Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

42 Minute Watch Nolen Johnson |
Director of Hardware/OT Security, LevelBlue
Nikita Kazymirsky |
Principal Security Researcher, LevelBlue
Karl Sigler |
Senior Research Manager, LevelBlue

On July 2026, attackers exploited internet-exposed PLCs and a reused vendor configuration to gain access to 30+ water and wastewater utilities across multiple US states. The activity shares characteristics with prior Iranian-affiliated PLC intrusions referenced in CISA’s AA26-097A advisory, though attribution is not confirmed. 

Join Karl Sigler, Nolen Johnson, and Nikita Kazymirskyi for the technical mechanism, the exposure data, and remediation guidance direct from the researchers tracking this campaign, and Q&A.

You'll learn:

  • How a single reused vendor configuration let attackers scale access across 30+ unrelated utilities

  • Where attribution actually stands, and how that differs from the headlines

  • Remediation priorities for water and public sector OT: remote access, credentials, logic integrity, and vendor review.

Watch the Webinar

Related Resources

Current: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Resource: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Webinar

Inside MAD-CAT: How We Recreated the Meow Attack for Security Testing

Current: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Resource: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Webinar

Inside 1,500+ Incidents: When Trusted Tools Become Attack Vectors

Current: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Resource: resourceswebinarsttp-emea-briefing-q2-2026
Webinar

LevelBlue EMEA TTP Briefing Q2 2026