HomeCyber AttacksCISA Says Iran-Linked Hackers Targeted More Than 100 US Water Systems in...

CISA Says Iran-Linked Hackers Targeted More Than 100 US Water Systems in July

The water sector is once again in attackers’ crosshairs. According to CISA, more than 100 internet-exposed water and wastewater treatment systems across the United States were targeted during July 2026, in activity the agency has linked to Iran-affiliated threat actors. At least a dozen states had confirmed targets, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama.

The common thread across the incidents was not a sophisticated zero-day or an elaborate phishing lure. It was something far more basic: programmable logic controllers, the small industrial computers that physically operate pumps, valves, and treatment equipment, left reachable over the open internet through cellular modems. CISA described the pattern directly, noting activity “commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.” A cellular modem gives a device its own path onto the internet that often sits outside a utility’s normal firewall and monitoring setup, which is exactly what makes this configuration attractive to attackers scanning for exposed industrial equipment.

So far, none of the confirmed intrusions caused a significant disruption to water treatment or delivery. CISA’s advisory reads as a warning rather than a catastrophe report, but it is explicit that the exposure itself, regardless of whether an attacker causes damage, is the underlying problem. Water utilities, especially small and rural ones, often rely on remote cellular connections to monitor equipment spread across wide service areas, and those connections are not always configured with the same protections as a standard corporate network.

CISA’s recommended fixes are mostly about closing that exposure rather than adding new detection tools. The agency is urging utilities to inventory every system reachable from the internet, remove connectivity that is not strictly necessary, change default passwords and apply available security updates, and route any remote access that is needed through a secure gateway or jump host rather than a direct connection. It also recommends multifactor authentication on remote access points, continuous monitoring of network traffic, and periodic reassessment as utility networks change over time.

The timing adds context. The same week this advisory drew renewed attention, the US Treasury Department announced sanctions against nearly 60 Iran-linked entities tied to cyber operations against critical infrastructure, part of what officials called “Operation Economic Outcast.” No CVE or specific software flaw has been assigned to the water sector intrusions themselves, since the underlying issue is exposed configuration rather than a single vulnerability, and CISA has not named a specific group behind the July activity beyond the broad Iran-linked attribution.

Sources: SecurityWeek, reporting on CISA’s advisory covering July 2026 attacks on water and wastewater systems, and The Hacker News on related US Treasury sanctions.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular