TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/Articles/Iran’s Water Utility Hacks Turn Exposed PLCs Into a National Security Problem
Articles

Iran’s Water Utility Hacks Turn Exposed PLCs Into a National Security Problem

A wave of Iran-linked cyberattacks on U.S. water utilities across a dozen states traces back to industrial controllers that a federal warning flagged months before the first plant went offline.

August 16, 2026 6 Min Read
40

For four months, the U.S. government had a warning on the books that Iranian-affiliated hackers were breaking into the industrial controllers that run American water systems. Then, on July 26 and 27, attackers hit more than 30 communities in Minnesota at once. Minnesota officials disclosed the incident on July 28, and within days the campaign had spread to a dozen states. The gap between the warning and the attack was not a failure to predict what would happen. It was a preview that arrived on schedule anyway.

Table Of Content

  • What Attackers Actually Reached
  • A Warning That Arrived Four Months Early
  • The Damage Across a Dozen States
  • An Attack Without an Official Name
  • Why Small Utilities Keep Losing This Fight

What Attackers Actually Reached

The devices at the center of the campaign are programmable logic controllers, or PLCs: small industrial computers that open valves, run pumps, and enforce safety limits at water and wastewater plants. The FBI’s July 30 public service announcement, alert I-073026-PSA, identified Rockwell Automation MicroLogix 1100 and 1400 series controllers as the targeted devices and said the intrusions had “degraded water operations” in at least seven states, with effects including pressure loss and flooding, according to Tenable’s summary of the alert.

The technique goes beyond simply flipping a switch. Tenable reported that attackers have been actively exploiting CVE-2021-22681, a Rockwell authentication bypass for which there is no vendor patch, only defense-in-depth workarounds. Cybersecurity Dive’s reporting on the flaw describes the mechanism: it lets an attacker discover a cryptographic key inside Rockwell’s Studio 5000 Logix Designer engineering software, then use that key to connect a non-Rockwell application directly to the controller. In a separate incident, the FBI observed a malicious project file that kept a controller’s normal, visible ladder logic intact while quietly inserting modified code modules, known as Add-On Instructions, that disabled safety shutdown and alarm systems, according to Tenable’s account of the federal findings. Attackers also altered what operator display screens showed, letting equipment run in unsafe conditions without alerting anyone watching the panel. Separately, hackers used the open-source Dropbear SSH tool to gain remote access to at least one targeted system, per Cybersecurity Dive.

A Warning That Arrived Four Months Early

CISA, the FBI, and partner agencies first published joint advisory AA26-097A on April 7, 2026, warning that Iranian-affiliated actors were exploiting internet-exposed Rockwell Automation and Allen-Bradley PLCs across U.S. critical infrastructure. On July 22, four days before the Minnesota attacks began, the agencies updated that advisory, according to WaterISAC’s summary of the notice. The update expanded the list of targeted equipment to Schneider Electric BMX P34/Modicon M340 and Siemens S7-1200 series controllers, documented for the first time that attackers were exfiltrating PLC project files to systems under their control, and added detection guidance for exactly the kind of hidden Add-On Instruction tampering the FBI later found in the field. The agencies’ central recommendation was blunt: remove PLCs from direct internet exposure behind a secure gateway and firewall, isolate cellular modem architecture, change default device passwords, and validate project files before letting a device run.

The Damage Across a Dozen States

In Minnesota, the town of Braham, population roughly 1,700, took its water plant offline for a few hours and asked residents to conserve water, TechCrunch reported. Maple Plain briefly declared a local state of emergency. Tenable’s tracking adds that the disabled controls and pressure loss across those Minnesota communities led to temporary shutdowns and manual operations, with no confirmed impact to drinking water quality and service restored within hours.

Michigan’s Department of Environment, Great Lakes, and Energy confirmed on August 1 that nine municipal water systems reported activity consistent with the federal warnings. In Georgia, the Clayton County Water Authority saw a pressure drop that triggered a boil-water advisory for its 300,000 customers in the Atlanta area before service was restored within hours, and Columbus Water Works separately confirmed a cyber intrusion on August 5 that did not affect drinking water, according to Tenable’s tracking of local reporting. New Jersey and South Dakota have also been identified as affected states, though the specific utilities involved have not been made public.

The exposure that made all of this possible is not new or hidden. Forescout reported finding more than 2,800 water-system controllers reachable directly from the public internet, TechCrunch noted, and a separate EPA investigation cited by Cybersecurity Dive found hundreds of U.S. sites carrying critical and high-severity vulnerabilities.

An Attack Without an Official Name

No federal agency has formally attributed the water utility attacks to a specific actor. Tenable’s own tracking is explicit on this point: attribution remains pending a federal investigation, though the timing lines up closely with the Iranian-affiliated PLC exploitation activity documented in advisory AA26-097A. TechCrunch reported that the Washington Post, citing U.S. intelligence agencies, said officials are “confident” that Iran, and specifically the Islamic Revolutionary Guard Corps, is responsible, but that the finding has not been made public because investigators are still working out which IRGC unit was involved, and because some officials may be reluctant to contradict President Trump, who said he did not think “there was an Iranian cyberattack” and instead blamed the state of Minnesota, led by Democratic Gov. Tim Walz, Kamala Harris’s 2024 running mate. WaterISAC’s own advisory summary notes that the updated CISA guidance builds on previously documented activity by CyberAv3ngers, a group operating under Iran’s IRGC Cyber-Electronic Command. The U.S. Treasury sanctioned six of the command’s officials in February 2024, and the State Department’s Rewards for Justice program is separately offering up to $10 million for information on a persona linked to the group, according to Tenable’s profile of it. CyberAv3ngers has escalated over several years, per that profile: from exploiting default credentials on Israeli-made PLCs in 2023, to deploying a custom ICS malware platform called IOCONTROL in 2024, to the CVE-2021-22681 exploitation seen this year.

A different, Iran-linked group has also been active against the water sector, and it is worth keeping the two separate. TechCrunch reported that a hacktivist group called Handala, which the U.S. government has tied to Iran’s Ministry of Intelligence and Security, disrupted operations at medical technology company Stryker in March and claimed responsibility for hacking the personal Gmail account of FBI Director Kash Patel. Cybersecurity Dive reported that Handala also claimed credit in June for an incident at California Water Service, one of the country’s largest water systems; Cal Water said its investigation found the activity limited to a customer’s stolen login credentials on two third-party service-provider platforms, with no impact to its internal IT or operational technology. That is a materially smaller and different kind of intrusion than PLC exploitation, but it points to the same underlying pattern.

Why Small Utilities Keep Losing This Fight

The United States has more than 150,000 water systems, many run by small municipal staffs with no dedicated security team. Tenable’s research points to a structural reason these operators keep getting hit: many manage their industrial equipment with consumer-grade remote access tools such as TeamViewer or AnyDesk, or expose PLC management interfaces directly to the public internet, bypassing enterprise security controls entirely. A 2024 CISA assessment found more than 70 percent non-compliance with existing safety requirements at U.S. water utilities, and Tenable estimates more than 60 hacktivist groups have since copied CyberAv3ngers’ playbook against similar targets.

“Once an attacker has a credential, compromises a workstation, or enters through a service provider, the question becomes whether they have a viable path to the controllers, engineering systems, and other operational crown jewels,” Frenos co-founder and CTO Harry Thomas told Cybersecurity Dive. For a rural water authority weighing a control-system upgrade against a state-mandated compliance deadline, that path has stayed open for years at a time, not because anyone missed the warnings, but because closing it costs money and expertise that a lot of these systems do not have.

No drinking water contamination has been confirmed in the incidents where outcomes have been publicly reported, including Minnesota and Georgia. TechCrunch’s reporting suggests that may be beside the point: the disruption itself, and the national coverage it drew, may be closer to what the attackers were after than any specific act of sabotage. A federal advisory named the technique and the sector four months before the first plant went offline. The utilities it was written for still could not act on it in time.

Sources: TechCrunch’s What we know about the alleged Iranian hacks on US water utilities, Cybersecurity Dive’s CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy, WaterISAC’s CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A), and Tenable’s Minnesota water utilities FAQ and CyberAv3ngers profile.

Featured image: Elk River, Minnesota water tower photograph by Kayden Harris, released under CC BY-SA 4.0 via Wikimedia Commons; cropped, resized, and converted to WebP. Elk River was not among the communities named in reporting on the attacks; the image is used to represent the type of municipal water infrastructure targeted.

Tags:

CISACritical InfrastructureIranOT SecurityWater Utilities

Share

Macro photograph of a human fingertip showing fingerprint ridge patterns
Previous Post

How to Detect Duplicate and Near-Duplicate Images With Perceptual Hashing in Python

A caliper's jaws holding a brass threaded pipe plug against a plain background, checking whether it conforms to a fixed size
Next Post

How to Get Reliable Structured JSON Output From Ollama Models in Python

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026