Executive Summary
In July 2026, a coordinated series of cyberattacks targeted water and wastewater systems across at least 12 U.S. states, including Minnesota, Georgia, Michigan, South Dakota, Alabama, and New Jersey. The attackers exploited vulnerabilities in internet-exposed programmable logic controllers (PLCs), specifically those from Rockwell Automation, Schneider Electric, and Siemens, to modify configurations and lock out operators. While no water contamination was reported, some systems experienced operational disruptions, such as water pressure drops and the issuance of boil water advisories. These incidents underscore the critical vulnerabilities in the nation's water infrastructure, particularly in smaller utilities lacking robust cybersecurity measures. (axios.com)
The attacks have been tentatively linked to the Iranian state-sponsored group CyberAv3ngers, known for targeting industrial control systems in critical infrastructure sectors. This campaign highlights the escalating cyber threat landscape and the urgent need for enhanced security protocols to protect essential services. (ampcuscyber.com)
Why This Matters Now
The recent cyberattacks on U.S. water systems reveal significant vulnerabilities in critical infrastructure, especially among smaller utilities with limited cybersecurity resources. With state-sponsored groups like CyberAv3ngers actively exploiting these weaknesses, there is an immediate need for comprehensive security measures to safeguard essential services and prevent potential public health crises.
Attack Path Analysis
Adversaries exploited internet-exposed PLCs in water systems to gain unauthorized access, modified controller configurations to lock out operators, moved laterally to other connected systems, established command and control channels, exfiltrated sensitive operational data, and caused operational disruptions such as water pressure drops.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Adversaries exploited internet-exposed PLCs in water systems to gain unauthorized access.
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Resource Hijacking
Data Manipulation: Stored Data Manipulation
Network Denial of Service
Application Layer Protocol: Web Protocols
Remote Services: SMB/Windows Admin Shares
Indicator Removal: File Deletion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Boundary Protection
Control ID: SC-7
NIST SP 800-53 – Identification and Authentication
Control ID: IA-2
NIST SP 800-53 – System Monitoring
Control ID: SI-4
NIST SP 800-53 – Contingency Plan
Control ID: CP-2
NIST SP 800-53 – Least Functionality
Control ID: CM-7
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Primary target of Iranian state-sponsored attacks on water infrastructure PLCs, requiring immediate ICS/OT segmentation and encrypted communication protocols.
Government Administration
Municipal water systems across dozen states compromised via Internet-exposed PLCs, demanding enhanced zero trust segmentation for critical infrastructure.
Information Technology/IT
IT/OT convergence vulnerabilities exploited through unencrypted PLC communications, requiring east-west traffic security and threat detection capabilities.
Computer/Network Security
Security sector must address widespread PLC exposure through enhanced egress filtering, anomaly detection, and industrial control system protection.
Sources
- Multistate Water System Attacks Widen, Iran Suspectedhttps://www.darkreading.com/ics-ot-security/multistate-water-system-attacks-widen-iran-suspectedVerified
- EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attackshttps://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranianVerified
- CyberAv3ngers Attacks U.S. Water Utilities with ICS Malwarehttps://www.ampcuscyber.com/shadowopsintel/cyberav3ngers-targeting-the-us-water-utilities-ics/Verified
- Cyberattacks target water systems in at least 12 states: reporthttps://www.axios.com/2026/08/04/water-cyberattacks-us-iranVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit unauthorized access to PLCs, restrict lateral movement within the network, and control data exfiltration, thereby reducing the attacker's operational impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing CNSF would likely limit unauthorized access to PLCs by enforcing strict identity-based policies, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely constrain attackers' ability to escalate privileges by isolating workloads and enforcing least-privilege access.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely reduce the attacker's ability to move laterally by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the establishment of command and control channels by providing comprehensive monitoring and control over network communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely constrain data exfiltration by monitoring and controlling outbound traffic.
Implementing CNSF controls would likely reduce the scope of operational disruptions by limiting unauthorized access and actions within the network.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Water Distribution Management
- System Monitoring and Control
Estimated downtime: 3 days
Estimated loss: $500,000
Operational data related to water treatment processes and system configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to critical systems.
- • Enforce East-West Traffic Security to monitor and control internal communications.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns.



