A Familiar Attack, a Widening Map
Since July 27, 2026, water and wastewater utilities in at least 12 states have reported cyberattacks on their operational technology, according to The Record, which cites FBI figures showing seven states hit in the campaign's first days before ABC News pushed the count to 12. Minnesota officials were first to disclose incidents; Michigan, South Dakota, and Georgia followed. On August 3, 2026, Georgia's Clayton County Water Authority confirmed "a temporary disruption affecting a portion of its operational systems and water service in parts of north Clayton County," forcing a precautionary boil-water advisory that was lifted after testing showed the water was safe. A second nearby Georgia authority reported a separate incident days later.
Federal agencies have not publicly attributed the July–August wave, but the tactics match a pattern CISA, the FBI, the NSA, and the Department of Energy had already warned about. A joint advisory updated July 23, 2026 (CISA advisory AA26-097a) said Iran-affiliated actors were exploiting internet-exposed programmable logic controllers (PLCs) — the small industrial computers that run pumps, valves, and treatment processes — allowing "systems to enter unsafe conditions without notifying operators of the anomalies," per TechCrunch's reporting on the advisory. CISA Acting Director Nick Andersen said the agency was "observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities," per The Record. Targeting began with Rockwell Automation/Allen-Bradley devices and has since expanded to Schneider Electric and Siemens controllers.
This is not a novel technique. In November 2023, the IRGC-linked persona "CyberAv3ngers" seized a Unitronics PLC at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing its human-machine interface with an anti-Israel message after exploiting a device left on the public internet with a default password, as The Hacker News reported at the time. The vulnerability class — internet-exposed PLCs, unchanged factory credentials — is nearly three years old. What changed in 2026 is scale: dozens of municipalities rather than one, and a geographic spread that outpaces any single state's capacity to respond.
The Case for a Federal Floor
The strongest argument for binding federal standards is straightforward: water is the only major critical-infrastructure sector without one. The electric grid has NERC's Critical Infrastructure Protection standards — mandatory, audited, backed by fines. Water does not. In March 2023, the EPA tried to close that gap with an interpretive memo folding cybersecurity checks into states' existing Sanitary Survey Program. Missouri, Arkansas, and Iowa, joined by the American Water Works Association and the National Rural Water Association, sued. The Eighth Circuit stayed the rule in July 2023, and the EPA formally withdrew it that October, citing the litigation, as The Record reported. A Congressional Research Service report to Congress (congress.gov, R48556) confirms what the fight left behind: no federal statute grants EPA authority to impose NERC-CIP-equivalent binding standards on the water sector, and legislation to create one has not moved in successive Congresses.
The consequences of that vacuum are measurable. In a May 20, 2024 enforcement alert, the EPA reported that more than 70 percent of water systems it had inspected since September 2023 were not in full compliance with basic Safe Drinking Water Act cybersecurity obligations — unchanged default passwords chief among the failures. That is a real, cited number, not conjecture, and it is the strongest evidence regulation proponents have: voluntary guidance has had three years to work and has not closed even the most elementary gaps.
Why the 8th Circuit Was Still Right to Stop the Memo
The court's objection was not that cybersecurity doesn't matter — it was that the EPA tried to legislate through interpretive memo rather than through Congress, and dumped the compliance burden onto state drinking-water agencies that, as the challengers argued, "lack the appropriate staffing, training and expertise to evaluate cybersecurity programs." That critique holds. Roughly 150,000 public water systems exist in the US, the overwhelming majority serving small towns with a handful of employees and no IT security staff. A one-size mandate modeled on NERC-CIP — designed for a consolidated grid of large, well-capitalized utilities — would land hardest on exactly the systems least able to absorb compliance costs, likely passed straight to ratepayers in small, often rural communities.
The fix is not to re-litigate the same overreach; it's for Congress to actually legislate the authority the CRS report says doesn't exist — narrowly, with funding attached, and scaled to utility size. The Safe Drinking Water Act's Section 1433 already requires larger systems to complete risk and resilience assessments; extending a funded, tiered federal floor from that existing statutory hook is a more defensible path than another agency memo daring the courts to strike it down again. CISA's role should stay what it already is post-AA26-097a: fast technical advisories and voluntary incident response, not a backdoor regulator.
What to Watch
Watch whether the current Congress moves any of the water-cybersecurity bills that have stalled in prior sessions, and whether CIRCIA's incident-reporting mandate — requiring utilities to report significant intrusions to CISA within 72 hours — actually produces the kind of aggregated threat picture that voluntary disclosure never has. A reporting mandate paired with funded, size-scaled security requirements would do more for the next Aliquippa than either an EPA memo or a wave of state boil-water advisories.