Twelve US states reported water system intrusions; the FBI still has not named who was behind them
Federal alerts confirm remote tampering with water and wastewater controls, including logic that overrode safety parameters at one plant. The attribution gap has now stayed open for three weeks.
The technical core of the case is in CISA advisory AA26-097A, updated on 22 July. The FBI reported that at one US victim organisation the actors used configuration software to download a malicious project file to a targeted programmable logic controller. Analysis indicated the file retained ladder logic for downstream function but added logic overriding specific instruction sets responsible for maintaining safe operating parameters. That is manipulation of a plant’s safety envelope, not a defacement. In the week of 27 July to 1 August, at least seven states reported cyberattacks interrupting water or wastewater operations, and the FBI and EPA issued a joint alert warning that “malicious cyber actors” have been remotely tampering with water systems; in Minnesota, operating technology at more than 30 water systems was targeted, according to the Washington Post reporting of Amy B Wang, Ellen Nakashima and Pranshu Verma on 1 August. Axios put the count at 12 states on 4 August. Route Fifty reported further systems struck around 10 August.
The intrusions are confirmed by federal alert. The attribution is not. The Washington Post’s framing is that US spy agencies suspect Iran; NewsNation reported that the FBI had not confirmed who was behind the attacks. CISA’s own formulation, in place since it identified disruption at US critical-infrastructure sites through victim engagements dating to at least March 2026, is “Iranian-affiliated” — a deliberately loose term that covers aligned criminal crews and hacktivist groups as well as state units. The distinction is not pedantry. The publicly circulating water-sector material from this conflict includes hacktivist video of valve and pH controls posted as a boast, a genre in which the claim and the capability are frequently mismatched in both directions.
Assessment: Watch how the gap closes, not just whether. An attribution delivered through an unattributed official briefing to a national outlet is a political act with a timetable; one delivered through an indicator-bearing advisory is an evidentiary one, and the two should not be reported in the same register. Note also the asymmetry in what is quantified: the American numbers are counts of affected utilities published by federal agencies, while the region’s other headline figures — Israel’s National Cyber Directorate reported roughly 4,800 hostile incidents in June 2026 against 1,600 in June 2025 — are a belligerent’s self-defined tallies with no published methodology. Treat the units before you treat the trend.