersecurity and Infrastructure Security Agency (CISA) disclosed the figure in a recent advisory. The attacks exploited programmable logic controllers connected directly to cellular modems, creating what the agency described as significant security risks.
The intrusions hit suspected Iranian targets at water and wastewater facilities across at least a dozen states, including mostly small, rural utilities in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. Federal and state officials have not identified all 12 states affected. While the 100-plus systems represent only about 0.5 percent of water utilities nationwide, the concentrated activity within a single month signals what one cybersecurity executive called test runs for a larger-scale assault. Just last week, five U.S. federal agencies warned that attackers are deploying AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities.
Matt Hartman, chief strategy officer at the Merlin Group and CISA's former acting head of cyber, said "the scale" stands out more than any individual incident. According to Hartman, the attacks point to a systemic vulnerability across the sector rather than isolated, unlucky targets, with much of the infrastructure running on operational technology "built for closed, physical environments" that was never designed to be reachable from the open internet. Cynthia Kaiser, senior vice president at Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, told reporters the activity appears to be a continuation of what's suspected to be Iran-affiliated actors targeting PLCs that underpin essential health, safety, and critical infrastructure across society.
Hartman explained that attribution in cyber incidents is inherently difficult and often takes time because adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems, forcing the government to be diligent before publicly assigning responsibility. The report notes that from a defender's perspective, the identity of the attacker matters less in the immediate term than understanding how the attacks are occurring and taking steps to stop them. John Gallagher, vice president at Viakoo, an OT and IoT cybersecurity provider, said the real threat is that these are test runs for a larger-scale attack, despite the relatively small fraction of utilities affected.
CISA recommended that organizations disconnect PLCs from the internet and ensure any remote access goes through a VPN or gateway device rather than connecting directly to the PLC. The agency also advised owner-operators to enable password protection—ideally multi-factor authentication—and change any default passwords, while ensuring that allowlist IPs only permit remote access from known engineering laptops or other critical operational technology assets. The guidance reflects CISA's focus on getting actionable information into the hands of water-sector operators quickly so they can defend their systems. For infrastructure operators still running decades-old control systems on public networks, the July wave serves as both warning shot and blueprint—closing the exposure gap will require not just technical fixes but a fundamental rethinking of how legacy equipment connects to the modern internet.

