# Iran Is Turning America's Water Systems Into a Nervous System — And We Let Them
Twelve states. Thirty-plus water utilities. Attackers who didn't need sophisticated malware, zero-days, or insider access. They needed an internet connection and a Shodan search.
The multistate campaign hitting US water and wastewater infrastructure isn't a story about a novel threat actor technique. It's a story about infrastructure that was never designed to be connected to the internet, connected to the internet anyway, and left there for years while operators assumed obscurity was the same as security.
## The Attack Is Embarrassingly Simple
The mechanics bear repeating because they're damning. Threat actors — linked with varying confidence to the Iranian government, per updated FBI and CISA advisories — are targeting programmable logic controllers (PLCs) made by Rockwell Automation/Allen Bradley, Schneider Electric, and Siemens. The playbook is two moves: change the PLC password to lock out the legitimate operator, then shift the IP address to cut off remote access entirely.
That's it. No custom implants. No living-off-the-land tradecraft. No supply chain compromise. The attackers are walking through an unlocked door and changing the locks from inside.
Minnesota confirmed attacks on more than 30 water systems late last month. By early August, the scope had widened to Georgia, Michigan, South Dakota, Alabama, and New Jersey — with more likely to surface as utilities complete their reporting obligations. CISA updated its advisory on July 30, explicitly warning of "a significant increase in cyber-threat actors targeting PLCs in the Water and Wastewater Systems sector" and telling operators to remove internet-exposed PLCs "as soon as possible."
That CISA is still telling utilities to do this in 2026 is its own editorial comment.
## Disruption Is the Point, Even Without Damage
No taps have gone dry. No contaminant has entered a distribution system. Officials have been careful to note this, and they're right to — but framing the absence of physical harm as a near-miss misses what's actually happening.
These attacks are designed to demonstrate reach, not cause casualties. The Iranian government — if attribution holds — doesn't need to poison a reservoir to make its point. It needs to prove that twelve US states' worth of water operators can be locked out of their own systems on a Tuesday afternoon by actors using publicly available scanning tools. That demonstration has value independent of any physical outcome.
This is psychological operations dressed as a cyberattack campaign. The message to US policymakers, infrastructure operators, and the public is: *we're in your systems, we can come back, and your water is more fragile than you think.*
The strategic calculation isn't that different from Russian information operations — create uncertainty and anxiety without triggering the proportional response that actual physical infrastructure destruction would invite. It's coercion on the cheap.
## A Known Problem That Never Got Fixed
The uncomfortable part of this story isn't Iran. It's that we've known about exposed industrial controllers in water systems for over a decade.
The 2021 Oldsmar, Florida incident — where an attacker briefly increased sodium hydroxide levels to 111 times the normal amount via remote access to a water treatment plant's SCADA system — should have been the alarm that changed operator behavior nationwide. The attack vector was a remote desktop application left accessible without multi-factor authentication. Basic. The water system had a secondary safety mechanism that would have caught the change before it reached consumers, but that near-miss should have triggered systematic audits of internet-exposed OT across the sector.
It didn't. Or at least, not at the scale needed.
CISA has been issuing advisories about water sector OT security since at least 2021. The FBI's April 2026 warning — updated in July specifically because the threat escalated — describes the same Rockwell, Schneider, and Siemens PLC attack surface the security community has flagged repeatedly. The sector is fragmented, underfunded, and operated by municipalities that often have one IT person splitting their time between water treatment software and the mayor's email.
That's not an excuse. It's a structural vulnerability that adversaries have mapped and are now exploiting at scale.
## What Defenders Actually Need to Do
The CISA guidance — remove internet-exposed PLCs — is correct but incomplete as a practical matter. Most small utilities can't simply air-gap their OT overnight. They use remote access for legitimate operational reasons, often because they don't have enough staff to have someone on-site around the clock.
The realistic defensive posture for water system operators right now:
Inventory first. You cannot protect what you cannot see. Run a scan of your external attack surface — what's listening on the internet from your OT network. Tools like Shodan will show you what attackers already know about you.
Segment aggressively. PLCs should not be reachable from the public internet under any circumstances. If remote access is genuinely necessary, it should route through a VPN with multi-factor authentication, not direct exposure.
Change default credentials. This remains one of the most common attack vectors across OT environments globally. It should not still be on the checklist, but it is.
Log PLC configuration changes. The attack described here — password and IP changes — should trigger immediate alerts. If you don't have visibility into configuration changes on your PLCs, you will not detect this intrusion until operators are already locked out.
Contact CISA. Seriously. The agency has free resources, assessment services, and incident response assistance for critical infrastructure operators. Most small water utilities don't use them.
## The Federal Gap
One thing missing from most coverage of this campaign: the regulatory gap that allows this exposure to persist. Water systems with fewer than 10,000 customers — which covers the majority of US utilities — face almost no federal cybersecurity requirements. The America's Water Infrastructure Act of 2018 required risk and resilience assessments, but the enforcement teeth are limited and assessments don't mandate remediation timelines.
The EPA has attempted to extend cybersecurity requirements to smaller utilities and faced legal challenges from states arguing federal overreach. The result is a sector where the smallest and most resource-constrained operators — who are also the most likely to have misconfigured, internet-exposed industrial controllers — are the least subject to federal security standards.
Iran didn't create that gap. But they found it, and they're walking through it state by state.
---
## HackWire Analysis
The water sector attacks deserve comparison to two earlier campaigns that should be informing current defensive strategy but largely aren't.
First, the 2020–2021 water sector targeting surge: in the months after Oldsmar, CISA documented multiple incidents targeting water treatment plants, including attempts via remote access to SCADA systems. The response was a flurry of advisories and a modest uptick in sector attention — followed by a return to baseline inertia. We are watching that cycle repeat.
Second, the Volt Typhoon pre-positioning campaign against US critical infrastructure — power, water, transportation — which CISA confirmed in early 2024. Volt Typhoon's approach was patient and stealthy; these Iranian-linked actors are doing the opposite, making noise on purpose. The contrast is instructive. China appeared to be pre-positioning for potential conflict scenarios. Iran appears to be conducting influence operations now, in the present, with coercive intent. The difference matters for how defenders should think about threat modeling: this isn't sleeper-agent infrastructure access, it's active signaling.
What's missing from current coverage is honest engagement with the remediation timeline problem. Even if every small water utility in America started hardening their OT tomorrow, meaningful change takes years — funding cycles, procurement, operational continuity requirements. The attackers know this. The current campaign may be calibrated specifically to the window before any serious federal security mandate could realistically take effect. The pressure is real, the timeline is short, and the sector's structural underfunding means that CISA advisories, however correct, are not the same as a solved problem.
The other missing angle: ISAC participation rates in the water sector are among the lowest of any critical infrastructure sector. The Water Information Sharing and Analysis Center (WaterISAC) exists and publishes threat intelligence — but most small utilities aren't members. That's an immediate, low-cost gap to close.
— HackWire Editorial
---
## Related Coverage