More than 100 U.S. water and wastewater systems were compromised by cyberattacks in July 2026 [1], [2].
The breach reveals a critical vulnerability in national infrastructure, specifically how internet-exposed controllers can be manipulated to disrupt essential public services.
The attacks targeted programmable logic controllers (PLCs) that were connected to cellular modems [2], [3]. These controllers are essential for managing the mechanical processes of water treatment and distribution. According to reports, the attackers utilized AI-generated exploits to penetrate these systems [3].
The campaign spanned at least a dozen states [1], [2]. Federal officials have now provided a specific number regarding the digital intrusions, though they have not yet linked the activity to a specific group [1].
While no formal attribution has been made by the U.S. government, the campaign is widely suspected to be linked to Iran [1], [2]. A CISA spokesperson said, "That's the first time the feds have put a number on the digital intrusions, but they have yet to attribute the campaign, widely suspected to be linked to Iran, to a particular group."
The use of artificial intelligence to create exploits marks a shift in the methodology of these attacks. By automating the discovery of vulnerabilities in PLC hardware, attackers can scale their operations more rapidly than through manual probing.
Industry experts expressed concern that these incidents may not be the end goal of the attackers. One industry expert said, "Experts warn it's just a test run."
The vulnerability stems from systems being internet-exposed, allowing external actors to find and target controllers that lack robust security layers or are running outdated firmware. This exposure creates a direct path for remote actors to access the operational technology that governs water flow and chemical levels [2], [3].
“More than 100 U.S. water and wastewater systems were compromised by cyberattacks in July 2026.”
The integration of AI into cyber warfare allows adversaries to identify and exploit hardware vulnerabilities in critical infrastructure at a speed and scale previously unseen. The targeting of PLCs suggests a move toward operational technology (OT) attacks, which can have immediate physical consequences on public health and safety, rather than simple data theft.



