ics-ottrade-pressNewsThe Broadside3 min read

Iran-linked water utility attacks hit 12 states

The campaign signals a shift from reconnaissance to disruption, with water utilities emerging as Iran's primary North American target.


TL;DR

Iranian state-linked cyberattacks on water utility operational technology have now hit facilities across 12 states, up from seven confirmed as of late July, according to ABC News and state officials. Georgia's Clayton County Water Authority issued a boil-water advisory after attackers disrupted a portion of its operational systems; a second Georgia utility and a South Dakota facility have also reported incidents. CISA and the FBI continue to urge utilities to remove internet-connected PLCs immediately, but for the small and medium operators most exposed, the guidance remains purely advisory; no enforcement mechanism compels compliance.

The expansion from seven to 12 states in under two weeks confirms what CISA's advisories have been telegraphing since April: Iranian-affiliated threat actors aren't just probing American water infrastructure; they're disrupting it. The operational effects now include boil-water notices in Georgia, sustained manual operations across multiple states, and FBI-confirmed reports of pressure loss and flooding that could allow untreated groundwater to seep into pipes.

The attack pattern is simple and, for utilities that haven't already acted, devastatingly effective. Threat actors locate internet-connected programmable logic controllers, the devices that open valves, run pumps, and manage chemical dosing, then change the passwords and lock out the legitimate operators. Once inside, they manipulate project files and alter what appears on HMI and SCADA displays. The utility loses both control and visibility. Fixing it means either restoring from backup or reverting to manual operations, which for many smaller systems means sending staff to physically check gauges every few hours, as Minot, North Dakota did in March following a ransomware incident at its water treatment plant (https://therecord.media/north-dakota-ransomware-water-plant).

CISA updated its advisory on July 22 to expand the manufacturer scope beyond Rockwell Automation and Allen-Bradley to include Schneider Electric and Siemens PLCs, and Acting Director Nick Andersen told The Record the agency is observing "a significant increase" in targeting. The agency's guidance is unambiguous: remove publicly exposed PLCs from the internet, deploy firewalls, use unique credentials, and restrict communication to expected control devices only. But a close read of the federal response reveals what's missing. CISA has no statutory authority to compel a small municipal water authority to do any of this. The EPA's regulatory reach over cybersecurity is contested and narrow. The FBI investigates after the fact. For the thousands of water utilities serving populations under 10,000, many run by a handful of employees with no dedicated IT staff, "as soon as possible" is an unfunded mandate with no enforcement backstop.

Why water and why now

The targeting shift is calculated. Since at least March 2026, Iranian-affiliated groups have pivoted away from the defense-industrial base and energy sectors and toward the water and wastewater sector: a target-rich, resource-poor environment where universal cybersecurity solutions are, in CISA's own analysis, "unfeasible." A single compromise can trigger cascading public health and trust effects disproportionate to the sophistication of the attack. Jake Braun, a former Biden administration cyber official who now connects volunteer experts with water utilities, noted that civilian water systems support military installations and underpin the data centers driving AI infrastructure. When disrupted, he said, they also erode public confidence in government's ability to deliver basic services.

The Iranian groups are targeting the same class of operational technology, PLCs, that the Stuxnet worm used against Iran's nuclear centrifuges more than a decade ago. That history doesn't make the current campaign more sophisticated. It makes the choice of target legible.

For practitioners at water utilities in the 12 affected states and beyond, the operational Monday is straightforward and unforgiving: if your PLCs are internet-accessible, they're findable, and the campaign isn't slowing down. Air-gap them or put them behind an authenticated gateway. There's no federal enforcement action coming to make you do it, and no federal remediation team coming to fix it after the fact.


Published ·Deep Fathom