
Coordinated Cyber Campaign Hits Water Utilities in 12 States; FBI Links Activity to Iranian-Backed Actors
A widespread cyber campaign targeting municipal water systems has expanded to 12 U.S. states, exploiting vulnerabilities in industrial control systems. Federal agencies warn of persistent Iranian-affiliated activity.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- United States
- Confidence:
- High Confidence
- CVE:
- CVE-2026-61893, CVE-2026-13584
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
As of August 8, 2026, the FBI and CISA have confirmed that a coordinated cyber campaign targeting U.S. water and wastewater systems (WWS) has expanded to include facilities in at least 12 states, including Minnesota and Michigan. The attacks, which began gaining significant momentum in late July, specifically target internet-facing Programmable Logic Controllers (PLCs). While operational disruptions have been localized, the breadth of the campaign represents one of the most significant challenges to municipal infrastructure security in recent years.
Threat Analysis
The campaign demonstrates a shift toward targeting "low-hanging fruit" within the critical infrastructure sector—specifically smaller municipal utilities with limited cybersecurity budgets. The actors are conducting broad scans for specific industrial hardware exposed to the public internet. Once identified, they utilize default credentials or known vulnerabilities to gain unauthorized access. The primary objective appears to be psychological impact and operational harassment rather than large-scale kinetic destruction, though the potential for the latter remains a significant concern for federal investigators.
Technical Details
The primary targets are Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. Attackers are exploiting these devices by accessing their web-based management interfaces, which are often left exposed on port 80 or 443 without robust authentication. Once inside, the actors have been observed changing device IP addresses, modifying logic settings, and resetting administrative passwords, effectively locking out legitimate operators. In some instances, the attackers have displayed political messages on the Human-Machine Interface (HMI) screens. Additionally, recent intelligence suggests the potential use of "Bit2Watt" style techniques to manipulate power draw, though this has not yet been confirmed in the water sector breaches.
Attribution Assessment
Evidence collected by Mandiant and federal agencies strongly points to Iranian-affiliated threat actors, specifically those operating under the banner of "Cyber Av3ngers" or similar IRGC-linked groups. The tactics, techniques, and procedures (TTPs) align with previous Iranian operations targeting Israeli and U.S. infrastructure. The timing of the escalation suggests a retaliatory or signaling component related to ongoing geopolitical tensions in the Middle East.
Implications
The successful compromise of utilities in 12 states highlights a systemic vulnerability in the U.S. water sector. Many of these facilities rely on legacy OT equipment that was never intended to be internet-facing. The inability of operators to regain control of their PLCs necessitates manual overrides, which can lead to service delays and increased risk of chemical imbalances in water treatment processes. Furthermore, this campaign serves as a proof-of-concept for nation-state actors looking to test the resilience of U.S. domestic infrastructure.
Recommendations
Encrygma recommends that all OT operators immediately audit their networks for internet-facing PLCs. Specific actions include: 1) Implementing multi-factor authentication (MFA) for all remote access to OT environments. 2) Changing all default passwords on Rockwell Automation and Mitsubishi Electric hardware. 3) Disconnecting PLCs from the public internet and utilizing hardware-enforced VPNs for necessary remote monitoring. 4) Applying patches for CVE-2026-61893 and CVE-2026-13584 as identified in recent CISA advisories.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate

Escalating Cyber-Physical Threats Target European and US Energy Grids

