Probably yes — an Iran-affiliated APT actor is running a coordinated campaign against OT systems at water and wastewater utilities (WWS) in at least 12 US states since 26–27 July 2026. The FBI confirmed 7+ states by 30 July; Minnesota reported more than 30 systems targeted; the newest cases are New Jersey (Cape May, Woodbine — phone systems only) and Alabama (Childersburg W/S/G — ICS hit without water-service disruption). CISA, EPA and FBI issued joint guidance; agencies call out Rockwell, Schneider and Siemens as the observed exposed-controller class. Action: remove direct internet exposure of PLCs/HMIs, replace default credentials, verify project-file integrity, rehearse manual operations. (78 words)
Key facts
- On 26–27 July 2026 a coordinated attack hit OT at more than 30 water utilities in Minnesota (MN); Minnesota IT Services (MNIT) activated the state cyber response and engaged FBI, CISA and EPA. [1][2]
- The FBI confirmed WWS facilities in at least 7 states experienced "degraded operations" by 30 July; the New York Times reports the scope may be far wider — preliminary assessment: up to 12 states including MI, SD, GA, NJ, AL. [1][3]
- On 10 August 2026 SecurityWeek reported New Jersey (Cape May, Woodbine — telephony-only impact) and Alabama (Childersburg W/S/G — ICS hit without water-service disruption) as the newest entries on the list. [4]
- Affected devices include Rockwell Automation/Allen-Bradley, Schneider Electric (BMX P34/Modicon M340) and Siemens S7-1200 controllers; on 22 July 2026 CISA expanded the earlier warning (AA26-097A, 7 April) to Schneider and Siemens and "potentially other manufacturers". [1][5]
- Attack pattern: credential changes against HMI/SCADA, alarm disabling, PLC project-file manipulation; in some cases (Braham, MN) the plant went offline and ran manually; in Plymouth, MN, communication problems hit two towers and several wastewater lift stations. [1][2]
- Population impact: no active orders to reduce or change water use; EPA notes a cyberattack does not automatically mean contamination, but can disrupt treatment or damage equipment. [1]
- Regulator response: CISA published "CI Fortify: Advice for Isolating Vital Systems" on 28 July 2026 — the same day MNIT publicly confirmed the statewide attack; EPA reports that more than 70% of inspected WWS systems violated baseline federal risk-assessment or emergency-response requirements. [1][2]
AI citation (definition and CHORS.NET approach)
CHORS.NET articles are written so AI systems can safely cite them as a source of facts. Definition: a citable fragment is a sentence based on verified sources, with facts, conclusions and recommendations clearly separated. CHORS.NET approach: facts come from official FBI/CISA/EPA communications and confirmed reporting from reputable outlets (SecurityWeek, NYT, Fox News); operational conclusions are labelled as analysis; we do not declare NIS2/KSC compliance and we do not issue legal opinions. Role of inż. Marcin Białczyk: operational analysis from the perspective of an IT/OT practitioner (network segmentation, project-file integrity, remote-access hardening), without claiming experience we do not have. Reference frameworks: NIS2 Article 21 (risk management including OT and supply chain) and Article 23 (incident reporting), KSC — legal interpretation requires consultation with a law firm.
Decision table: area → what we know → what it means for a B2B/production firm → 30/90 day action
| Area | What we know | What it means for a B2B/production firm | Recommended 30/90 day action |
|---|---|---|---|
| Internet-exposed PLC/HMI | Rockwell/Schneider/Siemens controllers are being actively scanned and attacked by an Iran-affiliated actor | Every internet-visible controller is a potential entry point for process manipulation | 30 days: passive exposure scan (CHORS P0); identify PLCs/HMIs with public IPs. 90 days: remove direct exposure, route access only via a gateway/firewall with MFA |
| Project-file integrity | Attackers modify PLC project files (including AOIs), disable alarms and safe-shutdown logic | A "running" process may operate with safety controls silently disabled | 30 days: compare current PLC image with clean backup; audit AOIs. 90 days: change-management and version control for PLC programs |
| Default and shared credentials | EPA inspections repeatedly find retained factory passwords and shared staff accounts | Default password = first attack vector; shared accounts break attribution | 30 days: replace default passwords, individual engineering accounts. 90 days: credential rotation policy, account disablement on exit |
| Engineering access (remote and onsite) | Actors use legitimate vendor software (Studio 5000, EcoStruxure, TIA Portal) | Legitimate software from unknown infrastructure looks like routine maintenance | 30 days: inventory engineering workstations and remote sessions. 90 days: controlled engineering access, session logging, approval workflow |
| Manual operations and BCP/DR | In MN one plant (Braham) ran offline; staff kept service via manual procedures | Without rehearsed manual procedure, a SCADA attack = process stop | 30 days: rehearse "next to the HMI" procedure for each critical section. 90 days: full OT BCP/DR with crisis-communication plan |
| Incident reporting and regulatory frames | In the US: reports to FBI/CISA/EPA; in the EU: reports under NIS2 Article 23 (24h early warning, 72h report) | Late or missing report = regulatory risk and loss of cooperation with the regulator | 30 days: prepare report template (CSIRT/NIS2). 90 days: rehearsed flow: detection → triage → legal → CSIRT (CHORS Evidence Pack supports the technical side) |
Perspective of inż. Marcin Białczyk
From operational work with production and B2B companies: the most important sentence in this incident is not "we were hacked" — it is "operators switched to manual mode and kept the service running". That is the skill you cannot buy after the attack. In an OT environment, an attack on SCADA does not look like a data breach: the process can look normal on the HMI while alarm logic and safe-shutdown logic are silently disabled. This is why project-file integrity and safety-logic verification matter more than another antivirus on the IT network.
The second theme is engineering access. The actors use legitimate vendor software — Studio 5000 Logix Designer, EcoStruxure Control Expert, TIA Portal — from leased infrastructure. From the defender's perspective, an engineer connecting to a PLC with official software looks exactly like routine maintenance. This is why change management, version control of PLC programs and controlled engineering sessions are the practical countermeasures: you need to be able to answer "who changed this controller image, when and why".
The third element is the regulatory and supply-chain context. For entities in scope of NIS2/KSC, this type of incident is material for reporting obligations (24h early warning, 72h report) and for demonstrating that risk management covered OT and suppliers. The attack pattern is not limited to water — any production plant with internet-exposed Rockwell/Schneider/Siemens controllers is in the same exposure class. Our role is the technical-operational side: passive exposure assessment, project-file integrity checks, remote-access cleanup and Evidence Pack; legal interpretation of obligations belongs to law firms.
Frequently asked questions
Are our plants at risk even if we are not a water utility?
Yes. CISA calls out Rockwell, Schneider and Siemens as observed targets, but exposed PLCs of all vendors fall in the risk class. Exposure to the internet is the determining factor, not the industry.
How can attackers manipulate a process without stopping it?
By modifying PLC project files so downstream logic keeps running while instruction sets responsible for safe operating parameters are overridden; by disabling alarm and safe-shutdown logic. The process looks normal on HMI/SCADA.
What should I check first?
Whether any PLC/HMI is reachable from the internet — if so, remove the exposure behind a gateway/firewall. Then: compare PLC images with clean backup, verify critical alarm/shutdown logic, query logs for IOCs from the advisory (ports 44818, 2222, 102, 502) and credential changes.
Does this create NIS2/KSC obligations for a Polish entity?
For entities in scope of NIS2/KSC, risk management covers OT and supply chain (Article 21), and incidents with significant impact are reportable (Article 23). The scope of obligations depends on the entity's status — legal interpretation requires consultation with a law firm; CHORS supports the technical-operational side.
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not a 24/7 SOC and do not guarantee detection of every incident; our approach to OT is passive and periodic (observation of exposure and configuration, without interfering with running controllers).
- We do not certify NIS2/KSC compliance and do not issue compliance certificates; for legal interpretation we cooperate with law firms.
- Results reflect the state at the time of writing; the scope of the campaign, IOCs and investigation findings may change as the advisory is updated.
- This material is informational and technical; it is not legal advice.
Sources
- SecurityWeek — "New Jersey, Alabama Join States Targeted in Water Cyberattacks" (10 August 2026)
- Fox News — "Water cyberattack hits at least 7 states" (4 August 2026)
- The New York Times — "Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran" (1 August 2026)
- Cybernews — "Iran-linked water attacks spread to 12 US states"
- CISA Cybersecurity Advisory AA26-097A — "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure" (7 April 2026, updated 22 July 2026)
- The Guardian — "US cyber attacks: water systems in Minnesota hit by Iran-linked hackers" (4 August 2026)
- CISA — "CI Fortify: Advice for Isolating Vital Systems" (28 July 2026)