Iran-Linked Cyberattacks Target US Water Utilities in Multi-State Disruption
Hackers linked to Iran have compromised internet-exposed industrial controllers at water facilities across at least 12 states, forcing operators to switch to manual controls.
By Sergei Orlov
Hackers linked to Iran have disrupted operations at municipal water utilities across at least 12 U.S. states over the past two weeks. By targeting internet-exposed industrial controllers, the attackers locked local operators out of their own systems, causing temporary pressure drops and forcing several towns to issue boil-water advisories. Yet despite the alarming headlines suggesting a sophisticated cyberwarfare campaign, no drinking water was actually contaminated. The breaches relied entirely on basic administrative negligence—specifically, leaving critical infrastructure plugged directly into the public internet—rather than advanced hacking capabilities.[1][3]
The campaign began in late July, initially striking roughly 30 community water systems in Minnesota before expanding to facilities in Michigan, Georgia, South Dakota, and other states. In Clayton County, Georgia, the intrusion caused a sudden drop in water pressure that triggered a precautionary boil-water notice, though service was restored within hours. Other facilities reported minor flooding or a loss of remote telemetry, forcing local IT departments to scramble to regain visibility over their own networks.[2][3][5]
The mechanics of the attack reveal a stark reality about American critical infrastructure: the vulnerability was entirely preventable. The attackers targeted Programmable Logic Controllers (PLCs)—specifically Rockwell Automation and Allen-Bradley models like the MicroLogix 1100 and 1400—that manage water pressure, pumps, and chemical treatment levels. These devices are designed to automate complex industrial processes, but they are not inherently secure when exposed to the outside world.[4][6][7]
Rather than deploying complex zero-day exploits to burn through enterprise firewalls, the hackers simply scanned the public web for PLCs that had been left exposed, often secured by weak or default passwords. Once inside the administrative panels, the threat actors modified the passwords and altered the devices' IP addresses. This effectively locked the legitimate operators out of the digital dashboard, creating a denial-of-service condition without actually destroying any hardware.[1][4][8]
"These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases," noted Joshua Corman, a public safety expert at the Institute for Security and Technology. The capability demonstrated here is less about elite state-sponsored hacking and more about automated opportunism—rattling digital doorknobs until an unlocked one opens, then changing the locks.[1][5]
In response to the escalating campaign, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Environmental Protection Agency issued urgent joint advisories. Their primary directive to the water sector was remarkably analog: disconnect all vulnerable industrial equipment from the public internet immediately, implement strict firewall rules, and prepare to run facilities manually until the networks can be properly secured.[4][6]
That manual fallback proved to be the saving grace for the targeted municipalities. When the digital dashboards went dark, operators simply walked onto the plant floors and physically took control of the pumps and valves. The ability to physically override the compromised PLCs ensured that chemical treatment levels remained safe and that no public health crisis materialized, proving that analog resilience is often the best defense against digital intrusion.[1][2][8]
While federal agencies have stopped short of issuing a formal, named attribution, multiple intelligence officials and cybersecurity firms have linked the activity to Iranian state-sponsored actors or affiliated proxy groups. The campaign mirrors a similar 2023 offensive by the IRGC-affiliated "CyberAv3ngers," which targeted Unitronics PLCs at water facilities using identical tactics of exploiting default credentials on internet-facing devices.[3][7]
Security analysts suggest the current wave of intrusions is likely a geopolitical signaling exercise rather than an attempt to cause mass casualties. By disrupting lifeline services in small American towns, the attackers demonstrate reach and capability without crossing the threshold into outright destructive warfare. It is a low-cost, high-visibility method of projecting power.[1][7]
The broader takeaway for the cybersecurity sector is a renewed focus on the "security poverty line." While massive federal agencies and Fortune 500 companies deploy AI-driven threat hunting, thousands of small municipal water districts lack the budget for dedicated IT staff. Until the baseline security of these local utilities is funded and enforced, critical infrastructure will remain vulnerable to anyone with a port scanner and a list of default passwords.[1][4][8]
Key points
- Hackers linked to Iran compromised water utilities in at least 12 U.S. states.
- The attackers targeted internet-exposed Programmable Logic Controllers (PLCs) with weak passwords.
- Intrusions caused temporary pressure drops and boil-water advisories, but no water was contaminated.
- Operators successfully mitigated the attacks by disconnecting systems and switching to manual controls.
- Federal Cybersecurity Agencies
- Focuses on the urgent need to remove industrial control systems from the public internet.
- Municipal Water Operators
- Emphasizes the effectiveness of analog resilience and manual overrides.
- Threat Intelligence Analysts
- Views the campaign as opportunistic geopolitical signaling rather than advanced warfare.
Perspectives this story doesn't cover
- Local residents affected by boil-water advisories
- Industrial control system manufacturers
Sources
[1]CBS NewsMunicipal Water OperatorsCyberattacks on U.S. water systems highlight vulnerabilities
Read on CBS News →
[2]Nextgov/FCWFederal Cybersecurity AgenciesCISA urges water utilities to take exposed systems down after Minnesota hacks
Read on Nextgov/FCW →
[3]The RecordMunicipal Water OperatorsCyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Read on The Record →
[4]Cyber MagazineThreat Intelligence AnalystsIran-Linked Cyberattack on US Water Systems Explained
Read on Cyber Magazine →
[5]QuartzIran-linked hackers suspected in wave of cyberattacks on water systems across 7 states
Read on Quartz →
[6]CISAFederal Cybersecurity AgenciesIranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLC) Across US Critical Infrastructure
Read on CISA →
[7]ShieldWorkzThreat Intelligence AnalystsCampaign overview: Iranian cyber threats actively targeting U.S. critical infrastructure PLCs
Read on ShieldWorkz →
[8]Industrial CyberThreat Intelligence AnalystsLevelBlue review finds attackers exploited exposed PLCs and remote access to disrupt US water infrastructure
Read on Industrial Cyber →
More in Technology
See all →Enterprise Security
Citrix Confirms Two Unpatched Zero-Day Vulnerabilities in NetScaler Under Active Exploitation
5 sources
OAuth 2.0
The Six Steps of the OAuth 2.0 Authorization Code Flow with PKCE
4 sources
Core Vulnerability
WordPress Patches Critical Core Vulnerability as Attackers Exploit Flaw Within Hours
5 sources
Maritime Security
FBI and Coast Guard Board US-Bound Oil Tankers Following Suspected Cyberattacks
5 sources
Comments
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns, free every day.




