Skip to content

Security1 publisher3 min readPublished

CISA logged more than 100 compromised water systems in July, typically reached through cellular modems

The controllers that failed in July sat on public cellular links, outside the network boundaries utilities spent years hardening, and the only municipal record of those SIMs is a line on a carrier invoice.

The Watch · Security desk

What happened

  • CISA identified more than 100 compromised systems in the water and wastewater sector during July, typically reached through controllers connected directly to cellular modems.
  • The FBI and the EPA reported on July 30 that utilities in at least seven states had reported incidents to the FBI since July 27.
  • A Clayton County, Georgia pump station failed around 1 a.m. on July 27 and the boil-water advisory lifted the next day; in early August the authority serving more than 260,000 people said unauthorized cyber activity may have contributed.
  • No federal agency has attributed the late-July water incidents, and the joint advisory that names Iranian-affiliated actors covers a separate set of intrusions tied to the broader campaign.
  • That advisory's July 22 revision expanded known targeting from Rockwell Allen-Bradley to Schneider Electric, Siemens and potentially others, five days before utilities started reporting.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A city that finished segmenting its plant network still owns whatever equipment a vendor connected by SIM, and that path is reachable from wherever the carrier reaches.
  • constraint Triage by brand is gone: a utility can no longer scope itself out of the campaign by confirming the panel is not Rockwell.
  • decision The cheapest available control lives in the finance system rather than the security budget, which makes the first move an assignment of ownership instead of a procurement.
  • contradiction Nothing published lets a utility test whether it was in scope, because the sector-wide system count, the states-reporting count and the press count rest on three different denominators.

A cellular modem bolted onto a controller years ago generates no traffic on the city network and shows up on no scan of one [11]. It does generate a line item. Every SIM a city pays for is listed on a carrier invoice, and in most municipalities accounts payable is the only department holding that list [12]. The FBI and the EPA point utilities toward isolated architectures for this equipment, with a private access point name at the top of their list [13], which is a carrier configuration change rather than a capital project.

The counts do not line up. If the more than 100 systems CISA logged for July sat inside the seven states that had reported to the FBI, that averages over 14 compromised systems per state [21]. Press accounts citing unnamed officials put a dozen states or more in scope [3]. The Clayton County pump station went down at 1 a.m. on July 27, the same day the FBI's reporting window opens [22], so the reporting started when the operational effects did rather than ahead of them. Across the sector the reported effects were operational, meaning lost visibility and in some cases lost function [8].

Mike Searight, Waco's former chief information officer, writing in CyberScoop, describes tracing a cabinet at one of the city's water treatment plants and finding the plant's controls on the network along with the branch library and the register at the municipal golf course, in a city of 145,000 where nobody had ever been asked to inventory what was on it [15]. Most of those systems sit outside IT on the org chart, each with its own budget, vendors and boss, and in his experience exactly one engineer per city understands the whole picture, which leaves when the engineer does [16]. His argument is that two decisions matter, who is accountable for the whole network and where the funding comes from, that neither is technical, and that both sit with city managers and councils and can be settled this fiscal year out of a budget request already in motion [14].

Nothing forces the reporting that would size this. Texas gives local governments 48 hours to report a security incident, but only where it involves a personal-information breach or ransomware, so seizing control of a controller falls outside the trigger [17]. The federal 72-hour covered-incident rule was supposed to be finalized in October 2025, and Searight writes that CISA is now targeting this month [18]. On the money side, the Texas Water Development Board added cybersecurity to the scoring criteria in its State Fiscal Year 2026 Intended Use Plan for the drinking water revolving fund [19].

The editor's note attached to the piece says Waco bought network segmentation technology from Elisity while Searight was CIO and that he is now a senior adviser to Elisity [20]. Weigh that against the argument he makes: segmenting the city network would not have caught July's exposure [11], and the control he prescribes is a free reconciliation between accounts payable and the plant floor [12].

What to watch

  • Whether CISA publishes a breakdown that reconciles its 100-plus compromised systems with the FBI's seven reporting states.
  • Whether the federal 72-hour covered-incident rule is finalized this month, and whether a controller takeover with no data loss is covered by it.
  • Whether the Clayton County authority moves from 'may have caused or contributed' to a stated cause for the pump station failure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories