Skip to content

Late July 2026 PLC Attacks

Summary

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The FBI and EPA documented a common technical pattern, but public evidence does not establish one actor behind every incident or identify the complete victim list.

Key facts

Timeline

  • Observed window: Jul 26, 2026–Jul 31, 2026

Assessment

  • Status: Active
  • Confidence: Medium

Evidence base

  • Linked incidents: 11
  • Campaign sources: 3

Recent campaign intelligence

Paid member assessment preview

Unlock the complete campaign assessment

New campaign assessments are available immediately to Sustainers, after 2 weeks to Supporters, and to everyone once they are more than 1 month old.

Sustainers help fund the research and verification behind the Cyber Incident Registry while receiving immediate access to new assessments.