Iran-Linked Hackers Expand Water-System PLC Attacks to 12 States, CISA and NBC Report
Iranian-affiliated threat actors have hit drinking water and wastewater PLCs in at least 12 states since July, with NBC reporting the targeting now extends to U.S. telecom and energy networks.
Federal agencies and press reporting have converged this summer on a broadening Iranian cyber campaign against U.S. water infrastructure, and the picture is still getting worse.
The clearest baseline is CISA advisory AA26-097A, issued jointly with the FBI, NSA, and EPA on April 7. The advisory described an urgent, ongoing threat from Iranian-affiliated actors exploiting internet-exposed programmable logic controllers at drinking water and wastewater facilities. CISA's published advisory confirmed those actors were using Rockwell Automation's Studio 5000 Logix Designer and Schneider Electric's EcoStruxure Control Expert, among other configuration software, to exfiltrate PLC project files to threat-actor-controlled infrastructure.
The summer months pushed the scope well past what April's advisory described. By late July, CISA updated its advisory to note a significant increase in PLC targeting across the water sector. A separate CISA alert from July 30, reviewed by Dark Reading, specified that threat actors were modifying PLC passwords to lock out operators and disconnecting controllers by altering their IP addresses. Minnesota was the first state to confirm attacks, disclosing that cyberattackers had targeted operational technology systems for more than 30 water systems.
The confirmed footprint has since widened considerably. Utilities in at least 12 states were impacted, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey, according to Cybersecurity Dive's running account of the campaign. CISA and the FBI have not publicly named all 12 states, but nine have self-reported, according to a Center for Strategic and International Studies mapping analysis. CISA noted that, among private companies targeted, many lacked sufficient resources to protect their networks.
Attribution carries moderate confidence at this point. CISA has used the label "Iranian-affiliated APT actors" throughout. One likely candidate is CyberAv3ngers, a hacktivist-branded persona that CISA and outside researchers link to Iran's IRGC Cyber-Electronic Command. The group first drew wide attention after defacing a water utility controller near Pittsburgh in November 2023. Dark Reading's coverage noted there has been no definitive public attribution for the 2026 multi-state campaign, and researchers have previously characterized CyberAv3ngers as opportunistic rather than precisely targeted.
The CSIS analysis is worth reading carefully on the scope question: the 2026 attacks simultaneously hit at least 12 states, whereas earlier Iran-linked water intrusions went after only one or a handful of targets at a time. Reported damage has been "relatively minor" so far in the CSIS framing, but that framing needs context. Jake Braun, a former Biden-era cyber official, told Recorded Future News that civilian water utilities support military installations and many targeted systems also underpin data centers, making the operational risk calculation harder than a contamination-only assessment suggests.
NBC News reported on September 2 that the targeting has extended beyond water to telecommunications, energy, and other infrastructure sectors, citing four people with access to government and industry threat information. Those attempts were described as unsuccessful so far. That's a meaningful distinction, but the NBC sourcing also introduces a classification problem: telecom infrastructure runs on fundamentally different control systems than water treatment PLCs, which suggests the September activity may involve broader network-access operations rather than a straightforward PLC-defacement campaign.
CISA's practical guidance hasn't changed since April: remove publicly exposed PLCs and OT devices from the internet immediately, change default credentials, and audit internet-facing applications. The reporting requirement gap is a documented problem. As the CSIS analysis noted, the current understanding of scope relies on states self-reporting as they search their own logs, and those reporting requirements are inconsistent.
The structural question this campaign raises isn't new, but the 2026 escalation makes it harder to defer. Small water utilities rarely have dedicated security teams. The EPA and the sector's civilian oversight framework were not designed with active nation-state intrusion campaigns in mind. Calls for minimum cybersecurity standards and additional federal funding were already circulating before this summer; the multi-state campaign has sharpened those calls without yet producing a legislative response.
Sources cited:
- CISA Advisory AA26-097A (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- EPA/FBI/CISA/NSA Joint Advisory Press Release (https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian)
- Dark Reading (https://www.darkreading.com/ics-ot-security/multistate-water-system-attacks-widen-iran-suspected)
- Cybersecurity Dive (https://www.cybersecuritydive.com/news/what-we-know-so-far-about-the-hacking-campaign-against-us-water-systems/828374/)
- Center for Strategic and International Studies (CSIS) (https://www.csis.org/analysis/mapping-iranian-cyberattacks-us-water-systems)
- Recorded Future News (The Record) (https://therecord.media/iran-cyberattacks-water-treatment)
- NBC News (https://www.nbcnews.com/politics/national-security/iran-attempted-cyberattacks-range-us-infrastructure-sources-say-rcna595424)
This release was originally distributed via ETL Newswire. Visit CISA Advisory AA26-097A for the full story, related releases, and contact information.
Visit CISA Advisory AA26-097A →