Executive Summary
In July 2026, cyberattacks targeting water supply and wastewater operations systems in the United States (US) have illuminated persistent cyber vulnerabilities within the Critical Infrastructure (CI) sector. American officials have assessed that Malicious Cyber Actors (MLAs) are increasingly exploiting internet-facing components and control systems used in Operational Technology (OT) and industrial control systems across multiple CI sectors. Although attribution remains under investigation, these cyberattacks occurred during a moment of heightened geopolitical tensions involving the US, Israel, and Iran, where concerns have mounted around CI as a potential target in grey-zone warfare tactics. These recent incidents underscore the growing need for reinforcing cybersecurity practices, improved network segmentation techniques, and enhanced threat detection workflows in the water supply and wastewater management sectors—and perhaps across CI more broadly.
Introduction
The ongoing conflict between the US, Israel, and Iran has created a geopolitical backdrop against which concerns have mounted regarding cyber threats to US CI. Between July 26th and July 27th, at least seven US states experienced malicious cyber activity targeting water supply and wastewater management operations through a coordinated offensive campaign.
These incidents follow recent warnings from federal agencies about suspected Iranian cyber threats targeting American CI. Although investigations into these incidents are still ongoing as federal officials attempt to further assess whether Iranian actors were involved, public attribution has not confirmed any actor.
Discussion
- CI comprises the systems, facilities, and services essential to national security, economic prosperity, and public wellbeing. Water supply operations and wastewater management services have become attractive targets for malicious cyber actors, primarily due to inconsistent cyber hygiene practices—the routine digital maintenance and foundational security measures—across networks and OT systems. MCAs frequently target internet-accessible control systems to conduct intelligence gathering, espionage, or sabotage in pursuit of their strategic objectives.
- In the US, there are sixteen CI sectors whose systems, networks, both virtual and physical, are vital to the security and prosperity of the country. Threats originating from cyberspace have become increasingly worrying for government officials due to incident response, containment, and attribution being expensive, time-consuming processes. Without these CI systems, there would be debilitating effects on national security, the economy, public health and safety, and beyond.
Analysis
As just one of many CI sectors, the water and wastewater systems sector in the US is part of a broader web of mechanisms and components that support national security, economic prosperity, and public health. As such, it remains an attractive target for MCAs.
- Recent evaluation suggests that the escalation timeline and “cascading geopolitical crises” that have emanated from the onset of the US’s Operation Epic Fury in Iran has profoundly reshaped Tehran’s cyber posturing, suggesting that Iranian-aligned MCAs may be placing a greater emphasis on disrupting public-facing CI as part of a broader grey-zone strategy. While explicit links to the recent July cyberattacks remain unconfirmed, the timing of these incidents underscores the extent to which geopolitical conflict ushers in new, acute threats to the cyber environment.
- Recent threat assessments suggest that, going forward, there is a high level of confidence that US Water and Wastewater Systems are at extreme risk of being targeted in malicious cyber operations. There are a few key indicators that inform this assessment, where the limited maturity of CI sector-wide cybersecurity hygiene and the prevalence of vulnerable control systems are the cause for most concern and require urgent attention from policymakers.
Policy Implications
Integration of Artificial Intelligence (AI) for Threat Detection
- AI, when used effectively and responsibly, can support cyber defence practitioners to detect, interpret, and respond to cyber threats. Automating the threat detection workflow will allow analysts to spend less time performing repetitive tasks, and instead, review the AI-prepared detections of malicious network activity, where they can validate, approve, modify, or further investigate detection reports.
- As AI is increasingly instrumental in facilitating cybercrime and malicious cyber activity, CI sectors must consider how automating threat detection workflows will promote efficiency without sacrificing accuracy. Typically, the human analyst-led cyber threat detection pipeline can take multiple hours, sometimes multiple days. AI-assisted threat detection workflows, on the other hand, can complete the same work in under an hour, ultimately relieving pressure on human analysts.
Proper Segmentation of OT/IT Infrastructure
- The segmentation of OT/IT infrastructure, or lack thereof, within American CI is an emerging vulnerability across sectors. As the systems and networks that support physical processes, internet-accessible OT greatly increases the risk of malicious cyber activity. MCAs, especially those that are well-resourced, may use IT networks to gain unauthorized access to non-segmented OT networks. A successful attack on internet-accessible OT could sabotage Industrial Control Systems that support the supply of potable drinking water and proper wastewater treatment for Americans.
- The complexity of emerging technology to support operations across American CI sectors can be complex, expensive to maintain, and can take a long time to implement. As a result, outdated systems that have not received patches or are “operating beyond end-of-life” can create vulnerabilities in non-segmented OT/IT infrastructure. Ensuring that no part of OT infrastructure is accessible via the internet will greatly reduce the likelihood of a successful cyberattack on American CI.
Bibliography
Braccia, C., 2026. Iran’s Cyber Operations Against US Critical Infrastructure: Escalation Patterns, Pre-Positioning, and Implications for US Homeland Defense. Threat Intelligence Brief.
Canadian Centre for Cyber Security, 2026. How the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineering. [Online]
Available at: https://www.cyber.gc.ca/en/guidance/canadian-centre-cyber-security-used-frontier-ai-accelerate-detection-engineering
Cybersecurity and Infrastructure Security Agency (CISA), 2026. CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers. [Online]
Available at: https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting
Cybersecurity and Infrastructure Security Agency (CISA) , n.d. Cyber RIsks and Resources for the Water and Wastewater Systems Sector. [Online]
Available at: https://www.cisa.gov/sites/default/files/2023-02/infographic-supply-water-national-critical-function-102021-508.pdf
Cybersecurity and Infrastructure Security Agency (CISA), n.d. Water and Wastewater Systems. [Online]
Available at: https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector
Government of Minnesota, 2026. Minnesota continues response to cyber activity affecting community water systems. [Online]
Available at: https://mn.gov/mnit/media/blog/#/detail/appId/1/id/762209
