The Cybersecurity and Infrastructure Security Agency reported that it observed malicious cyber activity targeting over 100 water and wastewater systems across the United States in July 2026. [Source: CISA advisory, August 2026] ## Critical Infrastructure Under Unprecedented Attack The attacks mostly targeted programmable logic controllers, or PLCs, which can monitor or control equipment. [Source: CISA advisory] Some communities have connected those devices to the internet so that they can be accessed remotely. [Source: Wired reporting] According to CISA, hackers are using AI to help generate scripts to attack the devices. [Source: CISA statement to TechCrunch] A leaked industry memo tied the unprecedented wave of cyberattacks to Iran. [Source: Wired, July 2026 report] The cybersecurity threat to water systems represents a growing concern for national security officials. PLCs are industrial control systems that manage physical processes like water treatment and distribution. When these systems are connected to the internet, they become vulnerable to remote exploitation. The American Water Works Association represents more than 4,700 water utilities serving approximately 180 million people across the United States. ## AI-Powered Attacks Escalate Threat Level The use of AI-generated attack scripts marks a significant escalation in cyber threats to critical infrastructure. Traditional hacking required specialized knowledge of industrial control protocols, but AI tools can now generate attack code that targets known vulnerabilities in PLCs. [Inference] CISA has recommended that water utilities disconnect PLCs from the internet where possible and implement multi-factor authentication for remote access. [Source: CISA Shields Up guidance] The agency has also provided free cybersecurity assessments to water utilities through its Shields Up campaign. The attacks on water systems come amid a broader wave of cyber threats targeting US critical infrastructure. In August 2026, OpenAI, Anthropic, and more than 100 companies cosigned a letter warning that organizations have mere months to prepare for AI-enabled cyberattacks. [Source: Wired, August 29, 2026] The letter calls for a collective response and suggests that every organization should make cyber defense an immediate leadership priority. [Source: OpenAI/Anthropic joint letter] It also calls on governments to give hospitals, water utilities, and local governments access to capable defensive AI, as well as to impose costs on attackers. [Source: joint letter] Axios noted that the letter does not include any specific commitments, deadlines, or investments. [Source: Axios reporting on the letter] ## FBI Disruption of State-Sponsored Hacking Tools The FBI recently announced that it has taken down two tools that the DOJ says are used by QTFY, an alleged Chinese state-sponsored hacking group. [Source: Wired, August 29, 2026] The DOJ says that the group has targeted numerous US agencies, including the US Senate and the DOJ itself. [Source: DOJ press release] Water utilities across the country have been urged to review their cybersecurity practices and implement recommended safeguards. The American Water Works Association has issued guidance to its members on protecting against AI-powered cyberattacks. [Source: AWWA advisory] The Department of Homeland Security has allocated additional funding for critical infrastructure cybersecurity in its fiscal year 2027 budget proposal. [NEEDS VERIFICATION: specific funding amount] The cybersecurity challenges facing water utilities highlight the urgent need for investment in industrial control system security across the United States.