Key Judgments
- [CONFIRMED] – The United States operates more than 150,000 public water systems, the large majority managed at the city, county, or local level with no central coordinating authority – a structural fragmentation that leaves cybersecurity investment and incident response capability wildly uneven from one system to the next.
- [CONFIRMED] – EPA’s most recent Drinking Water Infrastructure Needs Survey puts the 20-year investment requirement at $625 billion, two-thirds of it for pipe replacement and distribution infrastructure alone; ASCE’s 2025 Infrastructure Report Card grades US drinking water infrastructure C- and wastewater infrastructure D+, with average pipe age now 45 years, up from 25 years in 1970.
- [CONFIRMED] – Beginning July 26-27, 2026, a coordinated cyberattack campaign targeted internet-facing programmable logic controllers (PLCs) – specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series units – at water and wastewater utilities across at least 12 states, with the New York Times separately reporting at least 100 facilities targeted nationally and CSIS independently confirming the location of 55 of those through open-source research. CISA had issued a specific advisory warning of this exact exploitation pattern four days before the campaign began.
- [CONFIRMED] – No incident in the July 2026 campaign resulted in confirmed water contamination or a verified public health impact. The most severe documented consequence was a temporary water pressure drop and precautionary boil-water advisory in Clayton County, Georgia, which was lifted after testing confirmed water quality was unaffected; in Braham, Minnesota, operators restored manual control of the town’s well and treatment plant within approximately two hours of the intrusion being detected.
- [ASSESSED] – Multiple sources point to Iran-linked threat actors as responsible for the July 2026 campaign, consistent with a documented pattern of Iranian-affiliated groups (including the CyberAv3ngers-linked cluster CISA has tracked since 2023) specifically targeting water-sector operational technology. The US government has not issued a formal public attribution as of this writing, and this dossier treats the Iran linkage as ASSESSED rather than CONFIRMED accordingly.
The Threat Surface: Fragmented by Design
Water infrastructure security in the United States starts from a structural disadvantage no other sector in this series shares to the same degree: there is no single water authority.
Water management is distributed across roughly 150,000 separate public systems and tens of thousands of municipalities, many serving small populations with correspondingly small operating budgets. This fragmentation means cybersecurity posture varies enormously from one system to the next – a large metropolitan utility may run a modern, segmented network with dedicated security staff, while a rural system serving a few thousand residents may run the same internet-connected industrial control equipment with no dedicated IT security function at all. This dossier assesses that unevenness, more than any single technical vulnerability, is the water sector’s defining risk characteristic.
The physical infrastructure compounds this: EPA’s most recent needs assessment puts the 20-year investment requirement at $625 billion, with two-thirds of that tied specifically to aging transmission and distribution pipe. ASCE’s 2025 Infrastructure Report Card – drinking water at C, wastewater at D+ – reflects decades of underinvestment that predates and is analytically separate from the cybersecurity picture, but which compounds it: a utility straining to fund basic pipe replacement is rarely the same utility with resources to spare for control-system network segmentation or continuous monitoring.
The Concentrated Vector: Internet-Exposed Industrial Controls
Unlike the electrical grid’s broader mix of physical, cyber, and, increasingly, drone-based threats, water-sector risk concentrates heavily on a single, well-documented vector: internet-facing programmable logic controllers, the industrial devices that monitor and control pumps, valves, and treatment processes. These devices were often deployed for remote-monitoring convenience – allowing small-utility operators to check system status without a physical site visit – without commensurate security hardening.
- [ASSESSED] – This dossier assesses this specific vulnerability pattern (exposed remote access to PLCs, frequently with default or weak credentials) is disproportionately relevant to water relative to other infrastructure sectors examined in this series, because water utilities’ typically small scale and thin IT budgets make the convenience-over-security tradeoff more common than in better-resourced sectors.
Confirmed Compromise: The July 2026 Campaign

The clearest evidentiary case for this vulnerability pattern is the July 2026 campaign itself. Beginning July 26-27, attackers exploited internet-connected Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs at water and wastewater utilities in Minnesota, Michigan, Georgia, New Jersey, and South Dakota, among at least 12 states total. Minnesota was hit hardest and earliest: more than 30 community water systems affected, with four cities – Braham, Plymouth, South St. Paul, and Maple Plain – publicly confirming incidents. In Braham, a town of roughly 1,700 people, the intrusion disabled computerized operating controls and forced a temporary shutdown of the town’s well and treatment plant; public works crews restored operations within approximately two hours by reverting to manual control. Clayton County, Georgia’s water authority – serving roughly 300,000 customers in the Atlanta area – experienced a pump station disruption that dropped water pressure and prompted a precautionary boil-water advisory, lifted after testing confirmed no contamination.
CISA’s Advisory AA26-097A, updated July 22 – four days before the campaign’s first confirmed incident – had specifically warned that Iranian-affiliated cyber actors were exploiting exactly this class of internet-connected PLC across US critical infrastructure. The FBI and EPA issued a joint public service announcement confirming the pattern and urging utilities to disconnect systems from the public internet where possible, implement physical circuit breakers, and ensure operators remain trained on manual system control as a fallback.
- [DATA DEFICIT] – This dossier does not have a complete, independently verified list of all facilities affected in the July 2026 campaign. CISA and the FBI have not publicly named all 12 affected states, and this dossier’s confidence in the total facility count (100, per NYT reporting) rests on that single sourcing chain rather than independent confirmation.
Who’s Targeting Water, and How We Know
Multiple credible sources point toward Iran-linked responsibility for the July 2026 campaign, consistent with a documented, years-long pattern: Iran-affiliated actors have targeted US water facilities as far back as 2013 (New York) and 2023 (Pennsylvania), and have separately targeted Israeli water systems in 2020 and 2023. CISA’s own advisory (AA23-335A, later updated) specifically named IRGC-affiliated cyber actors as exploiting PLCs across multiple US infrastructure sectors – the same exploitation pattern documented in the July 2026 campaign. What distinguishes the 2026 campaign from this historical pattern, per CSIS’s analysis, is scale: earlier Iran-linked water-sector intrusions targeted one facility or a small handful; the 2026 campaign hit at least 12 states and multiple targets simultaneously.
- [ASSESSED] – CommandEleven Intelligence assesses the US government’s continued reluctance to issue formal public attribution – even as multiple sources independently point toward Iran and CISA’s own prior advisories have named IRGC-affiliated actors for functionally identical activity – likely reflects standard evidentiary and diplomatic caution around formal attribution during an active shooting war with Iran, rather than genuine uncertainty about the responsible actor. CommandEleven Intelligence also disagrees with the CISA assessment, understanding Chinese and Russian threat actors have infiltrated the water supply systems. The US is currently fighting 3 direct international cyber threats from Iran, China and Russia.
The Government Response
The federal response has been coordinated but reactive: CISA, the FBI, and EPA have worked jointly since the campaign’s discovery to help affected utilities secure systems, with the FBI’s public advisory specifically recommending internet disconnection, circuit-breaker use, and manual-control readiness – guidance that is sound but fundamentally defensive, addressing this specific campaign’s technical signature rather than the underlying structural vulnerability (fragmented ownership, uneven security investment).
At the state level, response has been uneven: Michigan State Police coordinated directly with affected municipalities; New York – not among the states hit in the July campaign – announced $9 million in grants for water-facility cybersecurity improvements, split between baseline assessments (penetration testing, risk assessments) and infrastructure upgrades (firewalls, network segmentation, incident response planning).
- [ASSESSED] – This dossier assesses New York’s proactive grant program, issued in response to a campaign that did not directly hit the state, is a more instructive model than reactive post-incident spending – the kind of upstream investment structural analysis suggests the sector needs most.
Assessment
[ASSESSED] – The water sector’s core vulnerability – thousands of independently operated, unevenly resourced systems, many running internet-exposed industrial control equipment with minimal security hardening – is structural and will not be resolved by any single incident response, however well-executed. The July 2026 campaign’s relatively limited real-world impact (no confirmed contamination, rapid manual-control fallback in every documented case) is a genuinely positive data point about current resilience, but this dossier assesses it should not be read as evidence the underlying vulnerability is well-managed – rather, it reflects that the attackers’ apparent objective in this campaign was disruption and demonstration rather than maximum harm, a different question than whether a more determined or sophisticated actor could achieve worse outcomes against the same exposed infrastructure.
Series Continuity
The next installment in this series examines the electricity grid – a sector sharing water’s aging-infrastructure and fragmented-ownership characteristics, but with a meaningfully different threat profile: a documented pattern of physical and drone-based attacks on substations and transmission infrastructure alongside the cyber vector examined here.
Sourcing Base (Confidence-Tiered, with Links)
CONFIRMED – Primary/Official Record & Direct Reporting:
- Federal Bureau of Investigation, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions“
- CSIS, “Mapping Iranian Cyberattacks on US Water Systems“
- Tenable, “Minnesota & other US Water Cyber Attacks, CISA AA26-097A“
- CNN, “Sweeping cyberattack on water systems in multiple states has US officials on edge,” July 31, 2026
- Cybersecurity Dive, “What we know so far about the hacking campaign against US water systems,” Aug. 20, 2026
- The Record, “Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents“
- EPA, “EPA’s 7th Drinking Water Infrastructure Needs Survey and Assessment“
- ASCE, “US Drinking Water Infrastructure,” 2025 Infrastructure Report Card
ASSESSED – Credible Secondary Reporting:
- ABC News, “At least 12 states face cyberattacks on their water systems, sources say“
- SecurityWeek, “Water Sector Cyberattacks Reportedly Hit at Least 12 States“
- Circle of Blue, “US Drinking Water Infrastructure and Its Challenges“
Excluded from this dossier: Any specific technical detail regarding PLC exploitation methodology, default credential lists, or remote-access configuration weaknesses beyond what is necessary to establish the general vulnerability pattern. This dossier treats such detail as unsuitable for public release.
Protecting Your Household’s Water Access: A $500 Baseline

This section is general emergency-preparedness guidance, modeled on standard FEMA and CDC household-resilience recommendations. It is not specific to any threat actor or incident, and does not depend on or respond to classified or sensitive information.
- Stored water (≈$75-100): FEMA recommends one gallon per person, per day, for at least three days (drinking and basic hygiene) as a baseline; many households target two weeks for a larger cushion. Food-grade water storage containers or commercially bottled water both work – rotate stock every six months.
- Basic filtration/purification (≈$50-150): A gravity-fed or pump-action water filter rated for biological contaminants (look for NSF/ANSI 53 or 58 certification) provides a fallback if stored water runs low and only municipal (untreated or boil-advisory) water is available. Water purification tablets are a cheap, shelf-stable backup.
- Manual boiling capability (≈$30-75): A basic camp stove or equivalent heat source independent of electrical service, since boil-water advisories assume you still have a way to boil water if grid power is also affected.
- Know your system type: Municipal water customers should know their utility’s boil-water-advisory notification method (text alert system, local news, utility website) in advance. Private well owners face a different risk profile – wells aren’t targeted by the utility-level attacks examined in this dossier, but should still maintain backup power for well pumps if on electric service.
- A basic emergency plan: FEMA’s Ready.gov provides a free household water-emergency checklist; completing it costs nothing and is the single highest-value action beyond the physical supplies above.
CommandEleven Intelligence is not a licensed emergency-preparedness or medical authority; this guidance reflects publicly available FEMA/CDC recommendations and general good practice, not a CommandEleven Intelligence-specific assessment of any household’s individual risk.