Skip to content

Late July 2026 PLC Attacks

Summary

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The campaign now includes 15 named incidents; Michigan has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA, supporting a possible shared-provider exposure. That pattern does not prove UIS itself was compromised or establish common attribution, and the complete victim list remains unknown.

Key facts

Timeline

  • Observed window: Jul 26, 2026–Jul 31, 2026

Assessment

  • Status: Active
  • Confidence: Medium

Evidence base

  • Linked incidents: 15
  • Campaign sources: 10

Campaign analysis

Campaign assessment

DysruptionHub assesses with medium confidence that a coordinated wave of attacks targeted U.S. water and wastewater operational technology beginning July 26-27, 2026. Minnesota IT Services described malicious activity against more than 30 community water systems during July 26-27 as coordinated. The FBI and EPA separately said utilities in at least seven states reported incidents beginning July 27 involving internet-facing programmable logic controllers. Subsequent reporting placed possible intrusions in at least 12 states. An Aug. 18 CSIS analysis said at least 100 facilities were targeted and assigned 55 reported facilities to nine states. Those aggregate counts are not a list of publicly named victims.

Technical pattern and operational effects

The federal alert identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in observed incidents. Attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused loss of monitoring or control. At least one organization found modified project files and ladder-logic discrepancies, while reported operational effects included pressure loss, flooding, manual operation and loss of automated capability. The agencies also identified similar third-party network setups as a possible mechanism for repeated success across customers.

Michigan provides the clearest publicly identified shared-provider cluster within the campaign. Alpena Township used UIS SCADA’s CRUiSE cloud platform and lost remote monitoring after its July 27 event; its contracted operator reprogrammed PLCs at multiple water and sewer sites. Brown City used UIS SCADA for system-control support and reported that attackers changed a municipal well’s IP address through a cellular connection, stopping water production for several hours. Algonac said a cyberattack targeted cellular modems used to communicate with remote PLCs at its water filtration plant; the city reported no significant operational impacts and later approved UIS SCADA security work. All three identified Michigan victims therefore have documented ties to UIS SCADA.

That three-victim pattern is consistent with the FBI and EPA finding that similar third-party network configurations across several victims may have allowed attackers to repeat successful access. It supports a possible shared-provider exposure, but it does not prove that UIS itself was compromised, that attackers breached UIS’s corporate network or software, or that a supply-chain attack occurred. It also does not establish common attribution. The public record does not show whether the initial targets were the CRUiSE service, internet-exposed customer PLCs or cellular modems, shared credentials, or repeated network configurations.

Disclosure pattern and likely public ceiling

Public identification of the first 12 named campaign members was concentrated between July 27 and Aug. 7. Alpena Township became the 13th named member through Aug. 28 local reporting, and Brown City and Algonac subsequently expanded the campaign record to 15 named incidents. These retrospective identifications show that additional names can emerge through municipal meetings, procurement records and local reporting even when no contemporaneous public alert identified the victim. The gap between 15 named members and reports of at least 100 targeted facilities nevertheless indicates that public identification is not keeping pace with the assessed campaign scope.

HTMUA’s Aug. 7 community update said a July 29 EPA briefing described events in at least six states and requested that technical details remain with attending water utilities. That supports closed handling of sensitive technical incident information, but it does not establish that EPA ordered utilities to conceal incidents, victim identities or public impacts. DysruptionHub assesses with medium confidence that the named-victim list is unlikely to approach the reported aggregate totals and that most additional victims will remain unnamed absent later local disclosures, public records or investigative findings. The three Michigan identifications demonstrate that further retrospective identification remains possible.

Scope and attribution

The 15 named campaign members are located in Alabama, Georgia, Michigan, Minnesota, New Jersey and South Dakota. Michigan now has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA. That concentration supports a possible shared-provider exposure, but it does not prove UIS was compromised or establish that the same actor caused all three incidents.

Campaign membership reflects evidence that an incident shared the reported operational-technology pattern or was publicly identified within a coordinated state or multistate cluster. It does not establish that every incident involved the same PLC model, access route, configuration change, infrastructure, vendor or operator. Shared timing, water-sector victimology, geography or use of one service provider is not sufficient by itself.

Michigan officials said nine water systems reported activity consistent with the federal description, but available reporting does not explicitly say whether Alpena Township, Brown City or Algonac was included in that total. Wisconsin officials detected malicious cyber activity at water facilities without naming the affected systems. CSIS also added Oregon, Arkansas and Utah to the public geographic picture, with Arkansas and Utah treated as suspected rather than confirmed.

Taken together, available reporting identifies activity or suspected activity in 10 states: eight with stronger public confirmation—Alabama, Georgia, Michigan, Minnesota, New Jersey, Oregon, South Dakota and Wisconsin—and two tentative states, Arkansas and Utah. That leaves at least two states unidentified within the reported minimum of 12. Because the national figure is a minimum rather than a complete total, the undisclosed geographic and victim scope may be larger.

Attribution remains unresolved. CSIS assessed that the campaign was likely Iranian, and public reporting described Iran as an investigative hypothesis and noted similarities to previously documented Iran-affiliated PLC activity. Federal authorities had not publicly attributed this campaign to Iran or a named group. The public victim list also remains incomplete, and the available evidence does not establish whether one actor caused every reported incident.

Linked incidents

Campaign connection indicates how strongly public evidence links each incident to this campaign. It does not indicate confidence that the incident itself occurred.

Campaign sources

10 sources
July's Cyberattacks Accessed an Oregon Drinking Water Provider's Operating Technology; Bend, Redmond OK

An Oregon state spokesperson said the late-July attacks temporarily disrupted the operational technology of an Oregon drinking-water provider. The affected provider was not named, and Bend and Redmond officials said their systems were not affected.

Analyst note

Campaign-level evidence supporting Oregon’s inclusion while preserving that the victim remains unnamed and state officials did not confirm an actor.

Minnesota IT officials disclose coordinated cyberattack at more than 30 local water systems

Reuters reported Minnesota IT Services’ statement that more than 30 community water systems were targeted July 26-27 in a coordinated cyberattack. The agency said timing, access methods and targeted infrastructure shared characteristics with other coordinated critical-infrastructure incidents while formal attribution remained open.

Analyst note

Statewide Minnesota campaign evidence and attribution boundary.

FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems

The Associated Press reported that Michigan officials identified nine water systems with malicious activity consistent with the federal operational-technology alert. State officials said all systems continued operating safely, local operators addressed the issues and no known public-health impacts occurred; the affected communities were not named.

Analyst note

Campaign-level evidence expanding the geographic scope to Michigan while preserving that the affected utilities remain unnamed.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions

The FBI and EPA said water and wastewater utilities in at least seven states reported incidents beginning July 27 involving internet-facing PLCs. Observed activity included remote access, IP-address and password changes, loss of monitoring or control, modified project files at one organization, pressure loss, flooding and dependence on manual operations.

Analyst note

Primary authoritative campaign-pattern source. It does not name affected utilities or attribute the activity to a specific actor.

Water Sector Cyberattacks Reportedly Hit at Least 12 States

SecurityWeek reported that the late-July water-sector campaign expanded beyond Minnesota, identified Michigan, South Dakota and Georgia in the public reporting, and described Clayton County’s temporary pump-station disruption. It preserved the absence of public federal actor attribution and the incomplete named-victim list.

Analyst note

Independent multistate scope reporting used with incident-specific sources rather than as sole proof of membership.

HTMUA proactive response to recent cyber security events

HTMUA said a July 29 EPA Quick Turnaround Web Update told participants that the attacks had affected at least six states and requested that technical details remain with attending water utilities. HTMUA said the briefing prompted additional reviews that led it to identify a likely attempted cyberattack.

Analyst note

First-party HTMUA account of the EPA briefing, not an EPA-authored publication. It supports the campaign’s disclosure-pattern assessment and six-state briefing scope but does not establish that EPA directed utilities to conceal incidents or victim identities.

Alpena Township board tables SCADA upgrade after July cyberattack

Josh Jambor reported that a July 27 cyberattack disrupted UIS SCADA’s CRUiSE platform for Alpena Township and other Michigan utilities. UIS customer communications linked the event to PLCs and platform-support communications, while Alpena’s operator reprogrammed PLCs at multiple township sites and the township considered replacing 15 older cellular modems with firewall- and IP-whitelisting-capable equipment.

Analyst note

Campaign-level evidence supporting the first named Michigan member and a vendor-linked multi-customer cluster. The reporting does not establish that UIS itself was compromised or that the event was a supply-chain attack.

Sweeping cyberattack on water systems in multiple states has US officials on edge

CNN reported that Wisconsin officials detected malicious cyber activity at water facilities and that the state Department of Natural Resources urged utilities to take immediate preventive action. The report described the activity as part of the coordinated multistate wave but did not name the affected Wisconsin facilities.

Analyst note

Campaign-level evidence expanding the documented state scope to Wisconsin. Republished by ABC17 News.

Mapping Iranian Cyberattacks on U.S. Water Systems

CSIS said at least 100 facilities were targeted and assigned 55 reported facilities to nine states. Its map classified seven states as confirmed and Arkansas and Utah as suspected, while acknowledging that public reporting and inconsistent state disclosure make the dataset incomplete.

Analyst note

Campaign-level geographic and victim-count analysis. The article text says nine states publicly confirmed targeting, but the accompanying map legend classifies seven as confirmed and Arkansas and Utah as suspected; the campaign assessment follows the more granular map classification.

Report: Utah among 12 states whose water infrastructure was targeted by Iran

The report cited targeted reconnaissance against Utah water infrastructure in November 2025 and identified Sage Water Resources as a victim of a separate March 15, 2026, PLC intrusion. Utah agencies did not publicly confirm a late-July attack, and the report does not establish Sage as part of the late-July campaign.

Analyst note

Campaign-level boundary evidence explaining why Utah remains tentative and why the named Sage incident is not added as a campaign member. Published on KSL.com.