Cyberattacks on US Water Systems Continue to Spread, with Iran Suspected as Culprit
A wave of cyberattacks targeting water and wastewater systems has been sweeping across the United States, leaving a trail of vulnerable industrial controllers in its wake. At least a dozen states have reported attacks, with the latest victims including Alabama and New Jersey communities that have confirmed they too are under attack.
The intrusions, which appear to be linked to Iranian threat actors, exploit low-complexity attacks against programmable logic controllers (PLCs). These PLCs control critical infrastructure such as pumps, valves, and treatment plants, making them a prime target for hackers. The attackers modify PLC passwords to lock out operators, disconnecting the devices by changing their IP addresses.
In recent weeks, water and wastewater organizations in Minnesota, Georgia, Michigan, and South Dakota have disclosed cyberattacks against their systems. While there have been no disruptions to the water supply so far, some of these attacks have caused significant disruption to operations. In Minnesota, for example, hackers locked operators out of PLCs, forcing them to use manual workarounds.
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are targeting PLCs in critical infrastructure manufactured by Rockwell Automation/Allen Bradley, Schneider Electric, Siemens, and possibly other vendors. CISA urges critical infrastructure owners to remove publicly exposed PLCs from the internet as soon as possible.
Experts say the attacks highlight a broader issue with the water industry’s reliance on outdated technology. “Industrial controllers like PLCs were historically engineered for physical isolation and reliability rather than Internet exposure,” explains John Gallagher, vice president at OT and IoT security firm Viakoo. “Many lack basic secure-by-design capabilities like multifactor authentication or encrypted communication.”
The attacks also expose a critical vulnerability in the water industry’s operations. Most water and wastewater systems are small, decentralized, and running outdated technology that was installed by third-party vendors. This has led to a lack of funding, mandate, or awareness to keep these devices secure.
In one case, hackers targeted Clayton County, Georgia, causing a water pressure drop and forcing the agency to issue a boil water advisory. Mark Mueller, field CISO at Nozomi Networks, warns that this is just the tip of the iceberg: “There are roughly 170,000 drinking water and wastewater systems in the US, and most lack the resources or expertise to secure their industrial controllers.”
The attacks on US water systems serve as a stark reminder of the dangers of neglecting cybersecurity. As Gallagher notes, “Cyber awareness and capabilities are limited at these utilities.” To prevent further disruptions, it’s essential for water and wastewater organizations to prioritize security and take immediate action to protect their critical infrastructure.
In practical terms, this means taking steps such as removing publicly exposed PLCs from the internet, implementing multifactor authentication, and encrypting communication. It also requires a shift in mindset, with operators recognizing that cybersecurity is no longer an afterthought but a vital component of maintaining reliable water services.
Source: Dark Reading — 2026-08-10