Skip to content

Late July 2026 PLC Attacks

Summary

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Key facts

Timeline

  • Observed window: Jul 26, 2026–Jul 31, 2026

Assessment

  • Status: Active
  • Confidence: Medium

Evidence base

  • Linked incidents: 15
  • Campaign sources: 14

Campaign analysis

Campaign assessment

DysruptionHub assesses with medium confidence that a coordinated wave of attacks targeted operational technology at U.S. water and wastewater utilities beginning July 26-27, 2026. Minnesota IT Services described malicious activity against more than 30 community water systems during that period as coordinated. The FBI and EPA separately said utilities in at least seven states reported incidents beginning July 27 involving internet-facing programmable logic controllers. Subsequent reporting placed possible intrusions in at least 12 states, while an Aug. 18 CSIS analysis said at least 100 facilities were targeted and assigned 55 reported facilities to nine states. Those aggregate figures describe targeted or reported facilities, not a list of confirmed disruptions or publicly named victims.

The registry links 15 named incidents in six states: Alabama, Georgia, Michigan, Minnesota, New Jersey and South Dakota. Public reporting also identifies unnamed late-July victims in Arkansas and Oregon, bringing the evidence-supported public state picture for the July activity to eight states. The Washington Post reported that a western Arkansas water utility was hit as part of the multistate intrusion wave. Oregon officials separately said an unnamed drinking-water provider experienced a temporary operational-technology disruption.

Colorado officials later confirmed two additional, unnamed incidents at privately owned water providers serving fewer than 200 people each. The governor’s office told ABC News that intruders changed equipment settings, disabled remote access and alarms, and altered pumping cycles in late August. Officials said the providers quickly addressed the incidents and that treatment processes and water quality were not affected. Colorado is therefore a ninth state with publicly documented, similar water-control attacks during the broader period, but no public authority has linked those incidents to the July campaign, identified the affected equipment as PLCs or attributed them to the same actor.

Technical pattern and operational effects

The federal alert identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in observed incidents. Attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused loss of monitoring or control. At least one organization found modified project files and ladder-logic discrepancies. Reported operational effects included pressure loss, flooding, manual operation and loss of automated capability. The agencies also identified similar third-party network configurations as a possible reason attackers repeatedly succeeded across customers.

Michigan provides the clearest publicly identified shared-provider cluster. Alpena Township used UIS SCADA’s CRUiSE cloud platform and lost remote monitoring after its July 27 event; its contracted operator reprogrammed PLCs at multiple water and sewer sites. Brown City used UIS SCADA for system-control support and reported that attackers changed a municipal well’s IP address through a cellular connection, stopping water production for about two hours. Algonac said a cyberattack targeted cellular modems used to communicate with remote PLCs at its water filtration plant; the city reported no significant operational impacts and later approved UIS SCADA security work.

The three-victim pattern supports a possible shared-provider or repeated-configuration exposure, but it does not prove that UIS was compromised, that attackers breached its corporate network or software, or that a supply-chain attack occurred. The public record does not establish whether the initial targets were the CRUiSE service, internet-exposed customer PLCs or cellular modems, shared credentials, or repeated network configurations. It also does not establish common attribution.

Disclosure pattern and public ceiling

The first 12 named campaign members were identified publicly between July 27 and Aug. 7. Alpena Township became the 13th through Aug. 28 local reporting, and Brown City and Algonac later expanded the registry to 15 named incidents. Colorado’s Sept. 18 disclosure added two confirmed but unnamed late-August victims without identifying their locations or formally connecting them to the July campaign. The delayed Michigan and Colorado disclosures show that additional victims can emerge through local records and retrospective reporting even when no contemporaneous federal notice names them.

National coverage did not track the specificity of those disclosures. The Associated Press reported on Aug. 1 that nine Michigan water systems had reported relevant activity, but the state did not identify them. The Alpena News named Alpena Township on Aug. 28, Sanilac County News named Brown City on Aug. 26, and Algonac’s municipal records documented the third publicly identified Michigan victim. A Sept. 19 DysruptionHub review located no other news publication that had assembled all three names or connected all three to UIS SCADA. DysruptionHub therefore appears to be the only discoverable outlet publishing that synthesis, although local reporting and public records supplied the individual names.

By contrast, the Colorado governor’s office provided ABC News with a centralized, on-the-record account describing foreign actors and concrete changes to water-control equipment. DysruptionHub assesses with medium confidence that this press-ready state-government framing, combined with the stronger national-security language, helped the unnamed Colorado incidents gain national attention. The Michigan identities emerged separately through local outlets and council records weeks after the initial statewide story, requiring reporters to reconcile technical details and independently establish the UIS relationship.

That disparity is better supported as a distribution and sourcing effect than as evidence of editorial suppression. Neither the coverage pattern nor the utilities’ silence establishes that federal agencies directed news organizations not to publish the Michigan names. The absence of direct victim or vendor comment nevertheless increased the reporting burden and left the Michigan cluster dependent on local reporting, municipal records and independent synthesis.

DysruptionHub sought comment from each of the 15 named victims during its reporting. None responded. That 15-for-15 nonresponse is distinct from the public notices, council records and attributed statements some victims released through other channels.

The uniform lack of direct responses is part of a broader pattern of constrained disclosure. HTMUA’s Aug. 7 community update said a July 29 EPA briefing described incidents in at least six states and requested that technical details remain with participating utilities. Bloomberg Law reported that the EPA, FBI and CISA did not answer questions about which states were affected and that state water regulators either declined specific questions or did not respond. The Washington Post likewise reported that the FBI declined to comment.

Taken together, the 15-for-15 victim nonresponse, the EPA briefing restriction, delayed local disclosures and the refusal of federal agencies to identify the full state or victim scope strengthen DysruptionHub’s assessment that federal coordination and investigative handling discouraged affected utilities from discussing the attacks publicly. DysruptionHub makes that assessment with medium confidence. The evidence does not establish a blanket gag order, a formal instruction not to speak to reporters, or a direction to conceal victim identities or public-health impacts. Active investigations, operational-security concerns, legal advice and the limited administrative capacity of small utilities also could have contributed.

The gap between 15 named members and reports of at least 100 targeted facilities indicates that public identification is not keeping pace with the assessed campaign scope. DysruptionHub assesses with medium confidence that the named-victim list is unlikely to approach the reported aggregate total without additional local disclosures, public records or investigative findings.

Geographic scope and evidence boundaries

The evidence supports public reporting of late-July campaign activity in eight states: Alabama, Arkansas, Georgia, Michigan, Minnesota, New Jersey, Oregon and South Dakota. The 15 named registry members come from six of those states; the Arkansas and Oregon victims remain unnamed. Because national reporting placed the July campaign in at least 12 states, at least four states within that reported minimum remain publicly unidentified.

Wisconsin should not be counted as a confirmed campaign state based on the available record. Its Department of Natural Resources issued a preventive warning that PLCs at Wisconsin systems might be susceptible, but Wisconsin Public Radio reported that the Wisconsin Statewide Intelligence Center had not confirmed an attack. Milwaukee, Madison and Green Bay utilities said they were unaffected.

Utah also remains an unresolved lead rather than a confirmed late-July campaign state. Reporting cited November 2025 reconnaissance against Utah water infrastructure and a separate March 2026 intrusion at Sage Water Resources, but it did not identify a Utah utility hit during the July wave. Colorado’s two late-August incidents expand the broader documented geographic picture to nine states while remaining outside the confirmed July campaign count.

Campaign membership reflects evidence that an incident shared the reported operational-technology pattern or was publicly identified within a coordinated state or multistate cluster. It does not establish that every incident involved the same PLC model, access route, configuration change, infrastructure, vendor, operator or actor. Shared timing, water-sector victimology, geography or use of one service provider is not sufficient by itself.

Attribution

Attribution remains unresolved. CSIS assessed that the campaign was likely Iranian. The Washington Post reported that U.S. intelligence agencies were confident Iran’s Islamic Revolutionary Guard Corps was responsible, citing people familiar with the matter, but said the government had not made a formal attribution and debate remained over which IRGC-linked group carried out the attacks. Federal authorities have not publicly attributed this campaign to Iran or a named group.

Colorado officials likewise did not identify the foreign actors involved or confirm that the two incidents were part of the same campaign. The available evidence does not establish that one actor caused every reported incident.

Linked incidents

Campaign connection indicates how strongly public evidence links each incident to this campaign. It does not indicate confidence that the incident itself occurred.

Campaign sources

14 sources
July's Cyberattacks Accessed an Oregon Drinking Water Provider's Operating Technology; Bend, Redmond OK

An Oregon state spokesperson said the late-July attacks temporarily disrupted the operational technology of an Oregon drinking-water provider. The affected provider was not named, and Bend and Redmond officials said their systems were not affected.

Analyst note

Campaign-level evidence supporting Oregon’s inclusion while preserving that the victim remains unnamed and state officials did not confirm an actor.

Minnesota IT officials disclose coordinated cyberattack at more than 30 local water systems

Reuters reported Minnesota IT Services’ statement that more than 30 community water systems were targeted July 26-27 in a coordinated cyberattack. The agency said timing, access methods and targeted infrastructure shared characteristics with other coordinated critical-infrastructure incidents while formal attribution remained open.

Analyst note

Statewide Minnesota campaign evidence and attribution boundary.

FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems

The Associated Press reported that Michigan officials identified nine water systems with malicious activity consistent with the federal operational-technology alert. State officials said all systems continued operating safely, local operators addressed the issues and no known public-health impacts occurred; the affected communities were not named.

Analyst note

Campaign-level evidence expanding the geographic scope to Michigan while preserving that the affected utilities remain unnamed.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions

The FBI and EPA said water and wastewater utilities in at least seven states reported incidents beginning July 27 involving internet-facing PLCs. Observed activity included remote access, IP-address and password changes, loss of monitoring or control, modified project files at one organization, pressure loss, flooding and dependence on manual operations.

Analyst note

Primary authoritative campaign-pattern source. It does not name affected utilities or attribute the activity to a specific actor.

Water Sector Cyberattacks Reportedly Hit at Least 12 States

SecurityWeek reported that the late-July water-sector campaign expanded beyond Minnesota, identified Michigan, South Dakota and Georgia in the public reporting, and described Clayton County’s temporary pump-station disruption. It preserved the absence of public federal actor attribution and the incomplete named-victim list.

Analyst note

Independent multistate scope reporting used with incident-specific sources rather than as sole proof of membership.

HTMUA proactive response to recent cyber security events

HTMUA said a July 29 EPA Quick Turnaround Web Update told participants that the attacks had affected at least six states and requested that technical details remain with attending water utilities. HTMUA said the briefing prompted additional reviews that led it to identify a likely attempted cyberattack.

Analyst note

First-party HTMUA account of the EPA briefing, not an EPA-authored publication. It supports the campaign’s disclosure-pattern assessment and six-state briefing scope but does not establish that EPA directed utilities to conceal incidents or victim identities.

Alpena Township board tables SCADA upgrade after July cyberattack

Josh Jambor reported that a July 27 cyberattack disrupted UIS SCADA’s CRUiSE platform for Alpena Township and other Michigan utilities. UIS customer communications linked the event to PLCs and platform-support communications, while Alpena’s operator reprogrammed PLCs at multiple township sites and the township considered replacing 15 older cellular modems with firewall- and IP-whitelisting-capable equipment.

Analyst note

Campaign-level evidence supporting the first named Michigan member and a vendor-linked multi-customer cluster. The reporting does not establish that UIS itself was compromised or that the event was a supply-chain attack.

Sweeping cyberattack on water systems in multiple states has US officials on edge

CNN reported that Wisconsin officials detected malicious cyber activity at water facilities and that the state Department of Natural Resources urged utilities to take immediate preventive action. The report described the activity as part of the coordinated multistate wave but did not name the affected Wisconsin facilities.

Analyst note

Campaign-level evidence expanding the documented state scope to Wisconsin. Republished by ABC17 News.

'Foreign actors' targeted small, private water providers in Colorado: Governor

ABC News reported that Colorado’s governor’s office confirmed two late-August incidents at unnamed private water providers serving fewer than 200 people each. Intruders changed equipment settings, disabled remote access and alarms, and altered pumping cycles; officials said treatment processes and water quality were not affected.

Analyst note

Campaign-level evidence adding Colorado to the geographic picture. The report does not identify the providers, specify PLC models or confirm that the incidents were part of the late-July campaign.

Mapping Iranian Cyberattacks on U.S. Water Systems

CSIS said at least 100 facilities were targeted and assigned 55 reported facilities to nine states. Its map classified seven states as confirmed and Arkansas and Utah as suspected, while acknowledging that public reporting and inconsistent state disclosure make the dataset incomplete.

Analyst note

Campaign-level geographic and victim-count analysis. The article text says nine states publicly confirmed targeting, but the accompanying map legend classifies seven as confirmed and Arkansas and Utah as suspected; the campaign assessment follows the more granular map classification.

Major water utilities in Wisconsin unaffected by recent cyberattacks

Wisconsin Public Radio reported that the Wisconsin Statewide Intelligence Center had not confirmed any attacks in the state. Milwaukee, Madison and Green Bay utilities said they were unaffected, while the state Department of Natural Resources characterized its notice as a warning about an ongoing threat.

Analyst note

Corrective campaign-level evidence. It distinguishes a Wisconsin preventive alert from confirmation that a Wisconsin utility was attacked and rebuts earlier reporting that counted Wisconsin as a confirmed state.

Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks

The Washington Post reported that a water utility in western Arkansas was hit in late July as part of the multistate intrusion wave. The report also said officials familiar with the matter placed the campaign in at least 12 states, while the FBI declined to comment.

Analyst note

Campaign-level evidence supporting Arkansas as a reported state and the continuing absence of a complete public victim or state list. The utility was not named.

US Water Attacks Spur EPA to Recommend Funds It Seeks to Cut

Bloomberg Law reported that the EPA, FBI and CISA did not answer questions about which states had been hit and that water regulators in the states it contacted either declined to answer specific questions or did not respond. The report did not establish that agencies ordered victims to remain silent.

Analyst note

Campaign-level evidence for the constrained disclosure environment. It supports an assessment of broad official opacity but not a claim that federal agencies imposed a blanket no-comment order on victims.

Report: Utah among 12 states whose water infrastructure was targeted by Iran

The report cited targeted reconnaissance against Utah water infrastructure in November 2025 and identified Sage Water Resources as a victim of a separate March 15, 2026, PLC intrusion. Utah agencies did not publicly confirm a late-July attack, and the report does not establish Sage as part of the late-July campaign.

Analyst note

Campaign-level boundary evidence explaining why Utah remains tentative and why the named Sage incident is not added as a campaign member. Published on KSL.com.