Iranian-Linked Cyberattacks Target U.S. Water Utilities Across 12 States
Water utilities across at least 12 U.S. states are reporting cyberattacks on their operational technology (OT) systems, with federal agencies pointing to Iranian-linked threat actors. These incidents have led to operational disruptions, including boil water advisories, and highlight significant vulnerabilities within critical infrastructure.
A growing wave of cyberattacks, allegedly linked to Iranian hackers, is impacting water utilities nationwide, with at least 12 states now reporting incidents. The campaign, which began gaining traction in late July, primarily targets **Programmable Logic Controllers (PLCs)**βcritical components of industrial control systems.
### Escalating Threat to Critical Infrastructure
State officials in **Minnesota** were among the first to report incidents last week, with the **FBI** confirming that water and wastewater utilities in at least seven states had experienced operational impacts since July 27. Recent reports from **ABC News** indicate the scope has expanded significantly, now encompassing facilities in Michigan, Georgia, and South Dakota, among others.
**Georgia's Clayton County Water Authority** confirmed a temporary disruption to its operational systems, leading to a precautionary boil water advisory that has since been lifted. A nearby water authority in Georgia also reported a cyber incident.
### Iranian Modus Operandi
While federal agencies have refrained from public attribution, multiple sources indicate the attacks bear the hallmarks of Iranian state-sponsored activity. Since 2023, Iranian groups have repeatedly targeted specific types of OT used by water and wastewater facilities, particularly internet-connected PLCs.
The **Cybersecurity and Infrastructure Security Agency (CISA)** issued an advisory two weeks ago, warning of Iranian state hackers targeting internet-connected OT devices. A follow-up advisory last week emphasized that these attacks have resulted in boil water notices and forced sustained manual operations, affecting water entities of all sizes.
**CISA Acting Director Nick Andersen** stated, βCISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities. We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.β
### Attack Mechanics and Impact
The **FBI** noted that the incidents share similar characteristics: attackers remotely access devices, change passwords, and disable officials' ability to monitor and control the systems. Reported operational effects include loss of pressure and localized flooding. The agency warned that pressure loss could allow untreated groundwater to contaminate pipes.
### Long-Standing Concerns and Geopolitical Echoes
Federal cyber defenders have long expressed concern over the cybersecurity posture of water utilities, often citing inadequate funding for system protections. **Jake Braun**, a former cyber official in the Biden administration who now leads a project connecting volunteer cyber experts with water utilities, highlighted three critical potential impacts of these attacks:
1. **Military Installations:** Civilian water utilities often support U.S. military bases.
2. **Economic Disruption:** Many utilities underpin data centers crucial for the economy, particularly in states like Minnesota.
3. **Erosion of Trust:** Attacks on essential services undermine public confidence in government.
Braun also drew a parallel to the **Stuxnet worm**, allegedly used by U.S. and Israeli officials to target Iran's nuclear program by exploiting similar operational technology. He emphasized the symbolic and strategic nature of these attacks, aiming to disrupt critical services and sow distrust rather than achieve specific physical objectives.
### Recommendations for Utilities
Both **CISA** and the **FBI** strongly urge organizations to:
* Remove PLCs and other OT from public internet exposure immediately.
* Implement robust firewalls.
* Utilize unique, strong passwords for all systems.
* Restrict communication to only expected control devices.