• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

Cyber Incidents USA 2026-27

August 18, 2026
Mapping Iranian Cyberattacks on U.S. Water Systems

In late July, Minnesota authorities disclosed that hackers had attacked not one or two water systems—but more than 30 across the state. The following weeks saw additional revelations in other states. Officials are beginning to understand the scope of what is likely an Iranian cyber campaign months in the making. Although the U.S. government has not publicly attributed the attacks, an Iranian actor linked to the Islamic Revolutionary Guard Corps (IRGC) known as the CyberAv3ngers has claimed responsibility, stating their intention was to “warn America to back down.”

The following set of charts brings together existing press reporting and CSIS expert analysis to provide a picture of what is known about the cyberattacks on the U.S. water sector so far. It is important to acknowledge that the reporting is thus far incomplete; the current understanding of the scope and scale of the attacks is reliant on states self-reporting incidents as they search their technical logs from recent weeks, and reporting requirements are inconsistent at best.

This style of attack is not new for Iran; water facilities have become something of an Iranian specialty. Actors linked to Iran attacked water facilities in the United States as far back as 2013 in New York and Pennsylvania in 2023; they also attacked water systems in Israelin 2020 and 2023. But these earlier attacks went after only one or a handful of targets, whereas the 2026 attacks simultaneously hit at least 12 states and multiple targets.​

Continued: https://www.csis.org/analysis/mapping-iranian-cyberattacks-us-water-systems




 
FBI Press Release
August 18, 2026

17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities

Mabna Institute Hackers Attacked Systems Belonging to Hundreds of Universities, Companies, and Other Victims to Steal Research, Academic and Proprietary Data, and Intellectual Property

A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. The defendants conducted many of these intrusions on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), one of several entities within the government of Iran responsible for gathering intelligence, as well as other Iranian government and university clients. Nine of the 17 defendants charged in the S2 indictment were previously charged in a 7-count indictment announced in March 2018. The case is assigned to U.S. District Judge Jesse M. Furman.

Continued: https://www.justice.gov/opa/pr/17-i...r-theft-campaign-behalf-islamic-revolutionary

 
[emphasis is mine]

August 19, 2026
Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them. The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs. could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.

The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:

• are properly protected with all applicable security patches and updates,

• are isolated from the Internet wherever possible,

• have strong access controls, and

• employ security tooling to monitor ICS environments for anomalous or malicious activity.

These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.

Technical details


Top Mitigations

Inventory all Siemens S7 Series programmable logic controllers (PLCs)

Apply critical security patches

Ensure PLCs are not accessible from the Internet

Strengthen access controls

Monitor for unauthorized activity

Harden PLC services, protocols, and ladder logic integrity

Hunt for anomalies that may indicate a compromise

Continued: https://www.ic3.gov/CSA/2026/260819.pdf



 
Tip of the Week – August 20, 2026

Review Network Segmentation

Separating operational technology (OT) from business IT networks can help limit the impact of a cyberattack. Water utilities should periodically review firewall rules, network connections, and pathways between IT and OT environments to confirm that only necessary communications are permitted. Strong network segmentation can prevent an attacker who compromises an IT system from easily reaching critical control systems and PLCs.

https://www.waterisac.org/tip-of-the-week-august-20-2026
 
(TLP:CLEAR) Supplemental General Security & Resilience Highlights – August 20, 2026
August 20, 2026​

The following posts are useful for general awareness of current physical security threats, natural disaster resilience, preparedness resources, mitigation guidance, and other security-related news or updates. These resources have been curated by the WaterISAC analyst team as items of broad relevance and benefit that do not need supplemental analysis at this time.

Continued: https://www.waterisac.org/tlpclear-...security-resilience-highlights-august-20-2026
 
August 20, 2026

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring.​

Continued: https://www.cisa.gov/news-events/ne...-federal-agencies-implement-effective-logging

 
Massachusetts, Andover
August 22, 2026

ANDOVER, MA — A cyberattack was responsible for a four-day network outage earlier this month that disrupted Town departments, delayed the release of teacher assignments to Andover Public Schools families and frustrated residents trying to access some municipal services.

Town Manager Andrew Flanagan confirmed in an email Friday that the disruption, first detected Aug. 13, was the result of a cyberattack. An investigation into the incident remains ongoing. The disclosure provides the first public explanation for an outage that Town officials initially described only as a temporary internet connectivity problem.

Continued: https://andovermanews.com/cyberattack-caused-four-day-network-outage-for-town-aps/
 
Back
Top