America's water supply has become a front line in modern cyberwarfare — and the attackers don't need sophisticated malware to cause real harm. Over the past several years, Iran-affiliated hackers have repeatedly demonstrated that basic security failures in water and wastewater utilities can be exploited with alarming ease, with consequences that ripple from flooded pump stations to boil-water advisories affecting thousands of residents. For critical infrastructure security teams, these incidents are not just news headlines — they are a detailed playbook of exactly where your defenses may be failing right now.

Here's what happened, how the attacks worked, and — most importantly — what your team must do about it today.


The Threat Is Real, Ongoing, and Escalating

Between April and August 2026, multiple U.S. municipal water and wastewater systems experienced coordinated cyberattacks attributed to Iranian-affiliated threat actors, according to joint advisories from the EPA, FBI, CISA, and NSA.

The initial signs of the most recent attack wave emerged between July 26 and 27, 2026, when authorities in Minnesota reported that hackers targeted about 30 water systems in their state.

The crisis quickly spread.

Water system cyberattacks linked to Iran spread to 12 states, forcing boil-water notices and manual operations.

This is not an isolated event.

CyberAv3ngers, widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), conducted its first sustained campaign in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them with anti-Israel messages.

The group has since escalated from exploiting default credentials on Israeli-made PLCs in 2023 to deploying a custom ICS malware platform called IOCONTROL in 2024.

Per federal advisory, the Iranian-backed hackers were "conducting this activity to cause disruptive effects within the United States," likely in response to the ongoing geopolitical conflict.

The message for security teams is clear: these actors are motivated, persistent, and growing in sophistication.


How the Attacks Actually Worked

Understanding the attack methodology is essential for defenders. The good news — and the sobering part — is that these were not zero-day exploits or nation-state-level wizardry.

The common thread is exposure, not sophistication. The controllers were reachable from the public internet, often with default or weak passwords, and in some cases through undocumented cellular modems added by vendors or integrators. Once a controller answers on the open internet, anyone who finds it can send it commands. No malware or zero-day was needed.

Once attackers gained access, the impact was immediate and operational.

After gaining access to PLCs, the threat actors remotely modified the passwords and disconnected them by changing their IP addresses to lock out operators.

In more advanced intrusions,

attackers modified or deleted project-file logic, manipulated human machine interface (HMI) and supervisory control and data acquisition (SCADA) display data, and disabled critical shutdown and alarm logic, creating unsafe conditions without notifying operators.

According to the FBI, hackers broke into one critical infrastructure provider and changed the controllers' programming logic to disable processes that handled critical shutdowns and alarms, allowing "systems to enter unsafe conditions without notifying operators of the anomalies."

The FBI reported operational effects including loss of pressure and flooding, and warned that pressure loss could potentially allow untreated groundwater to seep into pipes.

That is a public health emergency waiting to happen.


Why Water Utilities Are So Vulnerable

The scale of the vulnerability problem in the U.S. water sector is staggering — and largely structural.

The water sector is governed by the America's Water Infrastructure Act of 2018, which requires utilities to conduct risk assessments and develop emergency response plans — but a March 2024 EPA enforcement alert found that 70% of water systems inspected since 2023 were in violation even of that modest requirement.

A 2024 EPA Inspector General report found critical or high-severity vulnerabilities at 97 systems collectively serving approximately 26.6 million people.

The regulatory gap compared to other sectors is glaring.

Electric utilities operating the bulk power system are subject to mandatory NERC CIP cybersecurity standards enforced by FERC. Water utilities have no equivalent.

Many water utilities still rely on legacy PLCs and remote access methods that are vulnerable to cyberattacks. Smaller utilities often lack dedicated cybersecurity expertise and depend on third-party support, increasing their exposure to cyber threats, especially via publicly accessible cellular networks.

The problem is compounded by inadequate network segmentation between IT and OT environments. When a PLC is reachable from the same network as email servers and employee workstations, the blast radius of any compromise extends well beyond the initial point of entry.

Even internet-wide scanning is now revealing the scale of the problem.

Roughly 70 percent of U.S. water-connected OT assets are connected via cellular networks

— a significant and often unmonitored attack surface.

The bulletin from CISA notes that exposed operational technology may include undocumented cellular modems installed by operators, vendors, or system integrators.


Water utility security teams also face a fast-changing compliance landscape that adds urgency to every remediation action.

Under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), covered entities in critical infrastructure sectors — including water and wastewater systems — will be required to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours once final implementing regulations take effect, expected in September 2026.

A coalition of OT security organizations is calling for immediate action to strengthen the nation's critical infrastructure, asking Congress and CISA to enact key reforms following the coordinated attacks against U.S. water infrastructure sites.

The bottom line: non-compliance is no longer just an operational risk — it's a legal and financial one, too.


Key Lessons for Critical Infrastructure Security Teams

The Iranian water utility attacks offer hard-won lessons that apply to any operational technology environment. Here are the most important strategic takeaways:

1. Internet Exposure of OT Devices Is Indefensible

CISA's acting director confirmed that the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) at water utilities," urging "critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible."

If your PLC is internet-facing, it is a target — today.

2. Default Credentials Are an Open Door

Actors affiliated with Iran's Islamic Revolutionary Guard Corps used a similar playbook across multiple water and wastewater facilities by exploiting internet-connected controllers that retained their default passwords.

This is entirely preventable.

3. Segmentation Saves Systems

Utilities should implement network segmentation to isolate OT systems from IT networks and the internet.

A flat network that allows your SCADA system and your HR email to coexist on the same subnet is a ticking clock, not a network.

4. Backups Are Your Last Line of Defence

Once PLCs are disconnected from the public internet, operators should ensure a known-clean backup of the PLC image exists in case operators are locked out by a modified password. Utilities should make sure they maintain a backup copy in a secure location — the integrator should not be the only one with a copy of PLC code and backups.


Practical Tips Your Team Can Act On Right Now

Don't wait for the next advisory or the next incident.

As CISA has made clear: "These threat actors are targeting water entities of all sizes."

Here are the most impactful steps your team can take immediately:

Water and wastewater utilities should immediately verify whether any controller, cellular gateway, or remote-access endpoint is reachable from the public internet — starting with port 44818 (EtherNet/IP) and Modbus TCP — and remove any direct exposure found.

Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable.

Every device. Every credential. No exceptions.

The FBI, EPA, and CISA recommend routing remote access through virtual private networks (VPNs) or gateways.

Direct PLC access from the internet must be eliminated.

Inventory remote-access paths, including cellular modems and integrator connections you did not install yourself.

You cannot protect what you cannot see.

Confirm IT and OT are segmented so a phishing hit on the office network cannot reach the process network.

Enable and back up logging so you can prove what happened and restore known-good device settings after tampering.

Organizations should review the TTPs and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed to reduce the risk of compromise.


Conclusion: The Time to Harden Is Now

As the EPA's Jeffrey Hall has stated, "Cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience. A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust."

These are not abstract risks — they are proven outcomes already observed across more than a dozen U.S. states.

The Iranian campaign targeting U.S. water utilities is a masterclass in exploiting systemic neglect. The attacks succeeded not because adversaries had extraordinary capabilities, but because too many utilities had extraordinary vulnerabilities — exposed PLCs, unchanged default passwords, and no segmentation between corporate IT and critical OT systems. Every one of those failures is fixable.

If your team is responsible for critical infrastructure security, the actionable steps above are your starting point. Review your internet-facing OT exposure, rotate every default credential, enforce MFA, segment your networks, and back up your PLC configurations today. Then connect with CISA's free technical assistance programs, report suspicious activity through the proper channels, and build the muscle memory of regular OT-specific incident response drills. The next target could be your utility — and the time to be ready is long before the hackers arrive.