Skip to main content
Critical InfrastructureThreat AnalysisAug 9, 2026, 5:22 PM· 4 min read· #1 of 3 in technology

Iran-Linked Cyberattacks Target US Water Utilities in Multi-State Disruption

Hackers linked to Iran have compromised internet-exposed industrial controllers at water facilities across at least 12 states, forcing operators to switch to manual controls.

By Sergei Orlov

Federal Cybersecurity Agencies 40%Municipal Water Operators 30%Threat Intelligence Analysts 30%
Federal Cybersecurity Agencies
Focuses on the urgent need to remove industrial control systems from the public internet.
Municipal Water Operators
Emphasizes the effectiveness of analog resilience and manual overrides.
Threat Intelligence Analysts
Views the campaign as opportunistic geopolitical signaling rather than advanced warfare.

Why this matters

While no drinking water was contaminated, the breaches highlight how easily critical American infrastructure can be disrupted when small municipalities leave industrial control systems plugged directly into the public internet without basic security.

Key points

  • Hackers linked to Iran compromised water utilities in at least 12 U.S. states.
  • The attackers targeted internet-exposed Programmable Logic Controllers (PLCs) with weak passwords.
  • Intrusions caused temporary pressure drops and boil-water advisories, but no water was contaminated.
  • Operators successfully mitigated the attacks by disconnecting systems and switching to manual controls.

Hackers linked to Iran have disrupted operations at municipal water utilities across at least 12 U.S. states over the past two weeks. By targeting internet-exposed industrial controllers, the attackers locked local operators out of their own systems, causing temporary pressure drops and forcing several towns to issue boil-water advisories. Yet despite the alarming headlines suggesting a sophisticated cyberwarfare campaign, no drinking water was actually contaminated. The breaches relied entirely on basic administrative negligence—specifically, leaving critical infrastructure plugged directly into the public internet—rather than advanced hacking capabilities.[1][3]

The campaign began in late July, initially striking roughly 30 community water systems in Minnesota before expanding to facilities in Michigan, Georgia, South Dakota, and other states. In Clayton County, Georgia, the intrusion caused a sudden drop in water pressure that triggered a precautionary boil-water notice, though service was restored within hours. Other facilities reported minor flooding or a loss of remote telemetry, forcing local IT departments to scramble to regain visibility over their own networks.[2][3][5]

The mechanics of the attack reveal a stark reality about American critical infrastructure: the vulnerability was entirely preventable. The attackers targeted Programmable Logic Controllers (PLCs)—specifically Rockwell Automation and Allen-Bradley models like the MicroLogix 1100 and 1400—that manage water pressure, pumps, and chemical treatment levels. These devices are designed to automate complex industrial processes, but they are not inherently secure when exposed to the outside world.[4][6][7]

Rather than deploying complex zero-day exploits to burn through enterprise firewalls, the hackers simply scanned the public web for PLCs that had been left exposed, often secured by weak or default passwords. Once inside the administrative panels, the threat actors modified the passwords and altered the devices' IP addresses. This effectively locked the legitimate operators out of the digital dashboard, creating a denial-of-service condition without actually destroying any hardware.[1][4][8]

The attacks targeted internet-exposed Programmable Logic Controllers (PLCs) secured by weak or default passwords.
The attacks targeted internet-exposed Programmable Logic Controllers (PLCs) secured by weak or default passwords.

"These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases," noted Joshua Corman, a public safety expert at the Institute for Security and Technology. The capability demonstrated here is less about elite state-sponsored hacking and more about automated opportunism—rattling digital doorknobs until an unlocked one opens, then changing the locks.[1][5]

In response to the escalating campaign, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Environmental Protection Agency issued urgent joint advisories. Their primary directive to the water sector was remarkably analog: disconnect all vulnerable industrial equipment from the public internet immediately, implement strict firewall rules, and prepare to run facilities manually until the networks can be properly secured.[4][6]

That manual fallback proved to be the saving grace for the targeted municipalities. When the digital dashboards went dark, operators simply walked onto the plant floors and physically took control of the pumps and valves. The ability to physically override the compromised PLCs ensured that chemical treatment levels remained safe and that no public health crisis materialized, proving that analog resilience is often the best defense against digital intrusion.[1][2][8]

That manual fallback proved to be the saving grace for the targeted municipalities.

While federal agencies have stopped short of issuing a formal, named attribution, multiple intelligence officials and cybersecurity firms have linked the activity to Iranian state-sponsored actors or affiliated proxy groups. The campaign mirrors a similar 2023 offensive by the IRGC-affiliated "CyberAv3ngers," which targeted Unitronics PLCs at water facilities using identical tactics of exploiting default credentials on internet-facing devices.[3][7]

The campaign expanded from an initial cluster in Minnesota to affect facilities in at least 12 states.
The campaign expanded from an initial cluster in Minnesota to affect facilities in at least 12 states.

Security analysts suggest the current wave of intrusions is likely a geopolitical signaling exercise rather than an attempt to cause mass casualties. By disrupting lifeline services in small American towns, the attackers demonstrate reach and capability without crossing the threshold into outright destructive warfare. It is a low-cost, high-visibility method of projecting power.[1][7]

The broader takeaway for the cybersecurity sector is a renewed focus on the "security poverty line." While massive federal agencies and Fortune 500 companies deploy AI-driven threat hunting, thousands of small municipal water districts lack the budget for dedicated IT staff. Until the baseline security of these local utilities is funded and enforced, critical infrastructure will remain vulnerable to anyone with a port scanner and a list of default passwords.[1][4][8]

Viewpoints in depth

Federal Cybersecurity Agencies

Focuses on the urgent need to remove industrial control systems from the public internet.

Agencies like CISA and the FBI view these intrusions as a glaring failure of basic cyber hygiene. Their advisories stress that Programmable Logic Controllers were never designed to be internet-facing without robust firewalls and VPNs. From the federal perspective, the immediate fix is not advanced threat hunting, but simply unplugging vulnerable operational technology from the public web.

Municipal Water Operators

Emphasizes the effectiveness of analog resilience and manual overrides.

For local utility managers, the narrative centers on operational continuity rather than digital defeat. While acknowledging the IT breach, operators highlight that their ability to physically walk onto the plant floor and manually turn valves prevented any actual water contamination. They argue that this analog redundancy is the ultimate failsafe against cyber threats.

Threat Intelligence Analysts

Views the campaign as opportunistic geopolitical signaling rather than advanced warfare.

Security researchers point out that the attackers did not use sophisticated zero-day exploits or custom malware. Instead, they relied on automated scanning to find low-hanging fruit—devices with default passwords. Analysts interpret this as a low-cost way for state-sponsored actors to project power and cause psychological disruption without triggering a massive retaliatory response.

Sources

Source coverage

8 outlets

3 viewpoints surfaced

Federal Cybersecurity Agencies 40%Municipal Water Operators 30%Threat Intelligence Analysts 30%
  1. [1]CBS NewsMunicipal Water Operators

    Cyberattacks on U.S. water systems highlight vulnerabilities

    Read on CBS News
  2. [2]Nextgov/FCWFederal Cybersecurity Agencies

    CISA urges water utilities to take exposed systems down after Minnesota hacks

    Read on Nextgov/FCW
  3. [3]The RecordMunicipal Water Operators

    Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents

    Read on The Record
  4. [4]Cyber MagazineThreat Intelligence Analysts

    Iran-Linked Cyberattack on US Water Systems Explained

    Read on Cyber Magazine
  5. [5]Quartz

    Iran-linked hackers suspected in wave of cyberattacks on water systems across 7 states

    Read on Quartz
  6. [6]CISAFederal Cybersecurity Agencies

    Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLC) Across US Critical Infrastructure

    Read on CISA
  7. [7]ShieldWorkzThreat Intelligence Analysts

    Campaign overview: Iranian cyber threats actively targeting U.S. critical infrastructure PLCs

    Read on ShieldWorkz
  8. [8]Industrial CyberThreat Intelligence Analysts

    LevelBlue review finds attackers exploited exposed PLCs and remote access to disrupt US water infrastructure

    Read on Industrial Cyber

Comments

Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.