In an August 3 interview on CNBC’s Squawk Box, The Chertoff Group’s Head of Cybersecurity Adam Isles told host Becky Quick that while Iranian cyber trade craft is not new, the scale of the attacks on water systems in the US is bigger than we’ve seen previously. AI is lowering the knowledge gap for the bad guys, and the good guys have catch up work to do.
Isles pointed to two forces driving the current wave of attacks: an adversary with clear motivation and a vulnerable set of targets. Iran may be motivated in part by raising the cost on the US for recent strikes, but the vulnerability of water utility control systems is the more immediate problem for defenders.
What Happened
The FBI and EPA issued a joint warning on cyber threats to water systems July 30, and CISA released a separate advisory July 22 warning of Iranian attacks on internet-connected Operational Technology (OT) devices —including systems manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufacturers.
In June 2026, an Iranian proxy group claimed the breach of California Water Service systems and published a 5 GB data set including customer information and credentials; Cal Water later reported the activity was limited to accounts within two third-party service provider platforms, and its own networks were not affected.
What’s New and Different About this Campaign
Scale. Attacks on US water treatment plants are not new, but earlier incidents have been involved single utilities. In this campaign, dozens of utilities have been impacted. Water and wastewater utilities in at least seven states experienced cyber intrusions starting in July.
- Minnesota reported more than 30 community water systems affected, with no indication that drinking water was contaminated.
- Michigan reported 9 systems impacted.
- FBI/CISA reports also suggest service-provider vectors helped scale the attacks.
Preparatory Internal Reconnaissance in Industrial Systems. Isles noted US reports that Iranian-affiliated APT actors had stolen project files from PLC devices as a preparatory step in planning attacks.
- What is a PLC? A programmable logic controller is a small, rugged computer built for one job: to run industrial equipment.
- What is a project file? The PLC does not decide anything on its own. It follows instructions. The project file is those instructions.
Impact to Safety Systems. Later, FBI and CISA saw modification and deletion of project file logic. Some changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.
Why Iran is suspected
Iran targeted US water systems in 2023 and has shown interest in the sector for more than a decade. An Iranian proxy group claimed credit for the June 2026 Cal Water incident, and US authorities attributed a broader wave of critical infrastructure attacks to Iran in the July 22 advisory. Iran has used disruptive cyber operations as a tool for 15+ years, in the US and beyond.
Is the water supply safe?
The FBI and CISA warned that pressure loss could allow untreated groundwater to seep into pipes, and CISA reported boil water orders in some areas. Water utilities generally maintain redundant safety systems, though. The City of South St. Paul, Minnesota, said that drinking water remained safe throughout.
Where this is headed
Advancements in artificial intelligence are lowering the adversary knowledge gap on industrial technology and enabling automation, said Isles. He pointed to Iranian attempts to use LLMs for industrial technology research, as well as LLM usage by others to compromise water systems outside the United States.
Isles connected the safety message to timing: with the 25th anniversary of 9/11 a month away, he urged a focus on preparedness. Resiliency and the ability to disconnect systems from the internet and keep them running through manual operations are key. On where this goes next, he pointed to the broader geopolitical trajectory. “The technology available to attackers is getting better, and there is catch up work to do on the good guy side.” An April 2026 Censys analysis identified 5,219 internet-exposed hosts globally that responded to industrial protocols and self-identified as Rockwell Automation/Allen-Bradley devices. The United States accounts for 74.6% of global exposure.




