News: 0185210064

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

More Than 100 Water Systems Were Hit In July Cyberattacks

(Thursday August 27, 2026 @11:00AM (BeauHD) from the wake-up-call dept.)


CISA [1]says more than 100 internet-exposed U.S. water and wastewater systems [2]were targeted in July , often through programmable logic controllers connected directly to cellular modems. "That's the first time the feds have put a number on the digital intrusions, but they have yet to attribute the campaign, widely suspected to be linked to Iran, to a particular group," reports The Register. From the report:

> Suspected Iranian attackers targeted water and wastewater facilities across at least a dozen states in July, including internet-exposed PLCs. While neither federal nor state officials have identified all 12, we know that the cyberattacks occurred at mostly small, rural utilities in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. "This is very serious. What stands out isn't any single incident. It's the scale," Matt Hartman, chief strategy officer at the Merlin Group and CISA's former acting head of cyber, told The Register.

>

> "More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets," Hartman said. "Much of this infrastructure runs on operational technology that was built for closed, physical environments. It was never designed with the assumption that it would be reachable from the open internet."

>

> John Gallagher, VP at Viakoo, an OT and IoT cybersecurity provider, told us that while 100 systems represent a small fraction - only about 0.5 percent - of water utilities in the US, the "real threat is that these are test runs for a larger-scale attack." While the 100-plus water incidents occurred in July, just last week five US federal agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities.

>

> "This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs," Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register a week ago. "Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society," Kaiser, a former FBI cyber division deputy assistant director, added.

CISA urges organizations to keep PLCs off the public internet, route remote access through VPNs or gateways, replace default passwords, enable stronger authentication, and restrict access to allowlisted IP addresses from trusted OT systems.



[1] https://www.cisa.gov/resources-tools/resources/exposure-reduction

[2] https://www.theregister.com/cyber-crime/2026/08/26/more-than-100-water-systems-were-hit-in-july-cyberattacks/5292685



Crappy IT security has consequences (Score:2)

by gweihir ( 88907 )

This is really in no way a surprise. All that "trash" level security infrastructure has not been attacked before because nobody tried.

Re:Crappy IT security has consequences (Score:4, Insightful)

by Targon ( 17348 )

It's not even that they haven't tried, they are incompetent when it comes down to it. Why should ANYTHING infrastructure related be connected to the Internet in the first place? Put a public facing machine out there that gets data moved to it manually, but the actual operations should NOT be something that can be gotten to remotely. The politicians who just want convenient access can get off their asses for a change if they feel they need more direct access.

Re:Crappy IT security has consequences (Score:5, Interesting)

by AmiMoJo ( 196126 )

You have to understand that most of the people using these systems are not highly trained, and if you make them secure they will just blame you for them not doing their jobs and their boss will start shouting at you. It's "this needs fixing NOW, we are losing money!" vs "you might get hacked in future".

Once when I suggested we should secure a system the guy told me that we were not an important enough target to get hacked and so couldn't justify the expense.

The only solution is to make security a legal requirement and enforce it with regular inspections and heft fines.

Re:Crappy IT security has consequences (Score:5, Insightful)

by gweihir ( 88907 )

And that is exactly why we need regulation and liability, preferably liability with a personal component. When anybody is doing critical infrastructure without IT security expertise involved and they find themselves fined a significant part of their salary, things will change.

And stop the utterly idiotic "the operators cannot afford it" claim. Can they afford to get hacked and their infrastructure taken over and damaged? No? Then they can afford IT Security. It is not even hard or expensive. We are talking a day of consulting and taking some template known-secure architecture with VPN links and the like. But you have to do it. Ignoring the problem or claiming you cannot do it will only do one thing: It will make your problem much worse and much more expensive.

Re: (Score:2)

by Targon ( 17348 )

If you set it up properly, security isn't a big problem. Stop connecting every single thing to the Internet, keep things fully inside the network without a need for outside access, and things will work.

Re: (Score:1)

by drinkypoo ( 153816 )

This is American IT security in a nutshell. There are no penalties for ignoring CISA so everyone does. I have to change passwords on a cycle for no reason, whoops. They don't allow most special characters, whoops.

Re: (Score:3)

by sabbede ( 2678435 )

I don't know if I've mentioned it to you before, but I used to work for a company under the umbrella of MidAmerican Energy. Because that's a major utility, they, and thus I, were under strict security requirements. I spent the better part of a year on a CSC20 push, busting my ass and pulling out hair. Afterwards, I found out that MidAmerican had exempted themselves from a number of the controls they made me implement. I found that to be troubling.

Re: (Score:3)

by Tailhook ( 98486 )

> they are incompetent

You are exhibiting insufficient cynicism. The people responsible are highly competent.

Their competence is discreetly handling the acquisition of COTS hardware at DOD prices from politically connected contractors. The contractors pocket the massive margins and fund the designated campaigns. These are the real priorities. Not whatever silly security concerns plebs like you have.

Any given tech nerd could do better at a fraction of the cost. But that wouldn't fund the mcmansions and range rovers and bo

Re: (Score:2)

by BadgerStork ( 7656678 )

Any given tech nerd should have said no.

Re: (Score:3)

by sabbede ( 2678435 )

Okay, having worked for a company under the umbrella of a power company, I can tell you that's wrong. We bought Meraki hardware at a MASSIVE volume discount. Less than half MSRP for hardware and licensing. Then we replaced the firewalls with PaloAltos, again purchased at steep discounts.

The BS came about when I found out that the power company was exempting itself from rules they made me enforce.

Re: Crappy IT security has consequences (Score:4, Informative)

by fortfive ( 1582005 )

While youâ(TM)re not wrong in an ideal sense, consider the targets in this case: small town public utilities. Iâ(TM)m sure some are stupid or uncaring, but many probably want good security but canâ(TM)t afford it.

As to why public facing network connections, in a water or sewer system there are many distant sensors and actuators where it is impractical or even functionally impossible to string a wire for a closed intranet. They could maybe use a closed wireless setup but see funding problems i already identified.

Re: (Score:2)

by sabbede ( 2678435 )

And yet they managed to do it before the internet existed.

Re: (Score:2)

by thegarbz ( 1787294 )

> but the actual operations should NOT be something that can be gotten to remotely. The politicians who just want convenient access

It's not politicians who want convenient access. It's you. You the person who demands an always available water supply with stringent quality, accessible from any tap in the city. You're the one who is pushing them to make sure the hundreds / sometimes thousands of pumps, and valves in the water network can be controlled by operations quickly to make sure problems are quickly addressed and supply is always available.

I know a lot of people have this idea that operating a water supply is as complex as turning

Re: (Score:2)

by gtall ( 79522 )

Oh yes! Those dumb Iranians would never have thought to do this were it not for Stuxnet.

Re: (Score:1)

by NotEmmanuelGoldstein ( 6423622 )

Of course, they would have but the USA showed the world how a PLC can be completely weaponized. Now, the US culture of owning more stuff/"the libs", AKA exceptionalism, means AI will ignore guardrails and weaponize itself.

Re: (Score:2)

by gtall ( 79522 )

"but the USA showed the world how a PLC can be completely weaponized" This is the dumb Iranian argument. Give them a break, they are just as smart and wily as Americans.

High Value PLCs (Score:1)

by R80_JR ( 1094843 )

The Iranians are hoping to hit the PLC's controlling uranium enrichment centrifuges, just like they had.....

Suspected Iranians (Score:5, Insightful)

by phantomfive ( 622387 )

> Suspected Iranian attackers targeted water and wastewater facilities across at least a dozen states in July

Code for, "we don't know who it was, but calling them a state actor will distract from our poor security."

Re: (Score:1, Insightful)

by SumDog ( 466607 )

or they just made the entire thing up as a propaganda statement to make it easier to campaign for more war.

Re: (Score:2)

by PPH ( 736903 )

That article says that Rattcliffe _did_not_ meet Putin. Which stands to reason, as nobody in our administration, including Trump ranks high enough to deal with more than a mid-level apparatchik.

Re: (Score:2)

by phantomfive ( 622387 )

[1]Could be a spy swap [youtube.com].

Putin isn't going to make a deal on Ukraine until China plays their hand, and China won't make their move until the US is entrapped as possible in Iran.

[1] https://www.youtube.com/shorts/stXEJyL_X-8

Re: (Score:3)

by Targon ( 17348 )

You forget, China backed hacker groups, North Korea, and others as well.

Re: (Score:1)

by Anonymous Coward

but we can't bomb either of those and they're not in the middle of a war like my two choices

old news, and Project 2025 (Score:3)

by clovis ( 4684 )

Old news. We heard all this back in the 20th century.

1998,

LOpht testifies before Congress

[1]https://commdocs.house.gov/com... [house.gov]

Clinton weighs in to protect us from all this in 1998

[2]https://clintonwhitehouse5.arc... [archives.gov]

and countless other incidents

And now we have DOGE eviscerating CISA because Project 2025.

[3]https://www.darkreading.com/th... [darkreading.com]

[4]https://www.americanprogress.o... [americanprogress.org]

The problem with CISA is that cyber security measures previously taken have served to make Russia look bad and did nothing to prove Trump actually won in 2020.

[1] https://commdocs.house.gov/committees/judiciary/hju67303.000/hju67303_0f.htm

[2] https://clintonwhitehouse5.archives.gov/WH/EOP/NSC/html/documents/NSCDoc3.html

[3] https://www.darkreading.com/threat-intelligence/cisa-red-team-disarray-cyber-defenses

[4] https://www.americanprogress.org/article/project-2025-will-undermine-americas-national-security/

We ran water systems before the internet (Score:4, Insightful)

by drinkypoo ( 153816 )

Water systems haven't changed all that much since before the internet existed, let alone became popular. They still have broadly the same stages and generally the same things occur in them. There is literally no need for automation because it doesn't take many people to run a water system and they need surprisingly little training. It's a community college course! We implemented automation to reduce headcount, but if the automation systems are attacked and need work then that's actually increasing labor costs. Now you need to hire an engineer to fix what you should have done right the first time.

On the other hand, automation isn't even the problem, I only mention it to point out that these problems don't have to exist at all. You could solve the problem by not having remote control , or by not using the internet for that (there are other options) and by using one-way links for monitoring. Then you can still do your monitoring through the cheap and ubiquitous internet, and only have to use other resources for control.

Putting control of these systems on the internet gets you almost nothing and exposes you to risks which are completely unnecessary and doing so hardly saves you any money as you could use another option for your control links and it doesn't need to be high speed.

Re: (Score:2)

by thegarbz ( 1787294 )

> Water systems haven't changed all that much since before the internet existed, let alone became popular.

False as usual. The design and automation of water networks has grown orders of magnitude more complex from before the internet existed. But speaking of time, it is worth noting that funding and staged upgrades means a not insignificant portion of them date back to over 20 years ago, long before IEC 62443 become common place.

'Urges', with critical infrastructure? (Score:3)

by schwit1 ( 797399 )

This is critical effiing infrastructure, not vending machines.

Critical infrastructure should be constantly red-teamed by CISA, DOD, NSA should and DHS. If you're not passing with flying colors there should be massive fines.

CISA should park in their pocket until this gets fixed.

Re: (Score:2)

by thegarbz ( 1787294 )

> there should be massive fines.

Yes those governments who grossly underinvest in water infrastructure leading to systems that are decades out of date on modern security standards should fine themselves, that'll show them.

We need more information. (Score:2)

by sabbede ( 2678435 )

CISA (or whoever) should produce a public report showing exactly how each of these utilities was breached. These are public utilities, they belong to us and we deserve to know how they f-d up.

The utilities breached in my State weren't small. The Clayton County Water Authority serves a large chunk of Atlanta and surrounding suburbs. 298,374 customers served across 7 cities, including parts of Atlanta (https://www.tapwaterdata.com/utilities/ga/clayton-county-water-authority). They had exposed PLCs. Th

Cellular Modems? (Score:3)

by PPH ( 736903 )

They were just asking to get hacked.

Re: (Score:2)

by thegarbz ( 1787294 )

No, they were asking for money to invest in modern infrastructure. The typical ways governments fund infrastructure was asking for it to be hacked.

Re: (Score:2)

by Frederic54 ( 3788 )

Some SCADA stuff that monitor powerlines and water utilities and all are super old, those working with 3G modem are being replaced at least, it is sometimes 20 years old technology without security. For instance it reports by SMS and you send SMS to it to execute commands and all.

Absolute idiocy. Fire the IT departments. (Score:2)

by Puls4r ( 724907 )

I work for a *major* manufacturer with operations in numerous countries.

There is not one, single PLC connected through a wireless modem to the internet. That's stupidity. Absolute stupidity.

Our PLC software is hardlocked and unable to be changed without rebooting into a special password protected mode. It is set up in a data-send-only configuration where it can send the server production metrics, but will not accept *any* incoming connections. It is virus-protected, checked nightly against off-sit

test run (Score:2)

by bugs2squash ( 1132591 )

> "real threat is that these are test runs for a larger-scale attack."

How does that make sense ? If they plan a large attack in the near future why tip their hand ?

I suspect they attacked whatever they could using this approach, the next attack will use a different approach

South Dakota, huh.. (Score:1)

by Chuck Hamlin ( 6194058 )

Attack that red state, why don't you, Donny.. Kristi Noem's successor must've done it, right?

Einstein argued that there must be simplified explanations of nature, because
God is not capricious or arbitrary. No such faith comforts the software
engineer.
-- Fred Brooks