US critical infrastructure cybersecurity

A 12-State Water Utility Hack Wave Exposes a Regulatory Gap Congress Has Refused to Close

Iran-linked hackers hit water PLCs in 12 states; unlike the power grid, water utilities have no binding federal cybersecurity floor.

The Water Sector's Cyber Gap People of Internet Research · US 12+ States hit since July 27 Water/wastewater utilities reporti… 70%+ Systems non-compliant Water systems inspected by EPA sin… ~3 Years since first PLC hack Time since the Aliquippa, PA Unitr… None Binding federal standard EPA's 2023 cybersecurity rule was … peopleofinternet.com
The Water Sector's Cyber Gap People of Internet Research · US 12+ States hit since July 27 70%+ Systems non-compliant ~3 Years since first PLC hack None Binding federal standard peopleofinternet.com

Key Takeaways

A Familiar Attack, a Widening Map

Since July 27, 2026, water and wastewater utilities in at least 12 states have reported cyberattacks on their operational technology, according to The Record, which cites FBI figures showing seven states hit in the campaign's first days before ABC News pushed the count to 12. Minnesota officials were first to disclose incidents; Michigan, South Dakota, and Georgia followed. On August 3, 2026, Georgia's Clayton County Water Authority confirmed "a temporary disruption affecting a portion of its operational systems and water service in parts of north Clayton County," forcing a precautionary boil-water advisory that was lifted after testing showed the water was safe. A second nearby Georgia authority reported a separate incident days later.

Federal agencies have not publicly attributed the July–August wave, but the tactics match a pattern CISA, the FBI, the NSA, and the Department of Energy had already warned about. A joint advisory updated July 23, 2026 (CISA advisory AA26-097a) said Iran-affiliated actors were exploiting internet-exposed programmable logic controllers (PLCs) — the small industrial computers that run pumps, valves, and treatment processes — allowing "systems to enter unsafe conditions without notifying operators of the anomalies," per TechCrunch's reporting on the advisory. CISA Acting Director Nick Andersen said the agency was "observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities," per The Record. Targeting began with Rockwell Automation/Allen-Bradley devices and has since expanded to Schneider Electric and Siemens controllers.

This is not a novel technique. In November 2023, the IRGC-linked persona "CyberAv3ngers" seized a Unitronics PLC at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing its human-machine interface with an anti-Israel message after exploiting a device left on the public internet with a default password, as The Hacker News reported at the time. The vulnerability class — internet-exposed PLCs, unchanged factory credentials — is nearly three years old. What changed in 2026 is scale: dozens of municipalities rather than one, and a geographic spread that outpaces any single state's capacity to respond.

The Case for a Federal Floor

The strongest argument for binding federal standards is straightforward: water is the only major critical-infrastructure sector without one. The electric grid has NERC's Critical Infrastructure Protection standards — mandatory, audited, backed by fines. Water does not. In March 2023, the EPA tried to close that gap with an interpretive memo folding cybersecurity checks into states' existing Sanitary Survey Program. Missouri, Arkansas, and Iowa, joined by the American Water Works Association and the National Rural Water Association, sued. The Eighth Circuit stayed the rule in July 2023, and the EPA formally withdrew it that October, citing the litigation, as The Record reported. A Congressional Research Service report to Congress (congress.gov, R48556) confirms what the fight left behind: no federal statute grants EPA authority to impose NERC-CIP-equivalent binding standards on the water sector, and legislation to create one has not moved in successive Congresses.

The consequences of that vacuum are measurable. In a May 20, 2024 enforcement alert, the EPA reported that more than 70 percent of water systems it had inspected since September 2023 were not in full compliance with basic Safe Drinking Water Act cybersecurity obligations — unchanged default passwords chief among the failures. That is a real, cited number, not conjecture, and it is the strongest evidence regulation proponents have: voluntary guidance has had three years to work and has not closed even the most elementary gaps.

Why the 8th Circuit Was Still Right to Stop the Memo

The court's objection was not that cybersecurity doesn't matter — it was that the EPA tried to legislate through interpretive memo rather than through Congress, and dumped the compliance burden onto state drinking-water agencies that, as the challengers argued, "lack the appropriate staffing, training and expertise to evaluate cybersecurity programs." That critique holds. Roughly 150,000 public water systems exist in the US, the overwhelming majority serving small towns with a handful of employees and no IT security staff. A one-size mandate modeled on NERC-CIP — designed for a consolidated grid of large, well-capitalized utilities — would land hardest on exactly the systems least able to absorb compliance costs, likely passed straight to ratepayers in small, often rural communities.

The fix is not to re-litigate the same overreach; it's for Congress to actually legislate the authority the CRS report says doesn't exist — narrowly, with funding attached, and scaled to utility size. The Safe Drinking Water Act's Section 1433 already requires larger systems to complete risk and resilience assessments; extending a funded, tiered federal floor from that existing statutory hook is a more defensible path than another agency memo daring the courts to strike it down again. CISA's role should stay what it already is post-AA26-097a: fast technical advisories and voluntary incident response, not a backdoor regulator.

What to Watch

Watch whether the current Congress moves any of the water-cybersecurity bills that have stalled in prior sessions, and whether CIRCIA's incident-reporting mandate — requiring utilities to report significant intrusions to CISA within 72 hours — actually produces the kind of aggregated threat picture that voluntary disclosure never has. A reporting mandate paired with funded, size-scaled security requirements would do more for the next Aliquippa than either an EPA memo or a wave of state boil-water advisories.

Sources & Citations

  1. The Record: 12-state water utility cyberattacks
  2. TechCrunch on CISA/FBI/NSA/DOE advisory AA26-097a
  3. The Hacker News: Aliquippa PLC attack, Nov. 2023
  4. EPA: enforcement measures for water cybersecurity
  5. The Record: EPA withdraws cybersecurity memo after litigation
  6. GAO-26-109159: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector