logo

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

ID: ad712fb8-cb1b-589c-8086-de8a906f0040

STIX ID: report--ad712fb8-cb1b-589c-8086-de8a906f0040

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
80/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Nikita Kazymirskyi

...
...

Recent coordinated cyber activity in late July 2026 targeted internet‑facing water-sector operational technology—notably Rockwell MicroLogix 1100/1400 and other PLCs—impacting over 30 Minnesota community water systems and additional utilities across multiple U.S. states and Canada; attackers remotely accessed controllers, changed credentials and IPs, and in some cases modified ladder logic, producing pressure loss, flooding, communications outages, and shifts to manual operations. Federal advisories document technical overlaps with an Iranian‑affiliated PLC campaign while attribution for the Minnesota incidents remains unconfirmed; pro‑Russian hacktivist claims were also observed on the dark web. The report identifies insecure exposure, weak authentication, legacy equipment, and repeatable third‑party configurations as primary enabling conditions and provides prioritized OT remediation steps and monitoring recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.