Cyberattacks Target U.S. Water Systems as Exposed Industrial Controls Leave Critical Infrastructure Vulnerable
New Jersey confirmed on Wednesday that two municipal water systems were compromised in cyberattacks involving internet-exposed industrial control systems (ICS). Operators temporarily lost remote monitoring and management capabilities, forcing a shift to manual operations. While water service remained uninterrupted and drinking water safe, the incidents exposed persistent security gaps in critical infrastructure.
The attacks, investigated by the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) alongside the FBI and CISA, targeted programmable logic controllers (PLCs) devices that regulate physical processes like water pressure, chemical treatment, and pump operations. Despite New Jersey’s 2017 Water Quality Accountability Act, which mandated cybersecurity programs, incident reporting, and insurance for utilities, the compromised systems were accessible via the public internet a basic security failure.
The state has not disclosed the affected utilities, leaving residents unaware of whether their water systems were breached. Investigators suspect foreign involvement, with Iran as the leading suspect, though attribution remains unconfirmed. The attacks follow a broader pattern: since July 2026, at least 12 states including Minnesota, Michigan, Wisconsin, Georgia, and New Jersey have reported similar incidents, with attackers exploiting exposed PLCs, often using default credentials.
In Georgia, a July 27 water outage in Clayton County was initially dismissed as a routine pump failure before authorities linked it to unauthorized cyber activity. Nearby Columbus Water Works also detected suspicious activity the same day, prompting a switch to manual controls. In both cases, operators restored functionality, but the delayed disclosure eroded public trust.
The vulnerabilities extend nationwide. Georgia Tech researchers identified over 7,000 internet-exposed industrial controllers across water systems, hospitals, airports, and military facilities, with only 30% of notified owners removing the devices. The FBI and CISA have warned of ongoing attacks targeting Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens controllers, with some incidents causing pressure loss and flooding.
The U.S. water sector operates under voluntary guidelines, unlike the electric grid’s mandatory federal standards. An EPA inspector general report in 2024 found 97 water systems serving 26.6 million people with critical cybersecurity risks. Despite repeated warnings, enforcement remains lax, with utilities often lacking the resources to secure aging infrastructure.
The attacks’ limited impact so far is credited to employees who recognized anomalies and operated plants manually a thin margin of safety. As remote monitoring expands to cut costs, the same access points become attack vectors. The EPA has emphasized local responsibility, but small-town water departments, often understaffed and underfunded, struggle to defend against state-sponsored cyber operations.
With no federal enforcement, the risk of escalation persists. While immediate threats focus on pressure loss and operational disruptions, prolonged outages could lead to contamination. The incidents underscore a systemic failure: warnings, laws, and compliance deadlines have not translated into real-world security. The next attack may not be caught in time.
The Waterworks cybersecurity rating report: https://www.rankiteo.com/company/thewaterworksohio
"id": "THE1786048180",
"linkid": "thewaterworksohio",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Water utilities',
'location': 'New Jersey, USA',
'type': 'Municipal water systems'},
{'industry': 'Water utilities',
'location': 'Georgia, USA',
'name': 'Clayton County Water Authority',
'type': 'Water utility'},
{'industry': 'Water utilities',
'location': 'Georgia, USA',
'name': 'Columbus Water Works',
'type': 'Water utility'}],
'attack_vector': 'Internet-exposed industrial control systems (PLCs) with '
'default credentials',
'description': 'New Jersey confirmed cyberattacks on two municipal water '
'systems involving internet-exposed industrial control systems '
'(ICS). Operators lost remote monitoring and management '
'capabilities, forcing manual operations. Water service '
'remained uninterrupted, but the incidents exposed security '
'gaps in critical infrastructure. Investigations suggest '
'foreign involvement, with Iran as a leading suspect.',
'impact': {'brand_reputation_impact': 'Eroded public trust due to delayed '
'disclosure',
'downtime': 'Temporary loss of remote monitoring and management '
'capabilities',
'operational_impact': 'Shift to manual operations, delayed '
'response to anomalies',
'systems_affected': 'Industrial control systems (PLCs) regulating '
'water pressure, chemical treatment, and pump '
'operations'},
'initial_access_broker': {'entry_point': 'Internet-exposed PLCs with default '
'credentials'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Persistent security gaps in critical infrastructure, lack '
'of federal enforcement, underfunded and understaffed '
'utilities struggle to defend against state-sponsored '
'cyber operations, reliance on manual operations as a last '
'line of defense.',
'post_incident_analysis': {'corrective_actions': 'Removal of exposed devices, '
'enforcement of '
'cybersecurity standards, '
'improved incident response '
'planning.',
'root_causes': 'Lack of network segmentation, '
'exposed industrial control '
'systems, default credentials, '
'voluntary cybersecurity '
'guidelines, underfunded utilities, '
'aging infrastructure.'},
'recommendations': 'Remove internet-exposed industrial controllers, enforce '
'network segmentation, implement mandatory federal '
'cybersecurity standards for water utilities, improve '
'incident disclosure timelines, allocate resources for '
'securing aging infrastructure.',
'references': [{'source': 'New Jersey Cybersecurity and Communications '
'Integration Cell (NJCCIC)'},
{'source': 'FBI and CISA warnings'},
{'source': 'Georgia Tech research on exposed industrial '
'controllers'},
{'source': 'EPA inspector general report (2024)'}],
'regulatory_compliance': {'regulations_violated': 'New Jersey Water Quality '
'Accountability Act (2017) '
'- failure to secure '
'exposed systems'},
'response': {'communication_strategy': 'Delayed disclosure in some cases',
'containment_measures': 'Switch to manual operations, removal of '
'exposed devices (in some cases)',
'law_enforcement_notified': 'Yes',
'recovery_measures': 'Restored functionality in affected systems',
'third_party_assistance': 'FBI, CISA, NJCCIC'},
'threat_actor': 'Suspected foreign involvement (Iran as leading suspect)',
'title': 'Cyberattacks Target U.S. Water Systems as Exposed Industrial '
'Controls Leave Critical Infrastructure Vulnerable',
'type': ['Cyberattack', 'Unauthorized Access'],
'vulnerability_exploited': 'Exposed programmable logic controllers (PLCs), '
'lack of network segmentation, default credentials'}