Late July 2026 PLC Attacks
Summary
Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, including internet-facing PLCs, causing loss of monitoring or control and some operational disruption. The FBI and EPA documented a common technical pattern, but public evidence does not establish one actor behind every incident or identify the complete victim list.
Key facts
Timeline
- Observed window: Jul 26, 2026–Jul 31, 2026
Assessment
- Status: Active
- Confidence: Medium
Evidence base
- Linked incidents: 11
- Campaign sources: 3
Recent campaign intelligence
Paid member assessment preview
Unlock the complete campaign assessment
New campaign assessments are available immediately to Sustainers, after 2 weeks to Supporters, and to everyone once they are more than 1 month old.
Sustainers help fund the research and verification behind the Cyber Incident Registry while receiving immediate access to new assessments.