# Iranian Hackers Are Working Through America's Water Systems, State by State


Twelve states. Dozens of water utilities. One Iranian hacking campaign that started in late July and is still expanding its known footprint. New Jersey and Alabama confirmed attacks over the weekend, joining Minnesota, Michigan, South Dakota, and Georgia on a list that keeps getting longer while federal agencies stay conspicuously quiet.


This is not a drill, and it is not yet a disaster. But the gap between those two things is narrower than water utilities have been willing to admit.


---


## The Scope Nobody Wanted to Confirm


Minnesota was the first state to acknowledge what happened: more than 30 water systems had their operational technology targeted in coordinated intrusions. That number alone should have set off alarms across the sector. It didn't — or at least, the public response didn't match the scale of what was disclosed.


Then came Michigan. South Dakota. Georgia. This past weekend, Cape May and Woodbine utilities in New Jersey confirmed they were hit on July 27, with officials characterizing the damage as limited to phone system disruptions. On the same day, the Childersburg Water, Sewer and Gas system in Alabama was attacked. Hackers reached industrial control systems but didn't manage to disrupt actual water service.


Wisconsin, Pennsylvania, and Washington have issued warnings to utilities in their states without confirming whether specific systems were compromised. New York, notably, has said nothing about whether its infrastructure was targeted — but did announce over $9 million in grants to help water utilities harden their defenses, which reads as an implicit acknowledgment that something is wrong.


The FBI confirmed at least seven affected states as of July 30. That was eleven days ago. No public update since.


---


## What the Attackers Were Actually After


The campaign targeted industrial control systems — specifically equipment from Rockwell Automation, though reporting suggests other major ICS vendors may be involved. This is a precise choice. Rockwell's PLCs and HMIs are ubiquitous in American water infrastructure, particularly at smaller utilities that haven't had the budget or mandate to upgrade their OT environments.


Targeting ICS at water facilities is different from targeting their IT networks. IT-side attacks — ransomware on billing systems, phishing that compromises email — are disruptive and expensive, but they don't touch the physical process. ICS-level access is access to the pumps, the chemical dosing systems, the pressure controls. That's where "disruption" becomes a different kind of problem entirely.


None of the confirmed attacks appear to have resulted in manipulation of water treatment processes. Officials have consistently stated drinking water is safe. But "they got in and didn't do anything catastrophic" is a curious standard for reassurance. It means they got in.


---


## The Accountability Gap


CISA has issued guidance urging the water sector to secure OT systems in light of the campaign. That's the agency doing what it's supposed to do. What's less clear is why neither CISA nor the FBI has provided a public update since July 30, when the known scope was already seven states.


The attacks have been attributed to Iranian hackers. The geopolitical context matters here: Iranian threat actors have been probing US critical infrastructure for years, but campaigns of this breadth — hitting a single critical sector across more than a dozen states in a coordinated window — mark a meaningful escalation in operational tempo. This isn't reconnaissance anymore. It's a demonstration.


Water utilities operate under weaker cybersecurity mandates than other critical infrastructure sectors. The EPA's attempt to require cybersecurity assessments as part of routine sanitary surveys was struck down in court in 2023. What's replaced it is a patchwork of guidance, voluntary frameworks, and reactive state-level action. New York's $9 million grant announcement is smart policy. It's also, at this scale and speed, analogous to buying smoke detectors during a fire.


---


## The Pattern That Should Worry Defenders


This campaign has a signature: hit multiple small-to-mid-sized utilities in a state simultaneously, targeting their OT rather than their IT. Small utilities have fewer resources, older equipment, and less visibility into what's running on their networks. They are, in the language of vulnerability research, the attack surface that scales.


The July 27 date appearing in both the New Jersey and Alabama incidents suggests coordinated execution, not opportunistic scanning. Someone planned this operation and moved on a schedule.


For defenders at water utilities — and for state emergency management offices that are probably fielding frantic calls right now — the immediate priorities aren't complicated, even if they're resource-intensive:


  • Audit internet-exposed ICS. Rockwell devices showing up on Shodan or similar platforms are low-hanging fruit for any threat actor with moderate capability.
  • Segment OT from IT networks. If a compromised phone system can reach a SCADA interface, the segmentation didn't work.
  • Enable logging on OT devices where possible and get those logs somewhere the attackers can't reach.
  • Verify water treatment process baselines. If an attacker had brief access to control systems, confirming no parameter changes occurred requires more than a visual inspection.
  • Contact CISA's water sector specialists. The agency has dedicated resources; now is the time to use them.

  • ---


    ## HackWire Analysis


    The muted federal response is the story inside the story. Between July 30 — when the FBI confirmed seven affected states — and today, at least five more states have surfaced publicly with confirmed attacks or credible warnings. That's nearly a week of silence from the agencies best positioned to provide a coherent picture of what's happening.


    This isn't the first time Iranian threat actors have targeted US water infrastructure. The 2021 Oldsmar, Florida incident — where an attacker briefly increased sodium hydroxide levels before an operator caught it — was widely cited as a wake-up call. The lesson from Oldsmar was supposed to be that OT access at water utilities is both achievable by determined adversaries and catastrophically consequential if misused. Five years later, we're watching a coordinated campaign hit a dozen states, and the primary public communication from federal agencies has been a CISA advisory and FBI silence.


    The water sector's cybersecurity problem is structural. Small utilities — the ones running aging Rockwell equipment on networks that were designed before cybersecurity was a consideration — cannot be expected to out-resource nation-state threat actors. That's not a criticism of individual utility operators; it's an observation about the funding gap between what these organizations can afford and what a determined adversary can deploy.


    What's missing from most coverage of this campaign is any reckoning with the long-term strategic intent. Iranattributed hackers gaining persistent access to ICS environments at water utilities isn't necessarily about turning off the taps today. It's about mapping the attack surface, understanding the architecture, and maintaining the capability to do something much worse under different geopolitical conditions. The attacks didn't cause significant damage. That doesn't mean the capability established during these intrusions is gone.


    The water sector needs federal investment, updated regulatory frameworks, and direct OT security assistance — not another guidance document. States shouldn't have to announce cybersecurity grants in response to active attack campaigns. This is a national infrastructure problem being managed at the county level, and the gap is showing.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)