All stories
Security

CISA Confirms Over 100 US Water Systems Targeted in Iranian Cyberattacks

Federal cybersecurity agency CISA has confirmed that over 100 U.S. water systems were hit by malicious cyber activity in July 2026, primarily linked to Iranian threat actors, exposing critical infrastructure vulnerabilities and raising national security alarms.

By TECH NEWS Editorial·Source:TechCrunch·4 min read·33m ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
CISA Confirms Over 100 US Water Systems Targeted in Iranian Cyberattacks

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that over 100 internet-exposed U.S. water systems were targeted by malicious cyber activity in July 2026, primarily through programmable logic controllers (PLCs) connected directly to cellular modems. This wave of attacks, strongly linked to Iranian threat actors, marks a significant escalation in the ongoing cyber conflict against critical U.S. infrastructure. While the attacks generally caused limited disruption, they underscore profound vulnerabilities within the nation's fragmented water and wastewater systems, raising alarms about public health and national security.

The core of these attacks centered on compromising operational technology (OT) systems, specifically PLCs and human-machine interfaces (HMIs), which are essential for monitoring and controlling water treatment processes like pumps, valves, and chemical dosing. CISA observed threat actors exploiting insecure configurations, such as exposed PLCs and cellular modems, often coupled with weak or default passwords. In several instances, attackers changed IP addresses and modified passwords, locking out legitimate operators and forcing facilities to switch to manual operations. States like Minnesota, Michigan, Georgia, New Jersey, and South Dakota were among at least 12 impacted, with Minnesota alone reporting over 30 community water systems targeted between July 26-27. The most severe reported incident occurred in Georgia, where attackers shut down a pump station, causing a drop in water pressure and increasing the risk of contamination, leading to a precautionary boil water advisory.

This situation matters immensely because it exposes a critical nexus of national security, public health, and economic stability. Water systems are foundational to daily life, supporting everything from drinking water supply and food production to microchip manufacturing and data center cooling. The direct targeting of OT systems, rather than just IT networks, represents a shift from data theft or ransomware to potential physical disruption, carrying far more severe consequences. Although most attacks in July resulted in "low" to "medium-low" grade disruptions, according to a CSIS report, the intent to disrupt physical operations is clear. The average cost of a cyberattack on water utilities already exceeds $4.4 million per incident, and the long-term financial implications of bolstering defenses and managing public trust are substantial. Furthermore, the attacks highlight the vulnerability of smaller, often under-resourced utilities, which comprise the vast majority of the over 150,000 separate water systems across the U.S.. These smaller entities frequently lack the specialized staff and financial capital to implement robust cybersecurity measures, making them attractive, "low-hanging fruit" targets for adversaries.

The current wave of attacks is not an isolated phenomenon but rather an escalation in a long-running campaign, with Iranian-linked actors, including the group CyberAv3ngers (backed by the Islamic Revolutionary Guard Corps), having targeted U.S. and Israeli water systems since at least 2023. Previous incidents include the 2013 attack on the Bowman Avenue Dam in New York, where an Iranian hacker accessed control systems, and attacks in Pennsylvania in 2023. What distinguishes the July 2026 incidents is their scale and coordination, simultaneously hitting numerous targets across multiple states, rather than just a handful. The use of readily available vulnerabilities in common industrial control systems like Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs, some with legacy authentication bypass flaws (e.g., CVE-2021-22681 for Rockwell Automation), indicates a broad, opportunistic scanning approach rather than zero-day exploitation. This contrasts with more sophisticated, custom malware attacks, yet proves effective due to widespread insecure configurations. Even a March 2024 EPA and White House report noted that 70% of inspected utilities failed to meet necessary cybersecurity standards, a stark comparison to the more robust, centralized cybersecurity frameworks seen in some other critical infrastructure sectors or nations.

Looking ahead, the imperative for a comprehensive and aggressive cybersecurity posture in the water sector cannot be overstated. CISA, the FBI, and EPA have issued joint advisories urging utilities to disconnect publicly exposed PLCs, implement strong, unique passwords, enforce multi-factor authentication, and secure remote access through VPNs or gateways. The newly introduced "Water Cyber Shield Act" by Senators Amy Klobuchar and Adam Schiff on August 13, 2026, aims to expand federal oversight, mandate risk assessments for larger systems, establish tiered cybersecurity standards, and allocate an additional $600 million annually through existing revolving funds for cybersecurity improvements. Such legislative action is crucial, but its effectiveness will hinge on consistent implementation, particularly for smaller utilities that struggle with funding and expertise. Experts warn that without proactive defense and investment in structural systems, the U.S. remains vulnerable to more catastrophic impacts, including potential contamination or widespread service outages. The shift towards AI-enabled hacking, noted in an August 19 joint warning from CISA, FBI, NSA, DOE, and EPA, further complicates the threat landscape, demanding advanced threat detection and predictive capabilities. The current attacks serve as a potent warning: the "fear factor" aimed at by adversaries could easily translate into real-world harm if fundamental cybersecurity gaps are not urgently and comprehensively addressed.

Sources