Tactical Bulletin: Water Utility Cyber Campaign, August 10, 2026

Share Post

Overview

The following Situation Assessment summarizes the coordinated cyber campaign targeting municipal water and wastewater utilities across the United States beginning on July 26, 2026. This report aims to enhance the safety and security of Rozin Security’s clients.

Executive Summary

  • Beginning on July 26, a coordinated cyber campaign targeting operational technology (OT) affected more than 30 municipal water and wastewater utilities in Minnesota, with additional incidents reported across multiple U.S. states. Federal authorities are investigating the activity as a coordinated campaign believed to be linked to Iranian-affiliated cyber actors.
  • Although no public health impacts were reported, the intrusions forced multiple utilities to transition to manual operations after attackers gained unauthorized access to industrial control systems, modified administrative credentials, and altered system configurations.
  • The campaign demonstrates that state-sponsored cyber actors continue to view local critical infrastructure, including small municipal utilities, as viable targets for disruptive cyber operations designed to impose operational costs and demonstrate access while remaining below the threshold of conventional military conflict.
  • The incidents reinforce that geopolitical tensions increasingly extend into cyberspace and can have direct operational consequences for communities in Minnesota, highlighting the continued need for organizations responsible for critical infrastructure to strengthen operational technology security and incident response capabilities.
Download the bulletin to access concise, actionable intelligence designed to help organizations anticipate exposure and plan accordingly.

Name(Required)

Tactical Bulletin: Water Utility Cyber Campaign, August 10, 2026

Share Post

Overview

The following Situation Assessment summarizes the coordinated cyber campaign targeting municipal water and wastewater utilities across the United States beginning on July 26, 2026. This report aims to enhance the safety and security of Rozin Security’s clients.

Executive Summary

  • Beginning on July 26, a coordinated cyber campaign targeting operational technology (OT) affected more than 30 municipal water and wastewater utilities in Minnesota, with additional incidents reported across multiple U.S. states. Federal authorities are investigating the activity as a coordinated campaign believed to be linked to Iranian-affiliated cyber actors.
  • Although no public health impacts were reported, the intrusions forced multiple utilities to transition to manual operations after attackers gained unauthorized access to industrial control systems, modified administrative credentials, and altered system configurations.
  • The campaign demonstrates that state-sponsored cyber actors continue to view local critical infrastructure, including small municipal utilities, as viable targets for disruptive cyber operations designed to impose operational costs and demonstrate access while remaining below the threshold of conventional military conflict.
  • The incidents reinforce that geopolitical tensions increasingly extend into cyberspace and can have direct operational consequences for communities in Minnesota, highlighting the continued need for organizations responsible for critical infrastructure to strengthen operational technology security and incident response capabilities.
Download the bulletin to access concise, actionable intelligence designed to help organizations anticipate exposure and plan accordingly.

Name(Required)

Rozin Security

We provide solutions to safeguard your assets.

subscribe to our newsletter

Sign up to be notified of general news and updates from Rozin.