A collaboration between Lewis McLain & AI
What the July 2026 intrusions into U.S. water systems mean for Texas cities — and why this is a budget problem before it is an IT problem

What actually happened
On the nights of Sunday, July 26 and Monday, July 27, 2026, someone reached into the control systems of more than thirty community water and wastewater utilities in Minnesota. Minnesota IT Services confirmed on July 28 that the activity was coordinated. Four communities were named publicly: Braham, Plymouth, South St. Paul, and Maple Plain. Braham’s water plant went offline. Plymouth disconnected cellular-connected equipment at two water towers and several wastewater lift stations. Maple Plain declared a local state of emergency. Nobody’s drinking water was contaminated.
By Thursday, July 30, the FBI and EPA had issued a joint public service announcement: water and wastewater utilities in at least seven states had reported intrusions since July 27, and some of that activity degraded operations. The agencies declined to name the states. Michigan later confirmed it was among them, with nine municipal systems reporting problems. Wisconsin’s Department of Natural Resources sent its utilities an urgent directive the same week. CISA reported that some incidents had produced boil-water notices and forced utilities into sustained manual operation.
As of this writing, no public water supply anywhere in the country has been shown to have been altered or made unsafe.
How they got in — and why it should worry every small city
This was not an exotic attack. That is the point.
The targets were programmable logic controllers — PLCs — the small industrial computers that open a valve, run a pump, hold a tank level, dose a chemical feed. In the affected systems, those controllers were reachable directly from the public internet. The intruders connected to them using the manufacturers’ own engineering software, running on leased hosting infrastructure, then changed device IP addresses and passwords. That locked operators out of their own equipment and stripped them of monitoring and control. In some cases the result was pressure loss and flooding.
CISA’s advisory AA26-097A, first published April 7, 2026 and updated July 22 — four days before the Minnesota incidents — named the specific gear: Rockwell Automation/Allen-Bradley CompactLogix and Micro850, Schneider Electric Modicon M340, Siemens S7-1200. The July update added a detail worth pausing over: at one confirmed U.S. victim, the attackers modified the controller’s ladder logic to disable safety shutdowns and alarms, so that an unsafe condition could develop without anyone being told.
When the April advisory came out, the security firm Censys counted 5,219 internet-exposed hosts worldwide identifying themselves as Rockwell/Allen-Bradley devices on the standard industrial port. A large share of that exposure traced back not to corporate networks but to cellular carrier connections — which is to say, field equipment. Lift stations. Remote pump houses. Elevated storage tanks. The exact architecture that lets a two-person public works department watch a tank level from a truck at 2 a.m. is the architecture that was exploited.
There was no zero-day here. There was misconfiguration at scale.
On attribution, and the politics of it
Federal officials have said privately that Iran is the leading suspect, consistent with a documented Iranian-affiliated campaign that CISA, FBI, NSA, EPA, DOE, U.S. Cyber Command, and now Treasury have jointly tracked since April. The group has previously been tracked under the CyberAv3ngers alias and tied to the IRGC Cyber Electronic Command — the same actor set implicated in the 2023 Unitronics compromises at U.S. water utilities. There is no apparent financial motive, which argues against ordinary criminals.
Officials have also been careful to say the assessment is preliminary and that definitive forensic proof has not been established. That is normal. Complex intrusion investigations routinely take months, and sometimes never reach a public, authoritative conclusion.
The attribution question became political almost immediately. President Trump publicly rejected the Iran theory and blamed Minnesota’s state government, saying he thought Minnesota was behind it and disputing that an Iranian cyberattack had occurred at all. Governor Tim Walz rejected that and pointed to reductions in federal cyber support. Braham’s mayor, Nate George — a Republican running for state auditor — said federal and local officials on the ground had little doubt about the likely culprit, allowed that the president was entitled to his opinion, and argued the practical obligation now is helping cities harden their defenses.
That last framing is the useful one for those of us who work on city budgets. Whoever turned the knob, the knob was reachable.
Texas has already lived this
In January 2024, a citizen in Muleshoe noticed water pouring off an elevated tank. It was not a stuck valve. Attackers had gotten into the remote login system for the SCADA software through a third-party vendor’s access, and the tank overflowed for roughly 30 to 45 minutes before crews took the machine offline and went to manual. Abernathy had a tank overflow the same period. Hale Center logged something on the order of 37,000 attempts against its firewall over four days and unplugged rather than risk it. Lockney took precautions the same day.
Mandiant attributed the activity to Sandworm, the Russian GRU-linked group, operating through a front calling itself the Cyber Army of Russia Reborn. In July 2024, Treasury sanctioned two of that group’s leaders specifically for the Muleshoe and Abernathy hacks.
Muleshoe has about 5,000 people. Abernathy has under 3,000. Nobody targeted them because they mattered strategically. They were reachable, and that was enough. Security researchers describe this bluntly as adversaries taking low-hanging fruit — vulnerable services sitting directly on the internet.
Texas has been the demonstration case for two years now. The July 2026 wave is the same play run at larger scale by a different flag.
The structural problem is a finance problem
Here is the number that ought to reframe this whole conversation for anyone who works in Texas local government finance.
TCEQ oversees more than 7,000 public water systems serving roughly 29 million Texans. Of 7,053 systems counted in TCEQ’s Sunset self-evaluation, 84% serve fewer than 3,300 people. Of 4,641 community water systems, 3,483 serve fewer than 3,300.
Now set that against federal law. America’s Water Infrastructure Act of 2018, Section 2013 — amending Safe Drinking Water Act §1433 — requires community water systems serving more than 3,300 people to certify a Risk and Resilience Assessment and an Emergency Response Plan to EPA on a five-year cycle, and that cycle explicitly covers cyber threats. Recertification for systems serving 100,000-plus was due March 31, 2025. The 50,000–99,999 tier was due December 31, 2025. The 3,301–49,999 tier — where most Texas cities with a real utility fund actually live — came due June 30, 2026. Five weeks ago.
Everyone below 3,300 has no federal cyber assessment requirement at all. In Texas, that is the overwhelming majority of systems: water supply corporations, small districts, subdivisions, and towns operating with a licensed operator, a part-time clerk, and a SCADA package installed by an integrator a decade ago and touched only when something breaks.
The federal watchdogs have said as much. GAO’s 2024 review found roughly 170,000 U.S. water systems facing cyber risk in an increasingly automated sector. EPA’s Inspector General identified critical- or high-severity vulnerabilities at 97 drinking water systems serving 27 million people.
This is not a technology gap. It is a scale-economics gap. A city of 2,400 cannot carry an OT security program on 800 water connections, and no rate structure that voters will tolerate changes that arithmetic.
Where the regulatory line is moving
EPA tried in 2023 to fold cybersecurity reviews into state sanitary surveys. That rule was stayed in court and withdrawn. The agency has since worked through guidance and existing enforcement authority instead — a May 2024 enforcement alert on cyber gaps, and an October 2025 package including a revised Emergency Response Plan guide, a Cybersecurity Incident Response Plan template, incident-specific checklists, and a procurement checklist.
Meanwhile the states are moving. New York finalized binding cybersecurity regulations for wastewater facilities in March 2026, with mandatory incident reporting effective March 26, 2026, built around EPA’s own guidance incorporated by reference. Wastewater has never been covered by AWIA at all, which makes it the obvious place for states to start. Expect imitation.
At the federal level, CIRCIA will require covered entities — water and wastewater utilities included — to report significant incidents to CISA within 72 hours and ransom payments within 24 hours. Final rules are expected later in 2026. Any utility waiting for the final rule before building a reporting process is choosing to scramble later.
In Texas, the obligations already exist and are older than most people realize:
- 30 TAC §290.46(w) requires public water systems to notify TCEQ immediately, by toll-free number, of unauthorized entry, acts of terrorism, or unauthorized attempts to probe or access proprietary information supporting key activities. The threat hotline is (888) 777-3186.
- Since September 1, 2023, local governments — including municipalities, counties, districts, water authorities, and water supply corporations — must report security incidents to the state within 48 hours of discovery.
- HB 150, signed June 2, 2025, created the Texas Cyber Command as a component of the UT System headquartered in San Antonio, consolidating the cybersecurity functions previously held by the Department of Information Resources. The transfer is phased, with completion required by December 31, 2026. Governor Abbott framed the new agency in part as a response to threats from Iran, Russia, and China against power, water, and communications.
- SB 1034, filed in the 89th session as part of Senator Kevin Sparks’s water package, would have gone considerably further: prohibiting direct internet connection of SCADA systems except through secure VPN, requiring annual employee cyber training, authorizing security assessments and compliance audits, mandating 48-hour incident reporting, and giving retail public utilities access to state network security services, with full SCADA compliance by September 1, 2027. It did not become law. SB 1625, which would have expanded the §290.46(w) reporting list to name cyber threats explicitly, moved through committee but likewise did not reach enactment.
Texas came within one bill of having the strongest water-sector cyber statute in the country. The 90th Legislature convenes in January 2027, and after this summer the politics of that bill look very different.
Now the money — and this is the part cities will not like
The federal funding picture is thinner than the rhetoric suggests.
The State and Local Cybersecurity Grant Program — the $1 billion program from the 2021 infrastructure law that states have used to reach small utilities — expired September 30, 2025, along with the Cybersecurity Information Sharing Act of 2015, the law providing liability protection when utilities share threat intelligence. Both were reinstated November 12, 2025 in the shutdown deal, lapsed again briefly, and are currently extended only through September 30, 2026 under the Consolidated Appropriations Act, 2026. Annual SLCGP funding has already fallen sharply: $374,000,000 in FY2023, $279,000,000 in FY2024, $91,750,000 in FY2025. A ten-year reauthorization has passed the House but the program’s future funding level would be set annually through appropriations rather than guaranteed up front.
CISA also stopped funding MS-ISAC, which now charges fees — pushing out precisely the smallest and least-resourced members who benefited most.
What remains: the Drinking Water and Clean Water State Revolving Funds still carry the additional $11.7 billion each from the infrastructure law, and EPA continues to encourage states to fund cyber resilience projects from them. EPA’s Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability grant program made roughly $9,500,000 available nationally in its most recent round. Against 170,000 systems, that is a rounding error.
Translated into budget language: this is going on your rate base. Plan accordingly, and do not build a capital program that assumes a grant cycle which keeps landing on the continuing-resolution chopping block.
What belongs in the FY2027 budget
For a Texas city utility fund, the work sorts into things that cost almost nothing and things that need a line item.
Nearly free, do it this month:
- Inventory every internet-reachable OT device, including anything on a cellular modem. Most cities do not actually know. That inventory is also the foundation the RRA, any future state rule, and CIRCIA readiness all silently assume you already have.
- Take PLCs off direct internet exposure. Remote access through a controlled VPN, not an open port.
- Change default and vendor-set device passwords. Require multifactor authentication for remote access.
- Review your integrator and SCADA vendor’s remote access path. Muleshoe was entered through a third-party vendor’s remote login. Contract language matters here as much as firewalls.
- Confirm who calls the TCEQ hotline and who files the 48-hour state report, by name, and make sure they are not the same person who will be running the plant manually that night.
Needs money in the budget:
- Manual-operation capability and drills. Every utility that came through July intact did so by unplugging and running by hand. That is a staffing and training cost, and it is the cheapest resilience you will ever buy.
- Network segmentation between business IT and plant OT.
- Continuous OT monitoring and logging, sized to the system.
- An incident response plan that has actually been exercised with the city manager and at least one council member in the room.
- Cyber coverage review with your risk pool, and a candid look at what your policy excludes for nation-state activity.
And for the smallest systems: regionalization. A wholesale provider or a shared-services arrangement with a larger neighbor can carry an OT security program that 800 connections cannot. That has been the right answer to the small-system problem in Texas for thirty years for operations, compliance, and capital. It is now the right answer for security too.
A closing thought
There is a temptation to file this under exotic threats — foreign intelligence services, industrial control systems, the language of cyberwar. But strip the geopolitics away and what happened in Braham and Muleshoe was mundane. A controller was left where anyone could reach it. A default password was never changed. A vendor’s remote access was never reviewed. Somebody far away tried the door, and the door opened.
Public infrastructure is stewardship in the plainest sense. Somebody built the tank, somebody bonded it, somebody maintains it, and the water is clean tomorrow because a chain of unremarkable people did unremarkable things faithfully. The chain now includes a firewall rule and a password policy. That is not glamorous work, and it will not be in any ribbon-cutting photo. It should be in the budget anyway.
Sources
- FBI/EPA joint public service announcement, July 30, 2026
- CISA Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” April 7, 2026, updated July 22, 2026
- The New York Times, “Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran,” August 1, 2026
- NBC News, Engadget, Government Technology, The Record, Cybersecurity Dive — July 30–31, 2026 coverage
- Tenable, “What water utilities need to know about cybersecurity compliance,” July 30, 2026
- WaterISAC advisory summary on AA26-097A; IOActive analysis, July 2026
- CNN, Texas Tribune, and Lubbock Avalanche-Journal coverage of the Muleshoe, Abernathy, Hale Center, and Lockney incidents, April and July 2024
- TCEQ, 30 TAC §290.46(w); TCEQ Sunset self-evaluation, Chapter IX; TCEQ Homeland Security for PWS
- Texas HB 150 (89R); Texas SB 1034 (89R); Texas SB 1625 (89R)
- GAO-24-106744; EPA Office of Inspector General management implication report on drinking water cybersecurity
- FEMA State and Local Cybersecurity Grant Program funding history