INSIGHTS | September 11, 2026

Worse Than First Reported: What CISA’s Revised Water Sector Numbers Mean for Every Utility

Key Takeaways

  • CISA has confirmed that the July 2026 campaign against US water utilities targeted more than 100 internet-exposed systems across at least 12 states — over three times the roughly 30 Minnesota systems disclosed when the story first broke [2][4].
  • Georgia, Michigan, South Dakota and New Jersey have since confirmed their own incidents, including a precautionary boil-water advisory at a Georgia utility that was lifted after testing showed no water quality impact[5].
  • A second, separate joint advisory (AA26-231A), published August 19, describes threat actors using AI-generated exploitation scripts, disguised as legitimate monitoring tools, to probe internet-exposed Siemens S7 PLCs across six critical infrastructure sectors — reconnaissance and capability development, not yet confirmed disruption [6].
  • CISA followed up on August 21 with exposure-reduction guidance repeating, in near-identical language to April’s advisory, that PLCs should never be reachable directly from the internet through a cellular modem [3].
  • The revised numbers surfaced in a reporting vacuum: the federal CIRCIA rule that would mandate incident reporting for water utilities is still not final, with CISA now targeting September 2026, and at least one major state (Illinois) has no requirement at all for a utility to disclose a hack to the public or to law enforcement [9][2].

Why This Update Matters Now

Our first analysis of this campaign treated the Minnesota incidents as a measurement problem: how much distance sits between a federal advisory being issued and a utility being able to act on it. A month later, CISA has revealed that the measurement itself was wrong. The number of affected systems was not roughly 30. It was more than 100, spread across a dozen states, and the agency is only now saying so publicly [2][4].

That is not a minor correction. It means that for a month, water sector leaders, state regulators and the public were making risk decisions — about disclosure, about board briefings, about whether “this happened in Minnesota, not here” was a safe assumption — based on a picture that undercounted the actual campaign by a factor of three or more. Officials in the other 11 states now confirmed as targets did not get a warning proportional to what was actually happening in their sector, because no one outside the investigation knew the true scope yet.

Layered on top of that, a second, unrelated advisory has emerged describing attackers using AI-assisted tooling to build exploitation scripts against a specific, widely deployed PLC family. Whether or not that activity is connected to the July campaign, it confirms something water sector leaders should plan around regardless of attribution: the tooling gap between a nation-state operator and a lower-skilled one is narrowing, and it is narrowing fastest against exactly the kind of internet-exposed OT this campaign has repeatedly exploited.

What CISA Actually Confirmed on August 26

Reporting by NBC Chicago’s investigative team surfaced a line from CISA’s own guidance that had not previously drawn attention: “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem” [2][3]. The Register independently confirmed the same figure and noted it is the first time federal officials have put a specific number on the intrusions, though the campaign still has not been attributed to a named actor or group [4].

The 12 states are still not fully identified in public reporting, but Minnesota, Michigan, Georgia, South Dakota and New Jersey have each had incidents confirmed through state or utility disclosures [4][5]. In Georgia, Clayton County Water Authority reported a temporary disruption to a portion of its operational systems and water service, and issued a precautionary boil-water advisory that was lifted once testing confirmed water quality was unaffected; a nearby utility, Columbus Water Works, reported a separate cyber incident days later [5]. In South Dakota, a utility serving Rapid City reported an incident consistent with the same pattern [5]. The FBI, in a joint public service announcement, described the operational effects bluntly: loss of pressure and flooding, with pressure loss creating the potential for untreated groundwater to seep into distribution pipes [5].

Illinois has not been named among the 12 affected states. NBC Chicago’s reporting draws out why that distinction may be less reassuring than it sounds: the state has no law requiring a water utility to notify law enforcement or the public after a cyber incident. As the report put it, “the bitter reality is, even if they know, we might not” [2]. Illinois is not unusual in this respect. It is a reminder that the 12-state figure reflects what has been detected and voluntarily disclosed, not necessarily the outer bound of what occurred.

Three Federal Advisories in Five Weeks

Operators tracking this campaign have now had to absorb three substantive federal releases in a five-week window, on top of the original April advisory:

  • July 22 — the update to AA26-097A widened observed Iranian-affiliated PLC targeting from Rockwell to include Schneider Electric and Siemens devices, and added detection guidance for tampered logic modules [1].
  • August 19 — the new joint advisory AA26-231A, authored by NSA, CISA, the FBI, the Department of Energy and the EPA, describes threat actors using AI-generated exploitation scripts disguised as legitimate OT monitoring tools to conduct reconnaissance against internet-exposed Siemens S7 Series PLCs (the S7-200 through S7-1500 families) over the S7comm protocol on TCP port 102 [6]. The activity spans Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities [7]. CISA’s own advisory text is careful to frame this as reconnaissance and capability development, not confirmed operational disruption, and notes explicitly that the underlying exposure problem is broader than Siemens equipment alone [6]. No CVE and no indicator set accompany the advisory; the actionable finding, as several outlets have observed, is unglamorous and predates the AI framing entirely — an unauthenticated industrial protocol reachable from the open internet [8].
  • August 21 — CISA’s Internet Exposure Reduction Guidance restated the same core instruction that has now appeared in every release since April: route remote access through a secure gateway, firewall or VPN, never connect a PLC, HMI or RTU directly to the internet, and require unique credentials and phishing-resistant MFA for anything that must remain remotely reachable [3].

None of these three releases describes a new class of vulnerability. Each restates a known architectural failure — direct internet exposure of OT — and observes it being exploited at a scale that keeps expanding. For a sector already short on cybersecurity staff, three federal releases in five weeks is not a cadence that most utilities are resourced to fully absorb, verify against their own asset inventory and act on before the next one arrives.

What This Means for Operators Outside the Named States

Water and Wastewater Operators, Regardless of State

If your state has not been named among the 12, that is evidence about what has been disclosed, not evidence about your exposure. The campaign’s access method — internet-reachable PLCs, frequently connected through cellular modems installed by an integrator or vendor rather than the utility itself — is a function of how a given asset was deployed, not of which state it sits in [2][3].

Critical Manufacturing, Energy, Chemical, and Food and Agriculture Operators

AA26-231A extends the named target list beyond water and wastewater to five additional sectors, all sharing the same underlying pattern: Siemens S7 controllers reachable from the internet, with reconnaissance activity that could evolve into the same operational effects seen in the water sector campaign [6][7].

State Regulators and Legislators

The gap in Illinois — no requirement for a utility to disclose an incident to the public or to law enforcement — is not an isolated gap. It is a preview of what a September 2026 CIRCIA final rule is meant to close nationally, and a reminder that until it takes effect, disclosure in most states remains voluntary [9][2]. Officials weighing state-level reporting requirements now have a concrete, recent example of how much of a real campaign’s scope can remain unknown for a month under the status quo.

System Integrators and OT Suppliers

Cellular modems installed for remote telemetry, and engineering software used for legitimate configuration, both continue to be the access points described across every advisory in this campaign. Where an integrator made the connectivity decision, the resulting exposure is frequently outside the asset owner’s own visibility, and it is the integrator’s documentation, not the utility’s network diagram, that will show it [1][3].

What Are the Practical Challenges for Operators?

A Threefold Undercount Changes the Board Conversation

A leadership team or governing board that was briefed on “a Minnesota incident” in late July is now working from materially different facts. Whatever risk posture, budget request or public statement was built on the original scope should be revisited against the confirmed 100-plus systems and 12-state footprint, not left as originally briefed [2][4].

AI Lowers the Barrier to Building Working OT Exploitation Tooling

AA26-231A’s most consequential detail is not the Siemens targeting itself but the method: publicly available device documentation, combined with an AI coding assistant and open-source libraries, was reportedly sufficient to produce functional scripts capable of reading and writing PLC memory over a known protocol [6][7]. That is a capability that previously required specialized ICS tradecraft. It does not change what the correct mitigation is — the same segmentation and exposure-reduction controls apply — but it does mean the population of actors capable of acting on an exposed asset is larger than it was when the April advisory was written.

Disclosure Remains Voluntary in Most Places, Which Means Scope Estimates Should Be Treated as Floors

With CIRCIA’s mandatory reporting rule still pending and state-level requirements inconsistent, the 12-state, 100-system figure should be read as the confirmed floor of the campaign’s scope, not its ceiling. Operators and officials should plan on the assumption that additional incidents have occurred and gone unreported, rather than treating the absence of their state’s name as reassurance [9][2].

Advisory Fatigue Is Now a Documented Pattern, Not a Hypothesis

Our first analysis raised advisory fatigue as a risk. It is no longer speculative. Three federal releases inside five weeks, each restating the same architectural fix, is direct evidence that the constraint is not awareness — it is the engineering and coordination capacity to act on what has already been published.

How IOActive Can Help

The revised scope of this campaign does not change the underlying gaps our first analysis identified — assessment boundaries that stop short of remote, cellular-connected assets, and the absence of a validated baseline for controller logic. It does change the urgency, the number of sectors in scope, and the case for treating “we weren’t named” as insufficient reassurance. The services below map directly to what this update reveals.

Full Stack Security Assessments

With six sectors now named across two advisories, and internet-reachable PLCs confirmed as the common access point regardless of state or industry, the priority is establishing ground truth about your own estate — not relying on the absence of your name from a news story. Our Full Stack Security Assessments scope beyond the network and application layer to the facility and silicon level, verifying every internet-facing PLC, HMI and RTU against the live environment, including the cellular-connected remote assets that integrator-built architectures routinely place outside an asset owner’s visibility.

This is not a hypothetical exercise for our team. In a recent security advisory, IOActive researcher Ethan Shackelford identified and disclosed multiple vulnerabilities in the KUNBUS Revolution Pi, a DIN-rail industrial PC widely deployed for automation and process control — the same category of device implicated in this campaign, just from a different vendor [12]. The findings included an authenticated command injection in the device’s web management interface that led to arbitrary code execution (CVE-2024-8684), a directory traversal exposing system files (CVE-2024-8685), and a years-out-of-date sudo binary that allowed local privilege escalation to root (CVE-2021-3156). It is the same underlying pattern the CISA advisories describe: a web-exposed administrative interface on an industrial controller, reachable further than intended, with unsanitized input standing between an authenticated session and full device compromise. KUNBUS fixed all three findings following coordinated disclosure. This kind of assessment — treating the PLC’s own management interface as an attack surface, not just its network position — is exactly what a Full Stack engagement is built to find before an adversary does.

Red Team and Purple Team Services

AA26-231A describes reconnaissance and capability-building against a named protocol (S7comm) using AI-assisted tooling built from public documentation [6]. Our Red Team engagements can emulate that exact tradecraft against your environment — including AI-assisted script generation aimed at your specific controller inventory — while our Purple Team work confirms whether your team would detect it before it progresses from reconnaissance to the disruption pattern already documented at Minnesota, Georgia and South Dakota utilities.

Supply Chain Integrity

The access method across every advisory in this campaign is a cellular modem or remote-access path installed by a vendor or system integrator. Our Supply Chain Integrity service reviews the security posture and connectivity decisions of the third parties who built your control system architecture, closing the visibility gap before it becomes the next disclosed incident.

Advisory Services

With CIRCIA’s final rule now targeted for September 2026 and state disclosure requirements inconsistent in the interim, utilities and their counsel need a clear-eyed view of what reporting obligations already apply and what is coming. Our Advisory Services — programmatic security review, security program development, and Virtual CISO support — help translate this campaign’s revised scope into a board-ready risk picture and a prioritized remediation plan, rather than a reactive response to the next news story.

AI/ML Security Services

As attackers increasingly use AI coding assistants to generate reconnaissance and exploitation tooling, defenders benefit from the same fluency in how that tooling behaves. Our AI/ML Security threat-modeling work extends to evaluating your exposure to AI-assisted attack techniques, complementing the OT-specific assessments above rather than replacing them.

Training

Many of the utilities affected in this campaign are small systems without dedicated cybersecurity staff. Our staff augmentation and Virtual CISO offerings let a resource-constrained utility or municipal IT department bring in the OT security expertise needed to act on these advisories without a multi-year hiring cycle.

1. Re-brief leadership using the confirmed scope, not the original one. If your board or council was told this was a Minnesota-only event, correct the record before the next report cycle.

2. Treat your state’s absence from the 12 as unconfirmed, not clean. Verify your own internet-facing PLC, HMI and RTU inventory directly rather than inferring safety from news coverage.

3. Extend hunting to AA26-231A’s specific indicators. Look for engineering software or S7comm traffic (TCP port 102) originating from unexpected hosts, particularly if you operate Siemens S7-series controllers [6].

4. Confirm your remote-access architecture routes through a managed gateway. Direct PLC-to-internet paths via cellular modem remain the confirmed access method across every release in this campaign [2][3].

5. Check your state’s disclosure requirements now, before an incident forces the question. Do not assume CIRCIA’s federal rule already applies; it is not yet final [9].

6. Document what you would report and to whom, under both current voluntary norms and CIRCIA’s proposed 72-hour and 24-hour timelines, so the mechanics are already in place before September’s rule finalization.

7. Rehearse detection of the manipulation scenario, not just the outage scenario, as our first analysis recommended — this campaign’s revised scope makes that exercise more urgent, not less.

Conclusion

The story a month ago was that a warning arrived first and a sector-wide incident followed four days later. The story now is that the incident itself was three times larger than anyone said publicly for the following month. Both facts point at the same underlying constraint: the water sector’s capacity to detect, verify, and disclose is not keeping pace with either the scale of what is being attempted against it or the speed at which the tooling to attempt it is becoming available. A federal reporting mandate is coming, but it is not here yet, and in its absence, the confirmed numbers in any advisory should be read as a floor.

If you would like to discuss how your organization’s controller exposure measures up against the activity described here — across water, energy, manufacturing, chemical or food and agriculture — or how IOActive can support your OT/ICS resilience program, we welcome the conversation.

References

[1] CISA, FBI, NSA, EPA, DOE, CNMF and US Department of the Treasury. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A), published April 7, 2026, updated July 22, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

[2] C. Goudie, L. Capitanini, N. Halder. Government admits water system cyberattacks were worse than first reported, NBC Chicago, August 26, 2026. https://www.nbcchicago.com/investigations/government-admits-water-system-cyberattacks-were-worse-than-first-reported/3980961/

[3] CISA. Internet Exposure Reduction Guidance, published August 21, 2026. https://www.cisa.gov/resources-tools/resources/exposure-reduction

[4] J. Lyons. More than 100 water systems were hit in July cyberattacks, The Register, August 26, 2026. https://www.theregister.com/cyber-crime/2026/08/26/more-than-100-water-systems-were-hit-in-july-cyberattacks/5292685

[5] J. Greig. Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents, The Record (Recorded Future News), August 5, 2026. https://therecord.media/iran-cyberattacks-water-treatment

[6] NSA, CISA, FBI, DOE and EPA. Defending Against an Active Threat to Siemens S7 Series PLCs (AA26-231A), August 19, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a

[7] AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure, The Hacker News, August 2026. https://thehackernews.com/2026/08/ai-generated-exploit-scripts-target.html

[8] CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes, Industrial Cyber, August 2026. https://industrialcyber.co/industrial-cyber-attacks/cisa-nsa-fbi-warn-of-siemens-s7-plc-exploitation-using-ai-generated-scripts-to-disrupt-critical-industrial-processes/

[9] Federal News Network. CIRCIA, other big cyber rules expected to get finalized this fall, July 10, 2026. https://federalnewsnetwork.com/cybersecurity/2026/07/circia-other-big-cyber-rules-expected-to-get-finalized-this-fall/

[10] Testimony before the US Senate Committee on Environment and Public Works. The Cybersecurity State of the Water Sector, February 4, 2026. https://www.epw.senate.gov/public/_cache/files/5/3/53d93dfe-ed8c-4e48-b705-0b16cb92c90a/FA38A32EE48D7F3D4B0C069FDC08A69E6327376EB85838A03310B2E91C8582C1.02-04-2026-dr.-simonton-testimony.pdf

[11] House of Lords Library. Cyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026–27, June 2026. https://lordslibrary.parliament.uk/research-briefings/lln-2026-0032/

[12] IOActive Security Advisory. KUNBUS Revolution Pi – Multiple Vulnerabilities (CVE-2024-8684, CVE-2024-8685), discovered by Ethan Shackelford, published March 28, 2024, CVE IDs added February 11, 2025. https://www.ioactive.com/wp-content/uploads/2025/05/IOA-SecAdvisory-KUNBUS-Revolution-Pi.pdf

[13] IOActive. When the Advisory Arrives First: Minnesota’s Water Utilities and the Limits of Warning, August 10, 2026. https://www.ioactive.com/when-the-advisory-arrives-first-minnesotas-water-utilities-and-the-limits-of-warning/