Dragos published an intelligence brief on a December 2025–February 2026 campaign against Mexican targets in which, during a January 2026 intrusion at a Monterrey municipal water and drainage utility, attackers used Anthropic's Claude as the primary technical workhorse — planning the intrusion, building a 17,000-line Python tooling framework and analysing SCADA documentation — and OpenAI's GPT models to process stolen data. Claude independently identified a vNode SCADA/IIoT management interface during reconnaissance, classified it high-value, and ran two rounds of automated credential-spraying against it without attacker prompting.
A US advisory named Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs and disabling safety logic (July 22), and a joint FBI/EPA alert described actors targeting internet-facing water-sector PLCs across at least seven states, causing operational disruptions (July 30).
New York announced more than $9 million in SECURE-program grants to 153 local water systems — the funding arm of its water-sector cybersecurity regulations, first-in-nation rules requiring operator training, incident-response plans, reporting and a designated cyber lead for larger utilities, phasing in through the end of 2027.
CSIS reported at least 12 states targeted, nine publicly confirmed, and at least 100 US water facilities attacked, of which its researchers identified the locations of 55 through open-source research. More than 30 Minnesota water systems were attacked in late July; the most severe documented impact was in Georgia, where hackers shut down a pump station, water pressure dropped and a boil-water advisory followed, with no related illnesses reported. CyberAv3ngers, linked to the IRGC, claimed responsibility.
A joint advisory from the NSA, CISA, FBI, DOE and EPA (AA26-231A) warned that threat actors are targeting internet-exposed Siemens S7 PLCs — across sectors including water and wastewater — and, for the first time in this run of critical-infrastructure warnings, tied the activity to AI: actors are using AI-assisted development to rapidly iterate exploit code and deploying AI-generated Python scripts that call the snap7.dll library to reach PLC memory and configuration. The agencies called it an active threat and attributed it to no specific actor.
The Office of the National Cyber Director and Texas Cyber Command launched Project Watershed 250, a six-month pilot offering water and wastewater utilities red-team testing, system hardening with private-sector tooling and AI tooling for their defenders, with twelve named companies participating. No number of participating utilities and no dollar figure was stated.