Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems
Recent attacks on water and wastewater systems in Minnesota, Michigan, Canada, and elsewhere show that exposed PLCs, HMIs, cellular modems, and weak remote-access setups can allow attackers to disrupt physical operations without advanced malware. The incidents are technically similar to an Iranian-affiliated PLC campaign, while separate claims by NoName057(16) and Z-Pentest show that hacktivists are also targeting water infrastructure. #MicroLogix1100 #MicroLogix1400 #NoName05716 #ZPentest #CyberAv3ngers #Unitronics

Keypoints

  • More than 30 Minnesota community water systems were targeted in coordinated attacks on July 26–27, 2026.
  • Related activity was reported in at least seven U.S. states, with Michigan identifying nine affected water systems.
  • Attackers remotely accessed exposed PLCs, changed IP addresses and passwords, and in some cases modified project files or ladder logic.
  • Observed impacts included loss of pressure, flooding, communications outages, boil-water notices, and temporary manual operations.
  • The Minnesota incidents share similarities with an Iranian-affiliated PLC campaign documented in Joint Cybersecurity Advisory AA26-097A, but attribution remains unconfirmed.
  • Publicly confirmed and claimed incidents in Ontario and Quebec show that pro-Russian hacktivists are also probing water-sector OT systems.
  • The report stresses that insecure exposure, legacy equipment, and weak third-party remote access can be enough to disrupt water operations without custom ICS malware.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – Attackers abused internet-facing PLCs and remote-access paths to reach OT devices (‘internet-facing PLCs’ and ‘exposed controllers’).
  • [T1021 ] Remote Services – The actors used remote access to connect to controllers and infrastructure over exposed services (‘remote-access services’ and ‘remotely accessed exposed PLCs’).
  • [T1078 ] Valid Accounts – Attackers changed passwords and likely leveraged credentials or weak authentication to maintain access (‘changed their IP addresses and passwords’).
  • [T1606 ] Forge Web Credentials / Password Manipulation – Credential and access settings on PLCs were altered to block operator access (‘changed their IP addresses and passwords’).
  • [T0831 ] Manipulation of Control – The campaign modified PLC logic and control behavior to affect physical processes (‘modified control logic’ and ‘changed ladder logic’).
  • [T0829 ] Remote System Discovery – Operators identified malicious interaction across multiple sites and devices, indicating reconnaissance of exposed OT assets (‘multiple victims’ and ‘similar hardware and remote-access architectures’).
  • [T0883 ] Establish Accounts / Persistence via Configuration Change – Attackers used configuration changes on controllers and modems to preserve access or disrupt recovery (‘modified PLC project files’ and ‘Dropbear SSH on a victim modem’).
  • [T0868 ] Alarm Suppression – The advisory notes changes that disabled critical alarms and shutdown logic (‘disabled critical alarms and shutdown logic’).
  • [T0886 ] Remote Services: SSH – Dropbear SSH was used on a victim modem to establish remote access (‘Dropbear SSH on a victim modem’).

Indicators of Compromise

  • [IP addresses ] PLC access and configuration changes were made on exposed controllers – changed IP addresses, public IP addresses
  • [File names / project files ] Controller logic and engineering project artifacts were modified or reviewed – PLC project files, ladder logic files
  • [Device / product names ] Affected and targeted OT equipment families – Rockwell Automation MicroLogix 1100, MicroLogix 1400, CompactLogix, Micro850, Schneider Electric Modicon M340, Siemens S7-1200
  • [Software names ] Legitimate engineering tools used in the activity – Studio 5000 Logix Designer, EcoStruxure Control Expert, Siemens TIA Portal, RSLogix 500, RSLogix 5000, LogixPro 500
  • [Network ports ] OT protocols and remote-access ports observed in the campaign – TCP 44818, 2222, 102, 502, and port 22 (SSH)
  • [Organizations / infrastructure names ] Entities and infrastructure cited in the incidents – Minnesota IT Services, CISA, FBI, EPA, Braham, Plymouth, South St. Paul, Maple Plain, Saint-NoĂŤl
  • [Domains / hosting / infrastructure ] Remote-access and third-party infrastructure were discussed as attack paths – vendor-maintenance interfaces, cellular modem services, third-party network configurations


Read more: https://www.levelblue.com/blogs/spiderlabs-blog/review-of-the-july-2026-cyberattacks-against-u.s.-water-and-wastewater-systems