Reports detail US water attacks and Volt Typhoon pre-positioning
Sources disagree on attribution and state counts as reports describe US water-controller attacks and Volt Typhoon pre-positioning.
A CyberScoop op-ed and later reports describe cyber activity against US water systems and other critical infrastructure. CISA, NSA, and the FBI assess that China's Volt Typhoon is pre-positioning in IT networks spanning communications, energy, transportation, water, and Guam, using exposed appliances, valid administrative credentials, and living-off-the-land techniques, with persistence of at least five years in some environments, for possible later disruption. Sources disagree on recent water attacks: the op-ed says Iranian hackers struck utilities in 12 states, while later reports say utilities in at least seven states reported attacks on exposed controllers since July 27, 2026, with flooding and lost pressure; the newest account specifies Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 devices, says intruders changed passwords and network settings and in at least one case altered logic, and says the July activity has not been publicly attributed, whereas GBHackers separately reports Iranian-affiliated abuse of internet-facing Rockwell Allen-Bradley PLCs. The FBI warned that sufficiently low pressure could let untreated groundwater into pipes, but contamination was not confirmed. The NSA has warned of reconnaissance and AI-generated scripts aimed at Siemens S7 PLCs, and the op-ed cites AI systems such as Anthropic's Claude Mythos discovering zero-days, says about 80 percent of US water systems lack basic cyber hygiene and that roughly 45,000 systems serve 3,300 people or fewer, notes the EPA withdrew a 2023 cybersecurity interpretation, and says Senators Klobuchar and Schiff proposed the Water Safety Shield Act at about $600 million a year alongside EPA, FBI, and CISA guidance and a Texas pilot. Separately, CyberAv3ngers compromised at least 75 Unitronics devices between November 2023 and January 2024 using default or absent passwords.
- Since July 27, 2026, water and wastewater utilities in at least seven states reported attacks on exposed Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers; a CyberScoop op-ed instead says Iranian hackers attacked…
- Intruders changed passwords and network settings and, in at least one case, modified controller logic; reported effects included flooding and lost pressure. The FBI warned low pressure could let untreated groundwater into pipes,…
- CISA, NSA, and the FBI assess China's Volt Typhoon is pre-positioning in communications, energy, transportation, water, and Guam IT networks using exposed appliances, valid administrative credentials, and living-off-the-land techniques,…
- GBHackers cites a separate advisory that Iranian-affiliated actors abused internet-facing Rockwell Allen-Bradley PLCs; the NSA warned of reconnaissance and AI-generated scripts targeting Siemens S7 PLCs.
- CyberAv3ngers compromised at least 75 Unitronics devices between November 2023 and January 2024 using default or absent passwords.
- An op-ed says about 80 percent of US water systems lack basic cyber hygiene, roughly 45,000 systems serve 3,300 people or fewer, the EPA withdrew a 2023 cybersecurity interpretation, and the proposed Water Safety Shield Act would provide…
- The op-ed cites a 2026 threat assessment and AI systems such as Anthropic's Claude Mythos discovering zero-days, and urges zero-trust and formal methods for larger utilities.
Coverage timelineoldest first · each row is one article
- · 3d agoThe US needs a real plan to defend its water systems
CyberScoop· 36
Op-ed says US water utilities need a federal cybersecurity plan after foreign attacks and rising AI-enabled threats.
- · 2d agoOT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes
GBHackers· 81
State-linked actors are targeting US critical-infrastructure OT, with confirmed water-system disruption and Volt Typhoon pre-positioning.
- · 2d ago