This Week in Cyber - August 20–26, 2026

This week, more than 100 U.S. water systems were targeted, federal agencies disrupted infrastructure used by Chinese state-sponsored hackers, a cyberattack took a UK power generator offline for four days, and Boston Scientific disclosed a network outage that disrupted global operations.


More than 100 U.S. water systems targeted in July

On August 26, CISA disclosed that malicious actors targeted more than 100 internet-exposed systems in the U.S. water and wastewater sector during July.

The activity commonly targeted programmable logic controllers (PLCs) connected directly to cellular modems. CISA is urging operators to remove unnecessary internet exposure, strengthen access controls, and monitor traffic for abnormal activity.

Why it matters: Attackers don’t need to breach an enterprise network first if the controller itself is already reachable. Internet-exposed PLCs can put access to physical processes directly within reach of anyone scanning for them.


U.S. disrupts Chinese hacking platforms targeting critical infrastructure

On August 26, the Justice Department and FBI seized domains supporting QScan and QTRouter, two platforms operated by the China-linked hacking group QTFY.

QScan scanned for vulnerabilities and automatically infected thousands of IoT devices. QTRouter then used compromised devices to hide the origin of malicious traffic, sometimes making attacks appear to come from systems near the victim.

NSA and FBI said QTFY has targeted military, telecommunications, government, education, and critical infrastructure networks since at least 2018. DOJ said customers of the group included China's Ministry of State Security and People's Liberation Army.

Why it matters: Compromised devices aren’t always the final target. Attackers can turn them into infrastructure for future operations, hiding where attacks originate and making malicious traffic harder to distinguish from legitimate activity.


Cyberattack takes UK power generator offline for four days

On August 24, the UK government briefed energy industry leaders following reports that a cyberattack had disabled a small British power generator for four days in July.

Reports linked the attack to Iran, but the UK government has not confirmed attribution. Officials said the affected generator was small and the incident did not threaten the wider national power grid.

Why it matters: A cyberattack doesn’t have to take down an entire grid to create physical consequences. Four days of lost generation is operational disruption.


Boston Scientific cyber incident disrupts global operations

Boston Scientific identified a cybersecurity incident on August 25 that caused a network outage and disrupted company operations.

The incident affected access to operating systems and business applications, including systems used to process and ship customer orders. As of August 26, Boston Scientific said the investigation was ongoing and it did not yet know when all affected systems would be restored.

Why it matters: The line between an IT incident and an operational incident disappears when the systems required to move products and keep the business running become unavailable.


White House declares national emergency over U.S. bulk-power security

On August 26, the White House issued an executive order declaring a national emergency over risks associated with foreign-produced equipment used in the U.S. bulk-power system.

The order explicitly covers industrial control systems, programmable logic controllers, remote terminal units, intelligent electronic devices, distributed control systems, associated software, firmware, and remote-access capabilities.

The Department of Energy can require certain high-risk equipment to be identified, isolated, monitored, secured, disconnected, replaced, or removed.

Why it matters: Power-system cybersecurity isn’t only a network problem. The equipment, software, remote access, maintenance, and supply chain behind the control environment can all become part of the attack surface.


FBI investigates ransomware breach at water technology supplier

On August 26, Reuters reported that the FBI is investigating a ransomware breach at Micro-Comm, a Kansas company that provides control technology to water and wastewater utilities.

The ransomware group Barracuda claimed it stole roughly 644 GB of data totaling about 850,000 files. Micro-Comm said sensitive user credentials and remote-access information were not compromised. Authorities said the incident appears separate from the recent suspected Iranian activity targeting water utilities.

Why it matters: Water operators depend on technology suppliers to build and maintain the systems they are trying to secure. That makes the vendor ecosystem part of the critical-infrastructure attack surface.


That’s it for this week.

We’ll be back next Thursday with the next Weekly Roundup.

Next
Next

This Week in Cyber - August 13–19, 2026