# Iran's Water Campaign Is Bigger Than Minnesota — and the Attack Vector Should Alarm Every Utility in America
Seven states. Thirty-plus facilities. One persistent intrusion vector that the ICS security community has been warning about for years.
What started as a Minnesota story is now a national one. The coordinated cyberattacks against US water and wastewater infrastructure that surfaced publicly last week have spread well beyond one state's utility sector — Michigan officially confirmed incidents, Rapid City in South Dakota disclosed a hit on a wastewater lift station, and Georgia is reportedly on the list too. The names of the remaining three or four affected states still haven't been made public, which is itself a problem worth sitting with.
## Cellular Routers: The Quiet Door That Keeps Getting Kicked In
Here's the detail buried in the middle of most coverage that deserves to be the lede: multiple sources indicate the Minnesota intrusions were limited to "equipment connected via cellular communications." That's not incidental. That's the attack surface.
Water utilities — particularly smaller ones serving towns and cities with limited IT staff — routinely use cellular-connected PLCs and remote terminal units to monitor lift stations, pump controls, and treatment equipment without running fiber to every remote site. It's cheap, flexible, and widely deployed. It's also an internet-exposed OT endpoint that often lacks the authentication hardening or network segmentation applied to more obvious entry points.
Iran-linked actors ran this same play against Israeli water facilities, exploiting vulnerable cellular routers to reach industrial control systems. That was 2020. Six years later, the vector hasn't been closed at scale in the United States either.
CISA put out guidance after the Minnesota attacks broke urging water operators to protect their PLCs. Days before those attacks went public, federal agencies had already updated an April advisory warning that ICS hardware from Siemens, Schneider Electric, and Rockwell Automation was being actively targeted by Iranian-linked threat actors. The sequence matters: the advisory came first, then the attacks. Either the affected utilities didn't receive the guidance, didn't have the resources to act on it, or the advisory wasn't specific enough to prompt action in time.
## What "No Operational Impact" Actually Means
Every public statement from affected municipalities has followed the same script: systems continued to operate safely, no public health concerns, drinking water remains protected. Rapid City was particularly careful to note that its wastewater infrastructure was "never placed in jeopardy."
These statements are probably true. They're also not reassuring in the way officials intend them.
The goal of these attacks — at least the ones we know about — doesn't appear to have been to contaminate water supplies or cause a blackout-style disruption. The more likely objectives are reconnaissance, persistence, and demonstrating reach. An adversary that can touch 30-plus facilities across seven states in a 48-hour window has already accomplished something significant, regardless of whether a single valve turned.
Consider what's been established: Iran-linked actors have mapped US water infrastructure, identified cellular-connected OT endpoints at scale, and demonstrated the ability to conduct coordinated multi-state operations against critical infrastructure. If the intent was disruption rather than reconnaissance, they had the access to try. That they didn't — at least not visibly — is cold comfort when the same access could be re-used, escalated, or handed off to a more aggressive actor.
## The Intelligence Leak Problem
WaterISAC, the sector's information-sharing organization, produced a report linking the Minnesota attacks to Iran-aligned campaigns — and marked it TLP:Amber, meaning it was not for public release. Wired obtained a copy. The report is now effectively public.
This is a recurring tension in critical infrastructure cybersecurity: sector-specific ISACs produce actionable threat intelligence, but the classification level means the utilities most in need of it — smaller operators without dedicated security staff or existing relationships with federal agencies — never see it in time to act. The facilities that get the TLP:Amber reports are often the ones already hardened enough not to need them urgently.
The water sector is also uniquely fragmented. There are roughly 50,000 community water systems in the United States. Most serve populations under 10,000 people. Many have one or two IT staff, if any. The attack surface is enormous and the defensive baseline is uneven in ways that don't exist in sectors like financial services or energy.
## HackWire Analysis
This campaign deserves more scrutiny than it's getting as a "no harm done" story.
The cellular router vector connects this directly to documented Iranian ICS tradecraft going back to 2020, when Cyber Av3ngers (later sanctioned by the US Treasury) hit Israeli water infrastructure. The same group, or actors using their playbook, appeared in the 2023 Pennsylvania water facility breach that briefly made headlines before fading from coverage. Now, in 2026, the same vector is back — broader in scope, apparently more coordinated, and still exploiting infrastructure exposure that CISA has flagged repeatedly.
The pattern here isn't "Iran found a new trick." The pattern is that the water sector's cellular OT exposure has never been systematically addressed because the sector lacks both the regulatory pressure and the financial resources to remediate it at scale. EPA's attempts to mandate cybersecurity assessments for water utilities were struck down in court in 2023. What replaced them was voluntary guidance. Voluntary guidance does not close cellular-exposed PLCs.
What other coverage is missing: the Censys angle. Internet exposure scanning consistently finds thousands of water-sector OT devices reachable from the public internet — many of them the same Siemens, Schneider, and Rockwell hardware named in the updated federal advisory. The attack campaign against seven states may be less about sophisticated intrusion and more about the adversary running a query and knocking on open doors.
For defenders — particularly smaller utilities — the immediate action isn't complex: audit every cellular-connected OT endpoint, verify that remote access requires multi-factor authentication, and check whether those endpoints appear in Censys or Shodan. If they do, assume they've been seen.
The structural fix requires policy that has so far been politically impossible to mandate. Until then, count on more of these incidents.
— HackWire Editorial
## Related Coverage