Iran’s Water Utility Hacks Turn Exposed PLCs Into a National Security Problem
A wave of Iran-linked cyberattacks on U.S. water utilities across a dozen states traces back to industrial controllers that a federal warning flagged months before the first plant went offline.
For four months, the U.S. government had a warning on the books that Iranian-affiliated hackers were breaking into the industrial controllers that run American water systems. Then, on July 26 and 27, attackers hit more than 30 communities in Minnesota at once. Minnesota officials disclosed the incident on July 28, and within days the campaign had spread to a dozen states. The gap between the warning and the attack was not a failure to predict what would happen. It was a preview that arrived on schedule anyway.
Table Of Content
What Attackers Actually Reached
The devices at the center of the campaign are programmable logic controllers, or PLCs: small industrial computers that open valves, run pumps, and enforce safety limits at water and wastewater plants. The FBI’s July 30 public service announcement, alert I-073026-PSA, identified Rockwell Automation MicroLogix 1100 and 1400 series controllers as the targeted devices and said the intrusions had “degraded water operations” in at least seven states, with effects including pressure loss and flooding, according to Tenable’s summary of the alert.
The technique goes beyond simply flipping a switch. Tenable reported that attackers have been actively exploiting CVE-2021-22681, a Rockwell authentication bypass for which there is no vendor patch, only defense-in-depth workarounds. Cybersecurity Dive’s reporting on the flaw describes the mechanism: it lets an attacker discover a cryptographic key inside Rockwell’s Studio 5000 Logix Designer engineering software, then use that key to connect a non-Rockwell application directly to the controller. In a separate incident, the FBI observed a malicious project file that kept a controller’s normal, visible ladder logic intact while quietly inserting modified code modules, known as Add-On Instructions, that disabled safety shutdown and alarm systems, according to Tenable’s account of the federal findings. Attackers also altered what operator display screens showed, letting equipment run in unsafe conditions without alerting anyone watching the panel. Separately, hackers used the open-source Dropbear SSH tool to gain remote access to at least one targeted system, per Cybersecurity Dive.
A Warning That Arrived Four Months Early
CISA, the FBI, and partner agencies first published joint advisory AA26-097A on April 7, 2026, warning that Iranian-affiliated actors were exploiting internet-exposed Rockwell Automation and Allen-Bradley PLCs across U.S. critical infrastructure. On July 22, four days before the Minnesota attacks began, the agencies updated that advisory, according to WaterISAC’s summary of the notice. The update expanded the list of targeted equipment to Schneider Electric BMX P34/Modicon M340 and Siemens S7-1200 series controllers, documented for the first time that attackers were exfiltrating PLC project files to systems under their control, and added detection guidance for exactly the kind of hidden Add-On Instruction tampering the FBI later found in the field. The agencies’ central recommendation was blunt: remove PLCs from direct internet exposure behind a secure gateway and firewall, isolate cellular modem architecture, change default device passwords, and validate project files before letting a device run.
The Damage Across a Dozen States
In Minnesota, the town of Braham, population roughly 1,700, took its water plant offline for a few hours and asked residents to conserve water, TechCrunch reported. Maple Plain briefly declared a local state of emergency. Tenable’s tracking adds that the disabled controls and pressure loss across those Minnesota communities led to temporary shutdowns and manual operations, with no confirmed impact to drinking water quality and service restored within hours.
Michigan’s Department of Environment, Great Lakes, and Energy confirmed on August 1 that nine municipal water systems reported activity consistent with the federal warnings. In Georgia, the Clayton County Water Authority saw a pressure drop that triggered a boil-water advisory for its 300,000 customers in the Atlanta area before service was restored within hours, and Columbus Water Works separately confirmed a cyber intrusion on August 5 that did not affect drinking water, according to Tenable’s tracking of local reporting. New Jersey and South Dakota have also been identified as affected states, though the specific utilities involved have not been made public.
The exposure that made all of this possible is not new or hidden. Forescout reported finding more than 2,800 water-system controllers reachable directly from the public internet, TechCrunch noted, and a separate EPA investigation cited by Cybersecurity Dive found hundreds of U.S. sites carrying critical and high-severity vulnerabilities.
An Attack Without an Official Name
No federal agency has formally attributed the water utility attacks to a specific actor. Tenable’s own tracking is explicit on this point: attribution remains pending a federal investigation, though the timing lines up closely with the Iranian-affiliated PLC exploitation activity documented in advisory AA26-097A. TechCrunch reported that the Washington Post, citing U.S. intelligence agencies, said officials are “confident” that Iran, and specifically the Islamic Revolutionary Guard Corps, is responsible, but that the finding has not been made public because investigators are still working out which IRGC unit was involved, and because some officials may be reluctant to contradict President Trump, who said he did not think “there was an Iranian cyberattack” and instead blamed the state of Minnesota, led by Democratic Gov. Tim Walz, Kamala Harris’s 2024 running mate. WaterISAC’s own advisory summary notes that the updated CISA guidance builds on previously documented activity by CyberAv3ngers, a group operating under Iran’s IRGC Cyber-Electronic Command. The U.S. Treasury sanctioned six of the command’s officials in February 2024, and the State Department’s Rewards for Justice program is separately offering up to $10 million for information on a persona linked to the group, according to Tenable’s profile of it. CyberAv3ngers has escalated over several years, per that profile: from exploiting default credentials on Israeli-made PLCs in 2023, to deploying a custom ICS malware platform called IOCONTROL in 2024, to the CVE-2021-22681 exploitation seen this year.
A different, Iran-linked group has also been active against the water sector, and it is worth keeping the two separate. TechCrunch reported that a hacktivist group called Handala, which the U.S. government has tied to Iran’s Ministry of Intelligence and Security, disrupted operations at medical technology company Stryker in March and claimed responsibility for hacking the personal Gmail account of FBI Director Kash Patel. Cybersecurity Dive reported that Handala also claimed credit in June for an incident at California Water Service, one of the country’s largest water systems; Cal Water said its investigation found the activity limited to a customer’s stolen login credentials on two third-party service-provider platforms, with no impact to its internal IT or operational technology. That is a materially smaller and different kind of intrusion than PLC exploitation, but it points to the same underlying pattern.
Why Small Utilities Keep Losing This Fight
The United States has more than 150,000 water systems, many run by small municipal staffs with no dedicated security team. Tenable’s research points to a structural reason these operators keep getting hit: many manage their industrial equipment with consumer-grade remote access tools such as TeamViewer or AnyDesk, or expose PLC management interfaces directly to the public internet, bypassing enterprise security controls entirely. A 2024 CISA assessment found more than 70 percent non-compliance with existing safety requirements at U.S. water utilities, and Tenable estimates more than 60 hacktivist groups have since copied CyberAv3ngers’ playbook against similar targets.
“Once an attacker has a credential, compromises a workstation, or enters through a service provider, the question becomes whether they have a viable path to the controllers, engineering systems, and other operational crown jewels,” Frenos co-founder and CTO Harry Thomas told Cybersecurity Dive. For a rural water authority weighing a control-system upgrade against a state-mandated compliance deadline, that path has stayed open for years at a time, not because anyone missed the warnings, but because closing it costs money and expertise that a lot of these systems do not have.
No drinking water contamination has been confirmed in the incidents where outcomes have been publicly reported, including Minnesota and Georgia. TechCrunch’s reporting suggests that may be beside the point: the disruption itself, and the national coverage it drew, may be closer to what the attackers were after than any specific act of sabotage. A federal advisory named the technique and the sector four months before the first plant went offline. The utilities it was written for still could not act on it in time.
Sources: TechCrunch’s What we know about the alleged Iranian hacks on US water utilities, Cybersecurity Dive’s CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy, WaterISAC’s CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A), and Tenable’s Minnesota water utilities FAQ and CyberAv3ngers profile.
Featured image: Elk River, Minnesota water tower photograph by Kayden Harris, released under CC BY-SA 4.0 via Wikimedia Commons; cropped, resized, and converted to WebP. Elk River was not among the communities named in reporting on the attacks; the image is used to represent the type of municipal water infrastructure targeted.








No Comment! Be the first one.