Multistate Water System Attacks Widen, Iran Suspected

Cyberattacks on US Water Systems Widen, with Iran Suspected Behind the Threats

A growing number of states across the US have fallen victim to a wave of cyberattacks targeting their water and wastewater systems. The attacks, which have been linked to Iranian threat actors, have exposed weaknesses in the country’s critical infrastructure, leaving experts warning that the situation is “dangerously exposed.” At least a dozen states have confirmed incidents, with some experiencing disruptions to their services.

The attacks appear to be exploiting vulnerabilities in industrial controllers, specifically programmable logic controllers (PLCs), which are used to manage and control water treatment processes. According to the Cybersecurity and Infrastructure Security Agency (CISA), threat actors are modifying PLC passwords to lock out operators and disconnecting them by changing their IP addresses. This not only disrupts operations but also prevents emergency responders from accessing critical systems.

While there have been no reports of permanent damage or extortion, some attacks have caused disruptions to water services. In Minnesota, for example, cyberattackers targeted operational technology (OT) systems for over 30 water systems, forcing operators to use manual workarounds. Similarly, in Georgia, a water pressure drop was reported after a suspected Iranian threat actor launched an attack on the Clayton County water system, prompting a boil water advisory.

Experts point out that PLCs were historically designed with physical isolation and reliability in mind, rather than security features like multifactor authentication or encrypted communication. Many are also exposed to the internet due to the need for remote troubleshooting, which often goes unnoticed by central IT/OT teams.

“This is compounded by maintenance done by non-IT staff,” says John Gallagher, vice president at OT and IoT security firm Viakoo. “Field technicians and third-party integrators frequently install cellular modems or direct port forwards without notifying central teams.”

Markus Mueller, field CISO at Nozomi Networks, adds that the water industry’s decentralized nature and limited cyber awareness and capabilities make it an attractive target for threat actors.

“It is unfortunate,” he says, “as there are plenty of good people in the water industry who work hard to deliver clear, reliable services. But when you consider the sheer number of systems – 170,000 drinking water and wastewater systems – it’s no wonder they’re struggling to keep pace with security demands.”

The situation highlights the need for immediate action from critical infrastructure owners and operators to remove publicly exposed PLCs and other OT from the internet. As Mueller notes, “it is not a matter of if but when” another attack occurs.

Practical advice for readers includes:

* Ensure that all industrial controllers and OT systems are properly secured with multifactor authentication and encrypted communication.

* Regularly review and update maintenance procedures to prevent unauthorized access to critical systems.

* Invest in robust cybersecurity measures, including monitoring and incident response planning, to mitigate the risk of a successful attack.

By taking these steps, water system operators can help prevent further disruptions and ensure that their services remain reliable and secure.


Source: Dark Reading — 2026-08-10