Security1 distinct publisher2 min readPublished
The count federal agencies had not published arrives attached to a remediation list that begins with taking inventory, which says more about this campaign than the attribution does.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A programmable logic controller with its own cellular modem answers to a carrier network rather than to anything the IT department fronts, and CISA says that is the path the July activity commonly took [2]. The guidance does not say how those links came to exist. It says only that leaving PLCs and other industrial control systems reachable by cellular modem or the public internet is what enabled the activity against water and wastewater utilities [10].
The order of CISA's advice is the tell. It begins with identifying every internet-accessible system through internal inventories and external scanning, and only then asks which of those exposures operations actually require [8]. Everything that follows, including default password changes, security updates, remote access through gateways or jump hosts, multifactor authentication and traffic monitoring, applies to assets an operator already knows it owns [9]. An agency confident that water utilities held that list would not have led with building it.
The published arithmetic is thin in a specific way. Over 100 systems [1] spread across the at least 12 states the report places in scope [5] averages about eight per state [14]. Six states have confirmed publicly that they were targeted [6], which leaves at least six affected states unnamed in the public record [13]. Both figures are floors, so the per-state number is a shape rather than a measurement, and there is no published breakdown by utility size to tell whether the exposure sits mostly in small unstaffed sites.
Attribution and intent come from the same reporting: activity linked to Iranian threat actors, aimed at disrupting operational technology [3]. No significant disruption resulted [4], which describes an outcome and not the reach. The distinction matters because the remediation CISA is asking for does not depend on the intruders having done anything at all. A controller answering the public internet is the finding. This also arrived on the heels of CISA warnings about Iran-linked attacks on ICS built by Siemens, Schneider Electric and Rockwell Automation [11], so the vendor advisories and the exposure advisory are pointing at the same equipment population from opposite ends.
The last line of the guidance is the one utilities will find most expensive: reassess regularly, because networks and third-party connections keep changing [12]. That reframes internet exposure as a condition that returns whenever an integrator, a contractor or a maintenance visit adds a link, not a defect that a single scan retires. Water systems that treat this as a one-time cleanup will produce a clean inventory and then drift away from it, and the next count will be someone else's number to publish.
Ranked by verification strength, evidence, and original report placement.
CISA said it is aware of over 100 internet-exposed systems in the Water and Wastewater Systems sector targeted by malicious cyber activity in July 2026.
CISA said the activity came commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.
The water sector attacks are linked to Iranian threat actors and sought to cause disruption to operational technology systems.
The cyberattacks did not manage to cause any significant disruption.
Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.
CISA's updated guidance recommends first identifying all internet-accessible systems via internal inventories and external scanning tools, then determining which exposures are truly necessary for operations and removing or restricting the rest.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Direct agency quotation, single outlet, unlinked primary
The core numeric claim is a verbatim CISA quotation and the remediation steps are enumerated in detail, which is strong for a first disclosure. However the cluster contains exactly one publisher, the underlying guidance document is not linked or cited by title, and the secondary scope figure (at least 12 states) is explicitly not confirmed by government, so parts of the record cannot be checked within the supplied material.
Real-world targeting documented; remediation uptake unknown
There is concrete real-world footprint: 100-plus exposed systems actually targeted, six states confirming, and a published federal guidance artifact. What is entirely absent is any evidence that utilities have implemented the recommended inventory, exposure reduction or hardening, or that exposed PLC-on-modem deployments have declined, so the guidance side of the story shows publication without measurable follow-through.
Restrained relative to the exposure it documents
The report stays inside CISA's own wording, states plainly that no significant disruption occurred, and pairs the count with routine hygiene steps rather than catastrophe framing. If anything it understates: both headline figures are floors, at least six affected states remain unnamed, and the enabling condition (control systems directly reachable over cellular links) is presented as a checklist item rather than a structural finding. The small positive pull in the other direction is the flat restatement of Iranian attribution and disruptive intent without a cited advisory.
Agency disclosure paired with its own guidance push
The count was released by CISA as part of guidance urging organizations to shrink internet exposure, so the disclosing party has an institutional interest in making the exposure problem legible and in driving uptake of its recommendations; the sequencing after its Siemens/Schneider/Rockwell ICS warnings fits the same campaign. The publisher is security trade press with an attention interest in critical-infrastructure threat coverage. No vendor sponsorship, commercial product promotion or funding stake is disclosed in the supplied material, which caps this score.
Quoted core fact, uncorroborated periphery
Confidence is moderate: the central quantified claim and the remediation list are quoted or enumerated closely enough to rely on, but everything around them - state scope, attribution, technical depth of the intrusions, remediation follow-through - rests on one outlet with no linked primary source and explicit hedging in the text itself.
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
product
Emerald AI is worth $1.05bn on the theory that grid headroom is a scheduling problem1 distinct publisher
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026