Join us at Black Hat and discover how we’re reshaping the cybersecurity landscape. Learn More

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

In light of the water-sector activity described below, we've increased monitoring for related indicators of compromise across our client environments. Please contact your LevelBlue account team with questions specific to your environment.

Executive Summary

Recent cyber activity against water and wastewater systems demonstrates the growing exposure of operational technology to state-affiliated, criminal, and opportunistic threat actors. The July 2026 campaign affecting more than 30 Minnesota water systems, together with related incidents reported in other U.S. states and Canada, shows that internet-facing PLCs, HMIs, cellular modems, remote-access services, and recurring third-party configurations remain critical points of weakness. Reported consequences included loss of visibility and automated control, pressure disruption, flooding, temporary reliance on stored water, and the need to operate facilities manually.

Attribution remains incomplete. The latest U.S. incidents share technical similarities with an Iranian-affiliated PLC-targeting campaign, but federal and state authorities have not publicly confirmed responsibility for the Minnesota activity. Recent Canadian cases further demonstrate that water-sector systems may also attract hacktivist and opportunistic actors seeking exposed interfaces and weakly protected remote access. Overall, the incidents highlight that meaningful operational disruption does not always require advanced ICS malware, as legitimate engineering tools, publicly available technical knowledge, and insecure configurations can provide sufficient access to critical processes.

 

Incident Overview

As of August 3, 2026, the available evidence indicates that U.S. water and wastewater operators are facing at least two closely related bodies of malicious activity. The first is an Iranian-affiliated operational technology campaign documented by the FBI, CISA, NSA, EPA, Department of Energy, U.S. Cyber Command, and Department of the Treasury in Joint Cybersecurity Advisory AA26-097A.

undefined-Aug-04-2026-12-24-33-8017-PM
Figure 1. CISA’s statement.

The second is a newly disclosed wave of attacks reported from July 27 onward, including a coordinated campaign against more than 30 Minnesota community water systems. Although the campaigns share important technical characteristics, the Minnesota incidents and the wider multistate activity have not yet been formally attributed to Iran or to a named threat group. They should therefore be assessed as potentially connected but not treated as conclusively part of the same operation. As of early August 2026, the cyber threat to the Water and Wastewater Systems Sector has moved beyond isolated ransomware events and opportunistic network intrusions toward coordinated activity capable of directly affecting physical operations.

On July 30, 2026, CISA warned of a significant increase in cyber threat activity targeting operational technology used by water and wastewater utilities. On the same day, the FBI and EPA reported that water and wastewater organizations in at least seven states had identified incidents since July 27, with some attacks degrading water operations. The most recently observed activity focused specifically on internet-facing Rockwell Automation and Allen-Bradley MicroLogix 1100 and MicroLogix 1400 programmable logic controllers.

According to the FBI, attackers remotely accessed exposed PLCs and changed their IP addresses and passwords. These changes prevented operators from viewing, monitoring, or controlling connected equipment. At least one affected organization also found modified PLC project files after identifying ladder logic discrepancies across several sites. The FBI further reported that common network configurations supplied by third-party providers appeared across multiple victims, potentially allowing the attackers to reproduce the same access method against several utilities using similar hardware and remote-access architectures.

The operational effects reported across the wider campaign included loss of water pressure and flooding. Pressure loss is particularly significant because a drop in distribution-system pressure can create conditions in which untreated groundwater enters damaged or poorly sealed pipes. The degree of impact depended on whether the affected controller was used only for monitoring or was directly controlling pumps, valves, wells, treatment equipment, alarms, or other physical processes. The ability of operators to switch quickly to manual procedures also appears to have limited the consequences at several facilities.

Public reporting does not currently indicate that attackers attempted to poison drinking water or intentionally manipulate chemical concentrations during the Minnesota campaign. No confirmed compromise of water quality has been reported by Minnesota authorities or the publicly identified municipalities. However, the incidents demonstrate that remote manipulation of comparatively small field controllers can interrupt treatment, pumping, telemetry, and pressure-management functions, creating conditions that may develop into public-health or environmental consequences even without an explicit contamination objective.

The immediate scale of the campaign is significant. Minnesota authorities confirmed that operational technology at more than 30 community water systems was targeted during coordinated attacks on July 26 and 27, 2026. By August 1, Michigan had identified activity affecting nine additional water systems, while the FBI reported related incidents from water and wastewater utilities in at least seven states. Not every compromise caused a service interruption but confirmed operational effects across the broader campaign included loss of pressure, flooding, communications outages, boil-water notices, and extended manual operation. The FBI warned that pressure loss can create conditions in which untreated groundwater may enter distribution pipes, demonstrating how apparently limited PLC manipulation can develop into a public-health concern.

Publicly identified victims illustrate the range of possible consequences. In Braham, Minnesota, attackers disabled operating controls associated with the city’s well and water-treatment plant, temporarily leaving the community dependent on water stored in its tower. In Plymouth, malicious activity disrupted cellular communications with two water towers and several lift stations, although operators maintained normal service through manual procedures and reported no impact on water levels or quality. South St. Paul separately confirmed that automated water utility controls had been affected, while drinking water safety and service availability were maintained. Michigan authorities similarly reported that all nine affected systems continued to operate safely and that no known public-health consequences occurred.

The latest multistate incidents are technically and temporally consistent with this previously documented activity. However, attribution of the July attacks remains under federal investigation, and no U.S. agency has publicly assigned responsibility for the entire campaign to a specific state or threat group. The available evidence therefore supports treating Iranian-affiliated involvement as a credible working hypothesis rather than a confirmed conclusion.

 

Minnesota Coordinated Campaign on Water Systems

Minnesota IT Services confirmed that a coordinated cyberattack targeted operational technology at more than 30 community water systems on July 26 and 27, 2026. The state activated its cybersecurity incident-response capabilities and coordinated with the Minnesota Department of Public Safety, Bureau of Criminal Apprehension, Minnesota Fusion Center, Department of Health, Pollution Control Agency, CISA, EPA, FBI, and local utilities.

Minnesota authorities emphasized that classification as an affected system did not necessarily mean that water service was interrupted. In many cases, investigators identified malicious interaction with technology used to monitor or remotely control equipment, while the associated physical process continued operating. State reporting also noted similarities in timing and the types of technology involved, but investigators had not established that one actor was responsible for every identified incident.

The identities of most affected systems have not been publicly released, likely because the investigation remains active, and disclosure could reveal vulnerable infrastructure. Four municipalities have publicly confirmed incidents:

  • Braham, Minnesota. Attackers disabled the computerized operating controls associated with the municipal well and water-treatment plant. For a limited period, the city relied on water already stored in its water tower and asked residents to minimize consumption. Operators restored the plant, and officials reported no effect on drinking water quality. Braham represents the clearest publicly documented example of the campaign producing a direct physical-process interruption.

  • Plymouth, Minnesota. The attack disrupted cellular communications with two water towers and multiple wastewater lift stations. The city disconnected affected equipment, used manual operating procedures, and restored communications by Tuesday afternoon. Officials reported no impact on water levels or water quality. The incident is important because it illustrates how cellular telemetry and remote field connections can provide an attack path that may not pass through the utility’s conventional IT perimeter.

  • South St. Paul, Minnesota. The city reported that the incident affected automated water-utility controls. Public Works personnel implemented contingency procedures and maintained water and wastewater operations. Drinking water remained safe, while staff worked to restore normal automated functionality.

  • Maple Plain, Minnesota. The city confirmed a cybersecurity incident involving its water environment but disclosed limited technical information. Officials stated that drinking water remained safe, water and wastewater services remained fully operational, and no action was required from residents.

The Minnesota incident was not isolated geographically. By August 1, Michigan authorities had identified activity affecting nine water systems. All nine continued operating safely, local operators addressed the issues, and no known public-health impact was reported. Public reporting also indicated possible related activity in Georgia, while the FBI’s official statement confirmed reports from at least seven states without publicly naming all affected jurisdictions.

 

Relationship to the Iranian-affiliated PLC Campaign

The Minnesota attacks occurred only days after the July 22 update to Joint Cybersecurity Advisory AA26-097A. That advisory describes an Iranian-affiliated APT campaign active against U.S. critical infrastructure since at least March 2026. The targeted sectors include water and wastewater systems, energy, government services, and municipal organizations. Federal agencies assessed that the actors intended to cause disruption by accessing internet-connected PLCs, extracting project files, modifying control logic, and manipulating data displayed on HMI and SCADA systems.

The previously documented Iranian-affiliated activity involved Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric BMX P34 and Modicon M340 devices, and Siemens S7-1200 PLCs. The actors used legitimate engineering applications, including Studio 5000 Logix Designer, EcoStruxure Control Expert, and Siemens TIA Portal, from leased third-party infrastructure to connect to misconfigured controllers and exfiltrate PLC project files. The observed traffic targeted common OT ports, including TCP 44818, 2222, 102, and 502, as well as SSH on port 22. In one case, the actors used Dropbear SSH on a victim modem to establish remote access.

After obtaining project files, the actors modified or deleted control logic, including Rockwell Add-On Instructions and equivalent function blocks. Federal investigators also identified manipulation of HMI and SCADA data and changes that disabled critical alarms and shutdown logic. At one victim, malicious logic preserved the appearance of normal downstream operation while overriding instructions responsible for maintaining safe operating parameters.

The new FBI warning concerning the late-July incidents identifies MicroLogix 1100 and 1400 controllers, which are different from the Rockwell product families specifically identified in AA26-097A. This distinction indicates either an expansion in targeted hardware, a separate actor using similar methods, or broader opportunistic scanning of exposed industrial devices. It also means that monitoring and defensive programs should not limit coverage to the CompactLogix, Micro850, Modicon M340, or Siemens S7-1200 products named in the earlier advisory.

LevelBlue defends your grid, plants, and pipelines from cyber disruption.

Learn More

The Dark Web Spotted Data Findings

Water and wastewater facilities have become increasingly attractive targets for cybercriminals, hacktivists, and state-aligned threat actors due to their critical role in public health, economic stability, and community resilience. Unlike traditional IT environments, operational technology (OT) systems within water utilities directly control physical processes such as water treatment, pressure management, pumping operations, and wastewater processing. As a result, successful cyber intrusions can produce visible real-world consequences, making these organizations particularly appealing for actors seeking disruption, publicity, or psychological impact.

undefined-Aug-04-2026-12-24-34-0825-PM
Figure 2. Dark web actor shares news related to a community water facility.

Within underground and dark web communities, attacks against critical infrastructure often generate significantly greater attention than conventional compromises of enterprise networks. Water facilities represent high-profile targets where relatively simple actions, such as disabling remote monitoring, modifying programmable logic controller (PLC) settings, or causing temporary service degradation, can result in media coverage, government response, and public concern. This provides threat actors with an outsized return on investment compared to attacks against less visible organizations.

 

Dark Web Community Interest on the Topic

Threat actors targeting industrial environments do not necessarily rely on advanced proprietary knowledge. Underground forums, Telegram channels, and dark web communities frequently circulate legitimate training materials, technical manuals, engineering software, configuration files, and practical tutorials related to PLC programming and industrial automation. An identified post advertising a comprehensive course on Allen-Bradley MicroLogix, CompactLogix, and ControlLogix systems illustrates how publicly available educational content can be repurposed to help inexperienced actors understand ladder logic, process control, troubleshooting, and the operation of RSLogix 500, RSLogix 5000, and LogixPro 500.

undefined-Aug-04-2026-12-24-34-8339-PM
Figure 3. Actor on a dark web forum shares tutorials related to PLCs.

Although the course itself is legitimate and intended for engineers, instructors, and students, its practical examples involving wastewater treatment and chemical process control may also provide malicious actors with useful background for interpreting exposed HMI screens, PLC projects, alarms, process variables, and controller logic. In underground environments, this knowledge may be combined with leaked credentials, stolen engineering project files, network diagrams, device documentation, screenshots, and remote-access details shared by other users.

This exchange of technical knowledge lowers the barrier to entry for opportunistic attacks against water and wastewater systems. Less sophisticated actors may not be capable of developing advanced ICS malware, but access to structured training, vendor software, and victim-specific data can enable them to identify exposed systems, understand basic process functions, modify controller settings, or exaggerate limited access for propaganda purposes. Monitoring should therefore include not only offers of direct access, but also the circulation of PLC courses, engineering software, project archives, HMI screenshots, and water-sector automation documentation.

 

Other Attacks on Water Systems Spotted on the Dark Web

On July 23, 2026, the pro-Russian hacktivist network NoName057(16) claimed that participants in its DDoSia project had gained access to a water system in Ontario.

NoName057(16) is a pro-Russian cybercrime and hacktivist network that has operated since 2022. Its primary capability has historically been distributed denial-of-service attacks against governments, financial institutions, transportation providers, utilities, media organizations, and other entities in countries that support Ukraine. The group coordinates supporters through messaging platforms and uses the DDoSia project to distribute attack instructions and provide incentives to participants.

undefined-Aug-04-2026-12-24-35-7913-PM
Figure 4. NoName057(16)’s Telegram claim translation.

In a Telegram post, the actor described a municipal pumping station with four main pumps, backup generators, and a monitoring interface that displays pressure, flow, and pump-start history. The group alleged that several pumps were failing to start, alarms were active, and system pressure was fluctuating.

undefined-Aug-04-2026-12-24-36-1471-PM
Figure 5. NoName057(16) claims that four pumps failed to start.

The claims describe access to an operational monitoring or control interface and possible interference with a physical water-distribution process. However, the publicly available evidence currently consists primarily of the actor’s own statements and accompanying imagery reproduced by Telegram-monitoring services. This material does not independently confirm that the interface was live or that the group caused the displayed pump and pressure conditions.

No public confirmation of the compromise, water outage, pressure-loss event, boil-water advisory, or drinking-water quality impact was identified from the region during this review. The incident should therefore be recorded as a claimed and currently unverified OT compromise, rather than a confirmed operational cyberattack. The absence of public confirmation does not prove the claim is false, since critical infrastructure operators may limit disclosure while an investigation is ongoing.

On the same day, July 23, 2026, another pro-Russian hacktivist group Z-Pentest, also referenced as Z-Pentest Alliance or Z-Alliance, claimed that it had gained access to the municipal drinking-water system serving Saint-Noël, a small community in Quebec’s La Matapédia Regional County Municipality.

Z-Pentest is a pro-Russian hacktivist group established in September 2024 by actors and administrators previously associated with the Cyber Army of Russia Reborn and NoName057(16). Unlike groups that concentrate primarily on distributed denial-of-service attacks, Z-Pentest specializes in opportunistic intrusions into operational technology and industrial control environments. Its operations commonly involve accessing internet-exposed HMIs and publishing screenshots or recordings to support pro-Russian messaging and attract media attention.

undefined-Aug-04-2026-12-24-34-3568-PM
Figure 6. Z-Pentest Telegram channel’s claim translation.

The actor published material describing the target as “Eau potable St-Noel” and reportedly released video evidence purporting to show access to the water treatment management environment. The cyberattack itself was subsequently confirmed by the Municipality of Saint-Noël and the MRC de La Matapédia. According to their official statement, malicious activity targeted the municipal drinking-water station at approximately 7:30 a.m. on July 23. The incident was detected shortly after 8:00 a.m. by the municipal employee responsible for operating the facility. The operator intervened with assistance from the MRC, which manages network and internet infrastructure for municipalities across the region. Normal and secure operation was restored, and the facility continued operating following the intervention.

undefined-Aug-04-2026-12-24-35-2942-PM
Figure 7. Screenshot from the Z-Pentest shared video illustrating access to the water treatment management environment.

Local reporting indicates that the attackers had access to the water management system for several minutes. Municipal personnel assessed the potential impact, identified and corrected the security weakness, and introduced additional protective measures intended to prevent a recurrence. The municipality stated that drinking water quality and public safety were not affected. No water-use restriction, boil-water advisory, treatment failure, or interruption of supply was reported.

The Ontario and Saint-Noël incidents illustrate different levels of confidence in pro-Russian activity against water infrastructure: the Ontario case remains an unverified NoName057(16) claim, while the Saint-Noël attack was officially confirmed, although attribution to Z-Pentest was not supported by publicly released forensic evidence. Both actors are generally opportunistic and less sophisticated than state-sponsored ICS groups, but their use of exposed HMIs, weak remote access, and default or compromised credentials can still create real operational risk. This is relevant to the recent U.S. water sector campaign because Iranian involvement in the latest incidents has not yet been confirmed. Pro-Russian hacktivists, unaffiliated actors, or multiple groups exploiting similar exposed systems should therefore remain part of the threat assessment until technical evidence supports a definitive attribution.

 

Attribution Assessment

Federal agencies have formally attributed the campaign described in AA26-097A to Iranian-affiliated APT actors. The advisory also references similar historical activity conducted by CyberAv3ngers, also known as the Shahid Kaveh Group, an actor affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command. CyberAv3ngers previously compromised at least 75 Unitronics PLC and HMI devices beginning in November 2023 and replaced legitimate ladder logic with malicious code.

However, neither the FBI nor Minnesota IT Services has formally attributed the July 26 and 27 Minnesota campaign to Iran, CyberAv3ngers, or another named actor. Investigators have reportedly considered Iranian involvement, given the timing, target selection, and similarity to previously documented PLC activity. Those similarities provide a credible attribution hypothesis, but they do not constitute sufficient public evidence for a definitive conclusion.

From an analytical perspective, the Minnesota campaign should therefore be described as unattributed malicious OT activity with technical and contextual similarities to the ongoing Iranian-affiliated PLC campaign. Describing the attacks as confirmed CyberAv3ngers or IRGC operations would exceed the evidence currently available in public reporting.

 

Likely Cause and Enabling Conditions

The publicly available evidence does not identify exploitation of a specific zero-day vulnerability or a newly disclosed CVE as the primary access method. Instead, both federal advisories describe internet-accessible PLCs, insufficiently protected cellular modems, weak or absent authentication, misconfigured remote-access paths, and inadequate network restrictions. The actors appear to have used legitimate PLC engineering software and standard industrial protocols rather than custom malware for the initial controller interaction. This supports an assessment that the immediate cause was insecure exposure and configuration, rather than exploitation of a single product vulnerability.

The FBI’s observation of similar third-party network configurations across several victims is particularly important. Water utilities frequently depend on external system integrators, equipment vendors, and telecommunications providers to install PLCs, cellular gateways, telemetry systems, and remote-maintenance connections. When the same exposed architecture, credential pattern, firewall rule, or modem configuration is reused across multiple customers, compromise of one design can be scaled across many geographically separate utilities.

The incidents also demonstrate the security limitations of legacy and end-of-life controllers. MicroLogix devices remain widely deployed because they are reliable, familiar to operators, and expensive to replace, but older equipment may have limited authentication, logging, encryption, and access-control functionality. Directly exposing such devices through public IP addresses or cellular connections allows attackers to bypass enterprise identity controls and interact directly with the physical process layer.

 

Remediations

The late-July incidents represent a significant escalation because the attackers did not merely compromise business systems or steal utility data. They directly interfered with devices responsible for monitoring and controlling physical infrastructure. The observed actions required no highly destructive industrial malware and, in several cases, appear to have depended primarily on exposed controllers, insecure cellular connectivity, and repeatable configuration weaknesses.

The limited public impact should not be interpreted as evidence that the attacks were harmless. Manual operating capability, available water-tower capacity, rapid local response, and the specific functions assigned to affected PLCs prevented more serious consequences. The same access to a controller responsible for pressure regulation, chemical dosing, pump sequencing, overflow prevention, or safety alarms at a larger industrial or power-generation facility could produce materially greater operational, environmental, and public-health effects.

The following remediation measures are intended to reduce immediate exposure, strengthen OT resilience, and limit the operational impact of future attacks against water and wastewater systems:

  • The first priority is to remove direct internet exposure from PLCs, HMIs, remote telemetry units, cellular modems, engineering workstations, and vendor-maintenance interfaces. Where remote access is required, it should be provided through a hardened VPN, jump host, Zero Trust access platform, private cellular APN, or another controlled gateway with authentication, logging, and strict access rules.

  • All default, shared, weak, or previously exposed credentials should be changed immediately. Each device and account should use unique credentials, while multifactor authentication should be enforced at the remote-access gateway whenever the underlying OT device does not support it. Standing remote access should be replaced with time-limited, approved access wherever possible.

  • Organizations should verify the integrity of PLC project files and running logic against known-good engineering copies. Reviews should cover ladder logic, Add-On Instructions, function blocks, alarms, shutdown logic, network settings, passwords, and input or output configurations. Backups should be validated before restoration to avoid reintroducing malicious changes.

  • After the running logic has been verified, controller mode switches should be placed in the Run position where supported. Program or Remote mode should be enabled only during authorized maintenance. Software-based programming protection should also be applied to devices without physical mode switches.

  • Utilities should review the full remote-access chain, including modems, routers, firewalls, VPN appliances, HMIs, SCADA servers, engineering workstations, and vendor infrastructure. Investigations should look for unexpected password changes, IP address changes, project uploads or downloads, controller mode changes, and connections from unfamiliar hosting providers or foreign infrastructure.

  • IT and OT environments should be segmented through industrial firewalls and controlled intermediary zones. Engineering workstations should not have unrestricted internet access, and industrial protocols should be limited to approved source and destination pairs. Unused services such as Telnet, FTP, RDP, VNC, unnecessary web administration, and SSH should be disabled.

  • Third-party access should be reviewed as a high-priority risk area. Utilities should require integrators, telecommunications providers, and equipment vendors to document all remote connections, public IP addresses, privileged accounts, and cellular services. Shared credentials and identical customer configurations should be prohibited.

  • Operational resilience should be strengthened through verified offline backups and tested recovery procedures. Utilities should maintain the ability to manually operate wells, pumps, valves, lift stations, treatment processes, and other essential equipment when automation or telemetry is unavailable.

  • Legacy and end-of-life equipment should be placed into a documented replacement or isolation program. Where immediate replacement is not possible, compensating controls should include network isolation, gateway-mediated access, strict allowlisting, enhanced monitoring, and a defined retirement date.

  • External exposure, credential leakage, and dark web monitoring should include utility names, domains, remote-access systems, PLC families, engineering software, project files, ladder logic, cellular modem credentials, and system-integrator access. Findings involving controller addresses, project archives, network diagrams, or screenshots of live control systems should be treated as high-priority indicators.

  • Each utility should maintain an OT-specific incident response plan. The plan should cover safe isolation of affected equipment, transition to manual operation, evidence preservation, vendor coordination, public-health assessment, and communication with federal and state authorities. Regular exercises should include operators, IT teams, engineers, leadership, emergency management, and third-party providers.

 

Conclusions

The current threat landscape shows that water sector cyber risk extends beyond ransomware and corporate IT compromise. Threat actors are increasingly targeting PLCs, HMIs, remote-access systems, and other technologies that directly control pumps, treatment processes, pressure, telemetry, and alarms. In many cases, direct internet exposure, weak authentication, legacy equipment, and poorly managed third-party access are sufficient to enable intrusion without advanced malware or zero-day vulnerabilities.

The incidents also show that relatively unsophisticated actors can increase their capability through publicly available PLC training, engineering manuals, leaked project files, vendor software, and underground knowledge sharing. Water utilities should therefore account for state-sponsored actors, pro-Russian hacktivists, cybercriminals, access brokers, and opportunistic groups, while prioritizing OT isolation, secure remote access, logic validation, network segmentation, third-party controls, offline backups, and manual operating capability.

The limited public health impact observed so far should not be interpreted as low risk. Rapid detection and manual intervention prevented more serious consequences, but similar access to chemical dosing, pressure control, pump sequencing, or alarm logic could cause significant operational, environmental, and public safety effects.

ABOUT LEVELBLUE

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

https://www.levelblue.com/resources/blogs/internal-blog/how-to-create-a-blog-post/

Latest Intelligence

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo