Campaign assessment
DysruptionHub assesses with medium confidence that a coordinated wave of attacks targeted U.S. water and wastewater operational technology beginning July 26-27, 2026. Minnesota IT Services described malicious activity against more than 30 community water systems during July 26-27 as coordinated. The FBI and EPA separately said utilities in at least seven states reported incidents beginning July 27 involving internet-facing programmable logic controllers. Subsequent reporting placed possible intrusions in at least 12 states. An Aug. 18 CSIS analysis said at least 100 facilities were targeted and assigned 55 reported facilities to nine states. Those aggregate counts are not a list of publicly named victims.
Technical pattern and operational effects
The federal alert identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in observed incidents. Attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused loss of monitoring or control. At least one organization found modified project files and ladder-logic discrepancies, while reported operational effects included pressure loss, flooding, manual operation and loss of automated capability. The agencies also identified similar third-party network setups as a possible mechanism for repeated success across customers.
Michigan provides the clearest publicly identified shared-provider cluster within the campaign. Alpena Township used UIS SCADA’s CRUiSE cloud platform and lost remote monitoring after its July 27 event; its contracted operator reprogrammed PLCs at multiple water and sewer sites. Brown City used UIS SCADA for system-control support and reported that attackers changed a municipal well’s IP address through a cellular connection, stopping water production for several hours. Algonac said a cyberattack targeted cellular modems used to communicate with remote PLCs at its water filtration plant; the city reported no significant operational impacts and later approved UIS SCADA security work. All three identified Michigan victims therefore have documented ties to UIS SCADA.
That three-victim pattern is consistent with the FBI and EPA finding that similar third-party network configurations across several victims may have allowed attackers to repeat successful access. It supports a possible shared-provider exposure, but it does not prove that UIS itself was compromised, that attackers breached UIS’s corporate network or software, or that a supply-chain attack occurred. It also does not establish common attribution. The public record does not show whether the initial targets were the CRUiSE service, internet-exposed customer PLCs or cellular modems, shared credentials, or repeated network configurations.
Disclosure pattern and likely public ceiling
Public identification of the first 12 named campaign members was concentrated between July 27 and Aug. 7. Alpena Township became the 13th named member through Aug. 28 local reporting, and Brown City and Algonac subsequently expanded the campaign record to 15 named incidents. These retrospective identifications show that additional names can emerge through municipal meetings, procurement records and local reporting even when no contemporaneous public alert identified the victim. The gap between 15 named members and reports of at least 100 targeted facilities nevertheless indicates that public identification is not keeping pace with the assessed campaign scope.
HTMUA’s Aug. 7 community update said a July 29 EPA briefing described events in at least six states and requested that technical details remain with attending water utilities. That supports closed handling of sensitive technical incident information, but it does not establish that EPA ordered utilities to conceal incidents, victim identities or public impacts. DysruptionHub assesses with medium confidence that the named-victim list is unlikely to approach the reported aggregate totals and that most additional victims will remain unnamed absent later local disclosures, public records or investigative findings. The three Michigan identifications demonstrate that further retrospective identification remains possible.
Scope and attribution
The 15 named campaign members are located in Alabama, Georgia, Michigan, Minnesota, New Jersey and South Dakota. Michigan now has three identified victims—Alpena Township, Brown City and Algonac—and all three have documented ties to UIS SCADA. That concentration supports a possible shared-provider exposure, but it does not prove UIS was compromised or establish that the same actor caused all three incidents.
Campaign membership reflects evidence that an incident shared the reported operational-technology pattern or was publicly identified within a coordinated state or multistate cluster. It does not establish that every incident involved the same PLC model, access route, configuration change, infrastructure, vendor or operator. Shared timing, water-sector victimology, geography or use of one service provider is not sufficient by itself.
Michigan officials said nine water systems reported activity consistent with the federal description, but available reporting does not explicitly say whether Alpena Township, Brown City or Algonac was included in that total. Wisconsin officials detected malicious cyber activity at water facilities without naming the affected systems. CSIS also added Oregon, Arkansas and Utah to the public geographic picture, with Arkansas and Utah treated as suspected rather than confirmed.
Taken together, available reporting identifies activity or suspected activity in 10 states: eight with stronger public confirmation—Alabama, Georgia, Michigan, Minnesota, New Jersey, Oregon, South Dakota and Wisconsin—and two tentative states, Arkansas and Utah. That leaves at least two states unidentified within the reported minimum of 12. Because the national figure is a minimum rather than a complete total, the undisclosed geographic and victim scope may be larger.
Attribution remains unresolved. CSIS assessed that the campaign was likely Iranian, and public reporting described Iran as an investigative hypothesis and noted similarities to previously documented Iran-affiliated PLC activity. Federal authorities had not publicly attributed this campaign to Iran or a named group. The public victim list also remains incomplete, and the available evidence does not establish whether one actor caused every reported incident.