
In late July 2026, a coordinated cyberattack disrupted water and wastewater systems across the United States.
It started in Minnesota, where more than 30 community water systems were targeted over a single weekend. Within days, utilities in at least a dozen states reported incidents. Some facilities lost remote monitoring and control. Some experienced pressure loss and flooding. Several communities were placed under boil-water notices while operators switched their systems to manual operation.
The FBI and EPA issued a joint public service announcement. CISA scrambled to help utilities secure their systems. Officials have pointed to Iran-linked actors as a leading suspect, though no formal attribution has been made.
No drinking water was contaminated. Utilities regained control quickly, often by taking systems offline. By the standards of what could have happened, the country was fortunate.
But the message was unmistakable: America's water infrastructure is being actively targeted, and the attackers are not going away.
Critical Infrastructure Has Become a Prime Target
The July attacks did not come out of nowhere.
In April 2026, CISA published an advisory documenting Iranian-affiliated actors compromising internet-connected industrial control devices across the water, energy, and government sectors. The advisory confirmed disruptions at victim organizations dating back to at least March. It was updated on July 22, four days before the Minnesota attacks began.
And the pattern stretches back years:
- In November 2023, the Municipal Water Authority of Aliquippa, Pennsylvania was breached by attackers who found an internet-exposed controller still protected by its default password.
- In January 2024, Veolia North America, which serves water systems across the country, was hit by ransomware that knocked out billing systems in its Municipal Water division.
- In October 2024, American Water, the largest regulated water utility in the United States with 14 million people served, disconnected customer systems after discovering unauthorized activity on its networks.
Why water? Because it combines maximum psychological impact with minimum defensive investment.
The United States has roughly 50,000 community water systems, and most of them are small. Many are run by a handful of people who handle operations, maintenance, billing, and IT all at once. A dedicated security team is a luxury most utilities simply do not have.
Attackers know this. A nation-state actor looking to send a message, or a criminal group looking for an easy ransom, sees the same thing: an essential service that everyone depends on, defended by some of the leanest teams in critical infrastructure.
AI Has Changed the Math for Attackers
There is a second shift happening at the same time, and it is the one that should worry small utilities the most: AI has collapsed the cost of attacking people.
For years, a small water system in a small town had a quiet form of protection: it was not worth an attacker's time. Crafting a convincing, targeted phishing email required research and effort, and attackers spent that effort on bigger prizes. Generic mass phishing, with its misspellings and awkward phrasing, was what most utilities actually saw, and it was exactly what awareness training taught people to catch.
That protection is gone. With generative AI, an attacker can produce a flawless, personalized lure in seconds: correct grammar, the right professional tone, and details pulled from the utility's own website, public board minutes, procurement records, and employee LinkedIn profiles. What used to be a handcrafted spear-phishing attack reserved for high-value targets can now be generated at mass-phishing volume and aimed at every water system in a state at once.
WaterISAC's most recent threat analysis for the sector says exactly this: attackers are using AI to build more convincing social engineering and business email compromise attacks. And it does not stop at email. Voice cloning now makes a phone call from a "vendor" or a "supervisor at the county" cheap to fake, which matters in a sector where so much business still runs on trusted phone calls between small teams.
The result is a brutal asymmetry. The tells that employees were trained to look for, the typos and the clumsy wording, are disappearing. The volume of credible attacks is going up. And the target has not changed: a busy person, mid-task, deciding whether a routine-looking request is real. For a deeper look at how attackers are using generative AI, see our guide to AI phishing.
The Headlines Say Exposed Devices. The Data Says People.
The July 2026 wave exploited internet-exposed programmable logic controllers, the small industrial computers that monitor tanks, pumps, and treatment processes. That is what the federal alerts focused on, and hardening those devices matters urgently.
But it would be a mistake to conclude that this is primarily a hardware problem.
WaterISAC, the water sector's threat information sharing center, reported that in late 2025, phishing and social engineering accounted for 31 percent of the cybersecurity incidents reported by member utilities. That is nearly one in three incidents, second only to attacks on industrial control systems, and ahead of ransomware. And ransomware itself most often begins with a person: a credential harvested through a fake login page, or an attachment opened under pressure.
Even during the July attacks, the human layer was under simultaneous assault. The New Jersey Cybersecurity and Communications Integration Cell, responding to incidents at two municipal water systems, described active phishing campaigns in which attackers capture account credentials, then send new phishing emails from the compromised legitimate accounts to avoid suspicion.
The lures they documented were not exotic. They were ordinary workday requests:
- Payroll processing errors that need immediate attention.
- Shared documents for review, like event calendars or meeting notes.
- Expiring compliance training reminders.
- Past-due invoices for services.
- Encrypted or secure messages that require a login to open.

Every one of those lures ends the same way: with an employee looking at a page that asks for a password.
Why the Human Layer Is the Most Accessible Target
Compromising an industrial controller takes some technical knowledge. Compromising a person takes an email address.
For water utilities specifically, several conditions make the human layer the path of least resistance:
- Lean teams with broad access. When one person handles operations, billing, and IT, one compromised account can reach almost everything.
- IT and OT are converging. Remote access tools, cloud dashboards, and vendor portals increasingly connect business systems to operational ones. A credential phished from an office computer can be the first step toward the systems that move water.
- A trusted web of vendors and partners. Utilities constantly exchange emails with municipalities, regulators, engineering firms, and equipment vendors. WaterISAC has flagged email impersonation of exactly these trusted parties as one of the sector's most persistent risks.
- Basic hygiene gaps. An EPA enforcement alert found that over 70 percent of inspected water systems violated basic security requirements, including default passwords and shared logins. The Aliquippa breach happened because of a default password.
- AI-polished lures at scale. As covered above, the obviously fake email is disappearing, and every utility is now worth an attacker's time.
A phishing-based intrusion at a utility rarely announces itself. It follows a quiet sequence:
Convincing email → Fake login page → Credentials entered → Trusted access gained → Business systems, remote access, or OT reached
The most important thing about that sequence is where it can be broken. Everything after the credentials are entered belongs to the attacker. Everything before it belongs to the defender.
Training Alone Will Not Carry This
The standard response to human risk is awareness training, and most utilities that have a security program at all have some version of it.
Training matters. But an annual module cannot carry the weight of a threat environment where nation-state actors are actively probing the sector and phishing lures arrive every day.
An operator who completed a training course in January is not thinking about it in July when a payroll error email arrives during a night shift. They are thinking about their paycheck. Attackers deliberately design lures to trigger exactly that kind of fast, task-focused response.
For a lean utility team, this problem is sharper than it is almost anywhere else. There is no security operations center watching for the anomalous login. There is often no one to call before clicking. The employee at the point of decision is the security program.
Defend the Human Layer at the Moment of Decision
If the human layer is the most accessible target, it deserves the same real-time protection we give networks and endpoints.
That means shifting from a model that only prepares people in advance to one that also protects them in the moment:
- Detect the risky interaction when it reaches the employee, whether it arrives by email, text, collaboration tool, or search result.
- Interrupt the dangerous action before it completes, especially credential entry on suspicious pages.
- Explain what made the interaction dangerous while the moment is still fresh.
- Reinforce with short, relevant training tied to what just happened, not a generic annual course.
- Adapt future simulations to the lures actually hitting the organization, like the payroll and compliance-training themes hitting water utilities right now.

This protection-first model matters most for organizations that cannot afford a big security team. When there is no analyst watching the queue, real-time phishing protection has to live where the risk lives: in the browser, at the point where a busy employee is about to type a password.
It also changes what utilities can measure. Instead of only tracking who clicked a simulated email, a utility can see risky actions prevented, credential-entry attempts stopped, and whether employees improve after real interventions. For a sector under active attack, those are the numbers that describe actual resilience.
The Water Keeps Flowing Because People Keep It Flowing
The July 2026 attacks will drive overdue investment in securing exposed devices, and that work should happen as fast as possible.
But when the exposed controllers get firewalled and the default passwords get changed, the attackers will not give up. They will go where the access is. And in a sector staffed by small teams juggling many roles, that access runs through people.
Critical infrastructure is a prime target. The human layer is the most accessible way in. Defending it is no longer optional, and it cannot wait for the next annual training cycle.
Protect the People Who Keep the Water On
SavvyShield gives lean teams enterprise-grade human risk protection: real-time intervention in the browser when an employee encounters a dangerous page, adaptive simulations built from real attack patterns, and short training delivered at the moment it is relevant.
No security operations center required. Protection first, education always.
Learn how SavvyShield protects the human layer in real time.



