All incidents

Iran-linked hackers target US water facilities across multiple states

incidentopenAug 3, 2026 — Aug 10, 2026
FBI warns as Iranian hackers hit US water plants in 12 states

FBI has issued a warning after Iranian hackers targeted water and wastewater facilities in at least twelve U.S. states, with the campaign beginning in late July. The agency said the intrusions focused on operational technology gear and prompted alerts from multiple state regulators. SecurityWeek has reported that the targeting extended beyond the initial Midwest cluster to include states on the East Coast and the South. Officials stressed that while the actors sought to manipulate process controls, no contamination of drinking water has been confirmed.

SecurityWeek reporting notes that New Jersey and Alabama have recently confirmed infections, joining earlier reports from Minnesota, Michigan, South Dakota and Georgia according to a recent piece. The attacks primarily hit devices made by Rockwell Automation that were reachable over cellular links, though no common vulnerability identifier has been published for the flaw. Investigators observed that the malicious code attempted to reprogram programmable logic controllers to alter pump speeds and valve positions. Despite these attempts, safety interlocks and manual overrides kept the treated water within acceptable parameters.

Despite the intrusions, operators have said that drinking water supplies remained safe and any service interruptions were minor. Minnesota was the first state to go public, describing compromise of more than thirty water and wastewater plants before the wave spread to other regions. Michigan and South Dakota followed with disclosures of hit facilities ranging from small rural wells to larger municipal treatment works. Georgia’s utilities reported probing activity on their supervisory control and data acquisition servers but reported no successful manipulation of chemical dosing.

The Federal Bureau of Investigation attributes the activity to Iranian state‑sponsored actors, while CISA has urged utilities to review their remote access configurations and harden OT networks as outlined in another report. Although the U.S. government has stopped short of a formal indictment, investigators say the tactics, techniques and procedures match those seen in previous Iranian campaigns against critical infrastructure. The advisory highlights that many of the compromised units were exposed directly to the internet via cellular modems with weak or default passwords. Agencies recommend that owners treat these edge devices as trusted assets and apply the same rigour used for corporate firewalls.

Defenders should start by separating operational technology from corporate IT, enforcing strict multi‑factor authentication on any remote management portals and monitoring for unusual protocol traffic on cellular modems. Applying the latest firmware from Rockwell Automation and checking for default credentials can also reduce the attack surface, and utilities are encouraged to share indicators of compromise with the Water Information Sharing and Analysis Center.

Network segmentation should be reinforced with unidirectional gateways where feasible, preventing lateral movement from an infected IT system to the process control layer. Regular red‑team assessments that focus on OT-specific attack paths are advised to validate the effectiveness of these controls.

Finally, organisations are advised to revisit incident response plans, tabletop exercises that simulate a loss of OT control and ensure that backup communication channels remain available if primary links are disrupted. Staying vigilant and reporting any anomalous behaviour to the FBI’s Internet Crime Complaint Centre will help authorities track the campaign as it evolves.

Continuous monitoring of log aggregation systems for unexpected authentication attempts or configuration changes can provide early warning of a renewed push. By combining technical hardening with timely information sharing, the water sector hopes to blunt further Iranian‑linked intrusions.

Intelligence briefing updated Aug 10, 2026

Timeline Coverage

Swipe to explore timeline