
The FBI confirmed water and wastewater utilities in at least seven states lost control of their own equipment starting in late July. ABC News and The Record have since reported the number climbing toward a dozen as more utilities come forward, and investigators have linked the intrusions to Iran-affiliated actors, though federal agencies have not made a formal attribution. I’ve watched this vendor risk pattern show up in our public entity claims data for years.
Regardless, state count is the wrong number to track. What matters is how many utilities have an internet-exposed controller that nobody has inventoried, a count that will keep climbing as more utilities report in. The exposure itself doesn’t change until the devices come off the internet.
Operators in several states were locked out of programmable logic controllers and forced back to manual operation. In Minnesota alone, CBS News reported on Aug. 6, 2026, that more than 30 community water systems were affected. No ransom was demanded in any of it. The FBI and EPA flagged that absence as unusual in a joint advisory, a signal that disruption, not payment, was the goal.
This campaign started well before this summer’s water utility headlines. CISA and six other federal agencies (including the FBI, the NSA, and the EPA) have been tracking it since April 7, 2026, in a joint advisory, AA26-097A. They updated it on July 22, expanding the confirmed target list from Rockwell Automation’s Allen-Bradley controllers to include Schneider Electric and Siemens devices, and widening the affected sectors beyond water to energy and government facilities that run the same equipment.
Same mechanism, different equipment
This isn’t the first time a shared vendor turned into shared exposure. In 2023, an Iran-affiliated group known as CyberAv3ngers compromised a water authority outside Pittsburgh. The setup was a programmable logic controller made by the Israeli manufacturer Unitronics, left at its default settings and exposed to the internet. CISA, the FBI, the NSA, the EPA, and Israel’s National Cyber Directorate detailed the incident in a joint advisory, AA23-335A, in December 2023. The attackers weren’t after that specific utility. They scanned the internet for a specific controller model and hit every instance they found.
That is the same mechanism behind two of the most widely reported public sector breaches in recent memory. Cl0p, for example, did not target school districts and counties individually in 2023. It exploited a single vulnerability in MOVEit, a file transfer tool used across hundreds of public entities at once, documented in a joint CISA/FBI advisory, AA23-158A. Post-breach tracking from the security firm Emsisoft counted school districts and county governments among the victims; organizations that had never heard of each other before the breach. ShinyHunters did the same thing through Canvas, a learning platform used broadly across education.
A dozen states losing water system control within days of each other is shared-platform exposure at scale, running on control systems instead of software.
What the data already shows
Our public entity portfolio spans counties, cities, school districts, universities, transit authorities, water authorities, and housing authorities, and we’ve been measuring this exact pattern for years. Vendor exposure – meaning breaches and disruptions that originate from a third party rather than the entity’s own systems – accounts for roughly four in 10 claims in that portfolio (see note on the data below). Among claims where the point of entry is documented, vendor systems account for more than half, nearly four times the next most common way in.
Insider error adds another one in six. The remaining causes are individually smaller and mostly familiar: things like phishing, transfer fraud, and mismailed records.
Attacker skill has little to do with any of this. The real constraint is what public entities can buy, staff, and maintain. Procurement rules favor cost and compliance over security review; budgets rarely fund a team that audits vendor posture at renewal instead of just at purchase; and shared platforms get adopted at the state or district level, which turns one entity’s procurement decision into every entity’s exposure.
A control system is still a vendor relationship
A water utility does not build its own programmable logic controllers any more than a school district builds its own learning management system. It buys equipment from a manufacturer, under the same budget and staffing constraints that shape every other purchase, and that equipment often goes into service without anyone auditing its default configuration or its exposure to the open internet.
Our claims data doesn’t yet include a large sample of losses tracing directly to operational technology, a gap in the numbers, not the pattern. The 2023 CISA advisory and this summer’s reporting point to the same mechanism, a widely deployed product with minimal oversight after purchase, sold into a population of organizations that share a vendor and a vulnerability without ever having spoken to each other.
What this changes
Treat vendor risk as a procurement checkbox, reviewed once and not looked at again, and you end up on a list with a dozen other organizations you’ve never contacted, running the same compromised product. That’s exactly the failure mode risk-based vendor tiering is built to catch.
Whether that device is reachable from the public internet isn’t the vendor’s determination to make. It’s the same question your security team already asks about every other internet-facing asset on the network, verified continuously rather than attested to once at purchase or reviewed once a year at renewal. The count of affected states will keep climbing no matter what you do; whether your own controller ends up on it is the one part of this actually in your control.
A note on the data: the vendor-exposure and point-of-entry figures come from Resilience’s public entity claims portfolio from January 2022 through May 2026, covering counties, cities, school districts, universities, transit authorities, water authorities, and housing authorities. Full methodology available on request.
Nothing here should be taken as legal, financial, or security advice for your specific situation — see the full disclaimer at cyberresilience.com/disclaimer.



