ONE HUNDRED WATER SYSTEMS. THE SUMMER NOBODY NOTICED.

CISA confirmed it in September: over 100 U.S. water providers were compromised by Iranian-affiliated threat actors during summer 2026 (CISA Advisory AA26-097A). Not probed. Not scanned. Compromised. Hackers linked to the Iranian government gained access to programmable logic controllers and SCADA systems — the equipment that controls chemical dosing, pump operations, water distribution.

This happened during an active conflict between the United States, Israel, and Iran. It was retaliatory critical infrastructure targeting, and the scale says it wasn't opportunistic. One hundred municipal water systems don't fall to the same threat actor in the same summer by accident.

The advisory notes exploitation of PLCs across U.S. critical infrastructure. That means default credentials, unpatched systems, or no network segmentation — industrial control systems sitting internet-accessible with inadequate access controls. Municipal water facilities, the ones that keep cities running, left exposed.

Critical infrastructure gets ignored because the budget goes to the flashy stuff — threat intel subscriptions, EDR platforms, the security theater that makes executives feel protected. Meanwhile, the water treatment plant three miles from your house is running SCADA on Windows XP with the default admin password, and nobody with budget authority thinks that's their problem.

Here's what 100 compromised water systems actually means:

If those accesses were coordinated into sabotage — chemical dosing manipulated, pumps shut down, water supply interrupted — you're looking at mass civilian disruption. Not a data breach you find out about six months later. Immediate, physical harm. People without drinking water. Hospitals without water. Dialysis centers, fire suppression systems, sanitation — all of it stops.

The attackers didn't do that. They could have. They established access and persistence, which means they're sitting there, waiting, in case the conflict escalates to the point where shutting down American cities' water supply becomes tactically useful.

This is what happens when critical infrastructure cybersecurity is treated as optional. Municipal water systems are chronically under-resourced. There's no federal mandate requiring them to meet baseline security standards. The EPA regulates water quality, not the security of the systems that control it. So small towns and mid-sized cities are out here with ICS connected to the public internet, because nobody told them not to and nobody gave them the budget to do it right.

I'm dying. Pulmonary fibrosis — six months to two years, they said in July 2024. Still here. That diagnosis is the only reason I can write this without worrying about burning professional bridges or upsetting someone who might hire me later. I have nothing left to sell you and no reason to lie.

So here's the part nobody in the industry wants to say out loud: The people securing your critical infrastructure are not the ones making the decisions about what gets funded. The expertise exists. The tooling exists. What doesn't exist is the political will to treat water systems like the life-or-death dependency they are.

One hundred compromised water providers. An entire summer. And most people are hearing about it for the first time right now, months later, in a CISA advisory written in the past tense.

The access is still there. The vulnerabilities that let Iranian APT in are still there in every other under-resourced water district that hasn't been named yet. And the next time a conflict flares up, the question won't be whether critical infrastructure can be weaponized — it'll be whether anyone decided it was worth protecting before it was too late.

Alexius McMullin is a cybersecurity consultant. Autistic, terminally ill, and done pretending the industry's priorities make sense.