Iran-Linked Cyberattacks Target US Water Utilities in Multi-State Disruption
Hackers linked to Iran have compromised internet-exposed industrial controllers at water facilities across at least 12 states, forcing operators to switch to manual controls.
By Sergei Orlov
- Federal Cybersecurity Agencies
- Focuses on the urgent need to remove industrial control systems from the public internet.
- Municipal Water Operators
- Emphasizes the effectiveness of analog resilience and manual overrides.
- Threat Intelligence Analysts
- Views the campaign as opportunistic geopolitical signaling rather than advanced warfare.
Why this matters
While no drinking water was contaminated, the breaches highlight how easily critical American infrastructure can be disrupted when small municipalities leave industrial control systems plugged directly into the public internet without basic security.
Key points
- Hackers linked to Iran compromised water utilities in at least 12 U.S. states.
- The attackers targeted internet-exposed Programmable Logic Controllers (PLCs) with weak passwords.
- Intrusions caused temporary pressure drops and boil-water advisories, but no water was contaminated.
- Operators successfully mitigated the attacks by disconnecting systems and switching to manual controls.
Hackers linked to Iran have disrupted operations at municipal water utilities across at least 12 U.S. states over the past two weeks. By targeting internet-exposed industrial controllers, the attackers locked local operators out of their own systems, causing temporary pressure drops and forcing several towns to issue boil-water advisories. Yet despite the alarming headlines suggesting a sophisticated cyberwarfare campaign, no drinking water was actually contaminated. The breaches relied entirely on basic administrative negligence—specifically, leaving critical infrastructure plugged directly into the public internet—rather than advanced hacking capabilities.[1][3]
The campaign began in late July, initially striking roughly 30 community water systems in Minnesota before expanding to facilities in Michigan, Georgia, South Dakota, and other states. In Clayton County, Georgia, the intrusion caused a sudden drop in water pressure that triggered a precautionary boil-water notice, though service was restored within hours. Other facilities reported minor flooding or a loss of remote telemetry, forcing local IT departments to scramble to regain visibility over their own networks.[2][3][5]
The mechanics of the attack reveal a stark reality about American critical infrastructure: the vulnerability was entirely preventable. The attackers targeted Programmable Logic Controllers (PLCs)—specifically Rockwell Automation and Allen-Bradley models like the MicroLogix 1100 and 1400—that manage water pressure, pumps, and chemical treatment levels. These devices are designed to automate complex industrial processes, but they are not inherently secure when exposed to the outside world.[4][6][7]
Rather than deploying complex zero-day exploits to burn through enterprise firewalls, the hackers simply scanned the public web for PLCs that had been left exposed, often secured by weak or default passwords. Once inside the administrative panels, the threat actors modified the passwords and altered the devices' IP addresses. This effectively locked the legitimate operators out of the digital dashboard, creating a denial-of-service condition without actually destroying any hardware.[1][4][8]

"These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases," noted Joshua Corman, a public safety expert at the Institute for Security and Technology. The capability demonstrated here is less about elite state-sponsored hacking and more about automated opportunism—rattling digital doorknobs until an unlocked one opens, then changing the locks.[1][5]
In response to the escalating campaign, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Environmental Protection Agency issued urgent joint advisories. Their primary directive to the water sector was remarkably analog: disconnect all vulnerable industrial equipment from the public internet immediately, implement strict firewall rules, and prepare to run facilities manually until the networks can be properly secured.[4][6]
That manual fallback proved to be the saving grace for the targeted municipalities. When the digital dashboards went dark, operators simply walked onto the plant floors and physically took control of the pumps and valves. The ability to physically override the compromised PLCs ensured that chemical treatment levels remained safe and that no public health crisis materialized, proving that analog resilience is often the best defense against digital intrusion.[1][2][8]
That manual fallback proved to be the saving grace for the targeted municipalities.
While federal agencies have stopped short of issuing a formal, named attribution, multiple intelligence officials and cybersecurity firms have linked the activity to Iranian state-sponsored actors or affiliated proxy groups. The campaign mirrors a similar 2023 offensive by the IRGC-affiliated "CyberAv3ngers," which targeted Unitronics PLCs at water facilities using identical tactics of exploiting default credentials on internet-facing devices.[3][7]

Security analysts suggest the current wave of intrusions is likely a geopolitical signaling exercise rather than an attempt to cause mass casualties. By disrupting lifeline services in small American towns, the attackers demonstrate reach and capability without crossing the threshold into outright destructive warfare. It is a low-cost, high-visibility method of projecting power.[1][7]
The broader takeaway for the cybersecurity sector is a renewed focus on the "security poverty line." While massive federal agencies and Fortune 500 companies deploy AI-driven threat hunting, thousands of small municipal water districts lack the budget for dedicated IT staff. Until the baseline security of these local utilities is funded and enforced, critical infrastructure will remain vulnerable to anyone with a port scanner and a list of default passwords.[1][4][8]
Viewpoints in depth
Federal Cybersecurity Agencies
Focuses on the urgent need to remove industrial control systems from the public internet.
Agencies like CISA and the FBI view these intrusions as a glaring failure of basic cyber hygiene. Their advisories stress that Programmable Logic Controllers were never designed to be internet-facing without robust firewalls and VPNs. From the federal perspective, the immediate fix is not advanced threat hunting, but simply unplugging vulnerable operational technology from the public web.
Municipal Water Operators
Emphasizes the effectiveness of analog resilience and manual overrides.
For local utility managers, the narrative centers on operational continuity rather than digital defeat. While acknowledging the IT breach, operators highlight that their ability to physically walk onto the plant floor and manually turn valves prevented any actual water contamination. They argue that this analog redundancy is the ultimate failsafe against cyber threats.
Threat Intelligence Analysts
Views the campaign as opportunistic geopolitical signaling rather than advanced warfare.
Security researchers point out that the attackers did not use sophisticated zero-day exploits or custom malware. Instead, they relied on automated scanning to find low-hanging fruit—devices with default passwords. Analysts interpret this as a low-cost way for state-sponsored actors to project power and cause psychological disruption without triggering a massive retaliatory response.
Sources
[1]CBS NewsMunicipal Water Operators
Cyberattacks on U.S. water systems highlight vulnerabilities
Read on CBS News →[2]Nextgov/FCWFederal Cybersecurity Agencies
CISA urges water utilities to take exposed systems down after Minnesota hacks
Read on Nextgov/FCW →[3]The RecordMunicipal Water Operators
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Read on The Record →[4]Cyber MagazineThreat Intelligence Analysts
Iran-Linked Cyberattack on US Water Systems Explained
Read on Cyber Magazine →[5]Quartz
Iran-linked hackers suspected in wave of cyberattacks on water systems across 7 states
Read on Quartz →[6]CISAFederal Cybersecurity Agencies
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLC) Across US Critical Infrastructure
Read on CISA →[7]ShieldWorkzThreat Intelligence Analysts
Campaign overview: Iranian cyber threats actively targeting U.S. critical infrastructure PLCs
Read on ShieldWorkz →[8]Industrial CyberThreat Intelligence Analysts
LevelBlue review finds attackers exploited exposed PLCs and remote access to disrupt US water infrastructure
Read on Industrial Cyber →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.










