🕒 Created · Updated

CISA Confirms Cyberattack on Over 100 Water Systems Was More Widespread Than Initially Reported

The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that a major cyberattack targeting municipal water systems was significantly more extensive than first reported by federal officials. While initial reports suggested approximately 30 systems in Minnesota and a few other states were affected, CISA now confirms that more than 100 water providers across 12 states were targeted. The attacks, which began in July 2026, primarily compromised programmable logic controllers (PLCs) that regulate water flow and chemical treatment. Cybersecurity experts note that while larger systems benefit from economies of scale, smaller utilities often struggle to detect threats due to limited budgets. The federal government has utilized the Safe Drinking Water Act to mandate risk-and-resilience assessments for larger systems, though compliance remains a challenge, with over 70% of inspected systems in violation of basic requirements. Policymakers are currently considering whether to establish an independent organization to set cybersecurity standards, as water systems are generally not interconnected like the electricity sector.

Sources