CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

United States: cybersecurity landscape, July 2026

July ended with OT incidents in water, ransomware in health care and retail, and 7 regulatory moves; SharePoint and AD FS led exploitation.

United States: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 73 dated facts in July 2026. Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · USA Dominant threat: Incidents (23 of 73 events). Coverage: 73 dated events in July 2026 VERIFIED EVENTS 73 period base: all counts measured from below against this total RANSOMWARE / EXTORTION 22 1 asset encrypted confirmed · 1 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 23 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns REGULATION 7 rules, resolutions, or sanctions UNIQUE CVEs 8 CVE-2026-15409 / CVE-2026-15410
Verified Signal Monthly Dashboard — Base: 73 verified events dated within the period for the USA.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · USA Each incident counts on only one axis, so the total is exactly 73. "Unclassified incidents" is the remainder. Incidents 23 Ransomware 22 Vulnerabilities 18 Regulation 7 Unclassified 2 Fraud 1
Threat-axis distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 73 incidents in the period.
MONTHLY FIXED MODULE Sector Breakdown of Signals July 2026 · USA Base: 73 incidents in the period · total 105 because 23 incidents are classified in more than one sector. Public sector / Critical infrastructure 48 Technology 23 Other / no sector ident… 12 Telecom 11 Finance 7 Energy 2 Healthcare 1 Retail / Consumer 1
Sector Breakdown of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so totals can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in the USA July 2026 · USA 9 of 73 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 42 Explicit critical infrastructure 12 Energy / utilities 17 Telecom / Connectivity 6
Critical Infrastructure in the USA — Verified facts on the public sector, utilities, and essential services

Executive monthly summary in USA

July 2026 left the United States with an uneasy mix, coordinated attacks against operational technology at more than 30 water systems in Minnesota, a ransomware and extortion wave that again hit local governments and health care, and an active regulatory push around incident notification, cybersecurity maturity, and AI risk management. The month was driven more by incidents than by new rules. Of the 73 verified events in the period, 23 were classified as untyped incidents and 22 as cases with ransomware or extortion as the primary focus.

The case that best frames the month is Minnesota. Minnesota IT Services confirmed a coordinated cyberattack against community water systems, with outages in Braham, Plymouth, South St. Paul, and other localities. The available material indicates operational impact on controls and pumping, but no water contamination and no classic ransomware campaign with confirmed encryption. Formal attribution remained open throughout the month, although several sources linked the pattern to the Iranian campaign against industrial devices that CISA, FBI, NSA, and the Department of Energy had already described in public alerts.

At the same time, ransomware activity continued to concentrate in health care and local government. Fairlife, Coca-Cola’s US subsidiary, paused production after a ransomware event that compromised manufacturing systems. RingCentral appeared on leak sites claimed by ShinyHunters. Greene County, Georgia, and the City of Atlanta were listed in ransomware trackers. The July material also includes The Morton Grove Park District, City of Houston, and other local entities, although in several cases the source only supports a leak-site appearance or claims not publicly confirmed.

The vulnerability layer was the busiest part of the month. CISA warned about active exploitation of three flaws in SharePoint on-premises, and July’s overall set increased pressure on AD FS, SharePoint, and other internet-exposed products. The contrast with June was clear, there were 8 critical CVEs mentioned in the period’s material, compared with 4 the month before. That does not mean there were no other exploited flaws in the country, only that the July corpus focused attention on these cases.

On the regulatory side, the focus shifted less by volume than by operational density. CIRCIA continued moving toward its final rule, the House passed the NDAA with an extension of the Cybersecurity Information Sharing Act, the GAO released a report questioning duplicate reporting requirements, and the White House launched Gold Eagle as a coordination mechanism for vulnerabilities discovered with AI. The result is a month marked by sharp friction between reporting, coordination, and the real absorption capacity of critical entities.

Cronología de hechos relevantes en USA, julio 2026Línea de tiempo con hitos verificados del mes en incidentes, regulación y vulnerabilidades.USA, July 2026Jul 2DHS investigatesHSIN incidentJul 14SharePoint KEVexploitedJul 15Gold EaglebeginsJul 20 FairlifehaltsJul 23PLC alertIranJul 26-27waterMinnesotaunder attackHighlightsselected fromJuly 2026 onlywith datesconfirmed in thematerialprovided.
Timeline of the most relevant events in the USA, July 2026 — Verified milestones of the month in incidents, regulation, and vulnerabilities.

National Risk Snapshot for the U.S. in July 2026

The U.S. risk reading in July 2026 is high. Not because there was a single major breach, but because three material signals converged: attacks on critical water infrastructure, ransomware and extortion targeting health organizations and local government, and active exploitation of high-impact vulnerabilities in widely used software. The number of verified incidents was high for a single month, and the operational severity of several of them was real, not theoretical.

Tactically, the month showed a preference for targets where the effect is measured quickly. Water, health, public services, and exposed portals. Minnesota carried the story line for physical disruption and OT. Fairlife added the manufacturing and business continuity angle. Leak site and extortion campaigns against municipalities and service providers reinforced that economic pressure remains focused on entities with little tolerance for downtime and unavoidable public exposure.

A comparison with Latin America helps frame the context, even though the report focuses on the U.S. In the same period, there was ransomware activity using relatively rudimentary tools and abuse of Windows environments in the region, along with campaigns exploiting exposed remote services and configuration errors. The pattern repeated on both sides of the hemisphere is less sophisticated than public discourse sometimes suggests: weak credentials, exposed systems, poorly segmented collaboration and operations software, and a regulatory response that trails the incident.

From a defensive perspective, the month leaves one clear takeaway for the U.S.: the critical attack surface is no longer limited to email and endpoints. The mix of OT, SharePoint, AD FS, VPNs, routers, and identity systems pushed teams to look at the full chain of access, persistence, and recovery. Public exposure of administration services and the continued presence of default credentials or weak configuration kept appearing as common factors.

US period indicators

Indicator Value Note
Verified facts for the period 73 Base of all indicators; only facts dated July 2026
Time window for the indicators 73 facts dated July 2026 Closed period window
Unclassified incidents (breaches or outages) 23 Breaches, outages, or other incidents with no closed classification
Cases with ransomware or extortion as the primary focus 22 Period count, not mixed with other impact types
Confirmed asset encryption 1 Ransomware subtype with verified encryption
Exfiltration without encryption (simple extortion) 1 Ransomware subtype with verified exfiltration
Leak site mention only 5 Claims or listings without confirmed public impact
Impact subtype cannot be determined from the material 15 The source does not allow the impact subtype to be closed
Documented fraud or phishing cases 1 Isolated fact in the period
Documented regulatory moves 7 Regulatory, legislative, or compliance actions
Critical CVEs mentioned 8 Only the critical ones mentioned in the analyzed material
Sectors with at least one documented fact 7 One fact may affect more than one sector
Predominant threat of the month Incidents 23 of 73 facts
Facts with direct source confirmation 81% Direct confirmation over the total verified facts

Relevant incidents in the USA

Coordinated attack on Minnesota water systems

Minnesota IT Services confirmed that between July 26 and 27, more than 30 community water systems were affected by a coordinated attack against operational technology. Available reporting describes disruptions in Braham, Plymouth, South St. Paul, and other localities, with impacts on water towers, pumping stations, and treatment plants. In Braham, the water plant was out of service for several hours. The sources agree on one key point, there were no signs of contamination or lasting changes in water quality.

Attribution remained open. The joint advisory from CISA, FBI, NSA, and the Department of Energy had already warned about Iran-linked actors exploiting exposed PLCs in water, power, and municipal services. Several later reports suggested the pattern matched CyberAv3ngers, but the material from the period does not record a closed official attribution. For a monthly report, that means separating the confirmed operational impact from the attribution hypothesis.

Fairlife, production halted after ransomware

Coca-Cola said Fairlife temporarily paused production in the United States after a ransomware attack that compromised part of the systems used for manufacturing. The company itself confirmed the case, and later coverage said unauthorized access reached production systems. At the time of the material, it had not been resolved whether the incident also met a financial materiality threshold for the group.

Public pressure increased when the Anubis group appeared on leak sites claiming responsibility and threatening to publish data. Even so, the month’s source material allows this case to be classified as ransomware with confirmed encryption or operational disruption, because production was suspended. It should not be mixed with leak site cases that do not show verified impact.

DHS and the HSIN exchange network

DHS confirmed it was investigating an incident in a legacy classified information-sharing environment. Reuters and other reports linked it to HSIN, the platform used to share sensitive information among federal, state, and local agencies. Available material did not allow for a determination of the exfiltration type or public attribution, so the case remains an unclassified incident, with high institutional risk because it involves a government coordination system.

AssuranceAmerica and the exposure of millions of records

TechCrunch reported, and Check Point later repeated, that AssuranceAmerica notified a breach exposing personal data and driver’s license numbers of nearly 7 million people. The corpus does not include a full technical breakdown of the intrusion vector or whether ransomware was involved. In risk terms, it remains one of the month’s largest privacy events by affected volume.

RingCentral and ShinyHunters’ claim

RingCentral appeared on ShinyHunters’ leak site with claims involving employee data, user data, and credentials. Available material does not include independent public confirmation from the company about the incident, so the case can only be described as a leak site mention. That distinction matters, because a claim is not the same as a verified breach, much less confirmation of full exfiltration.

Greene County, Georgia, and other listed municipalities

Greene County, Georgia, appears in ransomware trackers as a presumed victim of Incransom. The City of Atlanta, City of Houston, West Chester Township, and Town of Vienna also appear in records from the same tracking ecosystem. In several of these cases, the public evidence consists of the leak site listing or trackers such as ransomware.live, with no official municipal statement or detail on the real scope. The monthly picture shows persistent pressure on local governments, but it does not allow all of those records to be treated as equivalent incidents.

Active threats and campaigns in the USA

Ransomware, encryption and simple extortion

The only case the material allows to classify as confirmed encryption is Fairlife, because of production disruptions at plants in the United States. The rest of the ransomware or extortion cases are split between exfiltration without encryption, leak site only mentions, and cases that cannot be classified. That spread does not reduce their operational value, but it does prevent grouping everything under one label without losing precision.

Subtype Cases Monthly reading
Confirmed asset encryption 1 Verified direct operational impact
Exfiltration without encryption 1 Simple extortion with claimed data
Leak site only mention 5 Public claim without independent confirmation
Cannot be determined 15 Not enough detail to lock the subtype

Fraud and phishing

Only one case was documented as fraud or phishing during the period. That should not be read as the absence of fraudulent activity in the country, but as the absence of events dated July 2026 and with sufficient confirmation within the body of work used for this report.

APT, hacktivism and campaigns against OT

The campaign linked to Iran against industrial devices remains the month’s main sign of operational APT or hacktivism in the USA. CISA, FBI, NSA and the Department of Energy said the actors are exploiting exposed PLCs and other OT equipment in water, energy and municipal services. Minnesota fits that frame based on the type of impact and the use of operational technology as the incident vector. The material does not settle final attribution, but it does make clear that the focus is critical infrastructure with public exposure.

Critical vulnerabilities with U.S. impact

CVE Software Exploitation Source
CVE-2026-32201 Microsoft SharePoint Server on-premises Active exploitation, unauthorized access and possible authentication bypass CISA
CVE-2026-45659 Microsoft SharePoint Server on-premises Active exploitation, deserialization and persistent access CISA
CVE-2026-56164 Microsoft SharePoint Server on-premises Active exploitation, missing authentication for critical function CISA
CVE-2026-56155 Active Directory Federation Services Active exploitation, local privilege escalation CISA
CVE-2026-50522 Microsoft SharePoint Added to KEV for evidence of active exploitation knutmichael.com
CVE-2026-16232 Check Point SmartConsole Exploitation in the wild, authentication bypass Rapid7
CVE-2026-15409 SonicWall SMA 1000 Added to KEV, actively exploited Secarma
CVE-2026-15410 SonicWall SMA 1000 Added to KEV, actively exploited Secarma

This month’s material puts SharePoint at the center of the defensive agenda. CISA did not just warn about active exploitation, it also recommended blocking exposed central administration, rotating IIS keys, and looking for known deserialization and persistence techniques. In AD FS, the issue was no less serious, because the exposure affects identity, authentication, and remote access, three layers many organizations still treat separately.

Regulation and compliance in the USA

July brought seven documented regulatory moves in the United States. The most important thread was CIRCIA, whose final rule CISA expects to close in September 2026. That rule will require reporting substantial cyber incidents within 72 hours and ransomware payments within 24 hours. The deadline is no longer theoretical. CISA has been holding town halls with critical sectors to define implementation, and the public debate shows the tension between more reporting and less operational friction.

The House of Representatives approved its version of the fiscal 2027 NDAA with a nine-year extension of the Cybersecurity Information Sharing Act of 2015. That matters because it keeps the information-sharing architecture alive as a core part of the US model. At the same time, the GAO released a report that found 117 cybersecurity regulations issued by 37 agencies, with 80 of them containing potentially duplicative reporting requirements. The message is clear: the regulatory ecosystem keeps growing, but it is still not organized.

The White House also pushed Gold Eagle, a coordination initiative for vulnerabilities discovered by AI. It is not yet a law or a new regulator, but rather a coordination platform among agencies, companies, and critical operators. At the same time, FINRA and the Treasury advanced AI risk management frameworks for the financial sector, confirming that the discussion is no longer limited to traditional cybersecurity, but also includes model governance.

Regulatory move Date Scope
CIRCIA moves toward final rule July 2026 Incident and ransomware payment reporting
Fiscal 2027 NDAA approved in the House 23 July Nine-year extension of CISA 2015
GAO report on duplication 22 July 117 regulations in 9 sectors
Gold Eagle launched 14 July AI vulnerability coordination
FINRA AI risk guidance 10 July GenAI risk in financial services

Most affected sectors in the USA

Local public sector was among the hardest hit this month. Minnesota put water utilities and municipal governments in the spotlight. Greene County, Houston, Atlanta, Vienna, and other names that appear in ransomware trackers reinforce the same point, local governments remain recurring targets, often with limited capacity to absorb prolonged incidents and with high public exposure by design.

Healthcare was again among the most affected sectors, although July's corpus shows both direct attacks and large-scale collateral impacts. Fairlife is not healthcare in the strict sense, but it is food and manufacturing, and its case adds to the persistence of breaches and extortion targeting hospitals, clinics, and vendors. The material also includes references to hospitals in other regulatory and criminal contexts, confirming that the sector remains under sustained pressure.

Critical water and energy infrastructure was the other block of structural relevance. The novelty there was not a single isolated campaign, but the repetition of a pattern: exposed PLCs, weak authentication, operation interfaces accessible from the internet, and an attacker's ability to alter or disrupt physical operations. When the flaw is exposure, the attack surface depends not only on the equipment manufacturer, but on the entire management architecture.

The comparison with the previous month shows that regulation fell from 19 to 7 documented events, while the critical CVEs mentioned rose from 4 to 8. That shift does not mean regulatory risk disappeared or that technical exploitation is anything new. It does show that the July corpus was weighted toward concrete operations, incidents, campaigns, and vulnerabilities being actively exploited.

The leading threat category moved from regulation in the previous month to incidents in July, with 23 of 73 events. That shift matters. In practice, the month’s pressure was no longer centered on policy debate, but on responding to events with real operational impact, especially water, health care, manufacturing, and local government.

The fraud or phishing figure did not change from the previous month. There was one case in June and one in July. There is not enough basis to say fraud went down or up in the country based on the available corpus, only that the material analyzed kept a marginal presence compared with incidents and vulnerabilities.

The vulnerabilities section deserves close monitoring. SharePoint continued to appear as an entry and persistence vector, AD FS as a sensitive identity point, and Check Point SmartConsole as an example of in-the-wild exploitation. In other words, the month left a short but highly sensitive list of products that should be high priority for patching and compromise hunting.

Security recommendations for teams in USA

First, review public exposure of management and collaboration services. SharePoint on-premises, AD FS, VPNs, routers, and OT portals should not be reachable from the Internet unless there is a strict need and compensating controls are in place. If an instance must be exposed, hardening has to happen before publication, not after an incident.

Second, rotate credentials and secrets tied to IIS, SharePoint farms, edge devices, and remote access services. The July material keeps repeating the same pattern: attackers do not need exotic malware if they can steal machine keys, abuse valid accounts, or exploit weak configurations.

Third, segment OT from IT based on operational need, not just on paper. The Minnesota case sends a clear signal for water, energy, and public services: remote administration, PLCs, and HMI monitoring cannot share a trust boundary with standard corporate systems.

Fourth, prepare active hunting for persistence. In SharePoint, that means looking for anomalous deserialization, web shells, configuration changes, new machine keys, and suspicious outbound connections. In OT, it means reviewing remote access, logic changes, screen alterations, and after-hours events.

Fifth, align legal, continuity, and technical response before an incident. With CIRCIA moving forward, the 72-hour and 24-hour deadlines for certain reports will require traceability, evidence, and early decision-making. The team that waits for forensic closure before notifying will probably be too late.

Material limitations

This report was prepared exclusively from the facts dated July 2026 included in the provided material. The indicator window covers 73 facts dated July 2026, and no aggregated telemetry or material outside that cutoff was included. Facts from earlier months were used only when relevant to compare trends, and always with their explicit month.

An indicator at 0, especially in the CVE section or any other category, means only that it did not appear in the material analyzed for this period, not that the fact does not exist in the USA or in the region. The same applies when the ransomware classification could not be closed, the absence of a subtype does not mean the absence of an incident.

The material excluded consumer social networks, LinkedIn posts, and sponsored or commercial content that was not within the enabled sources. As an integrity criterion, attempts, blocks, scans, and other forms of telemetry that do not constitute verifiable incidents for the period were also left out. When attribution was only suggested by a tracker or by a secondary source without official confirmation, it was treated as such and not as certainty.

Sources