News Room
16
Share
Coordinated Cyber Campaign Hits Water Utilities in 12 States; FBI Links Activity to Iranian-Backed Actors
criticalCritical Infrastructure

Coordinated Cyber Campaign Hits Water Utilities in 12 States; FBI Links Activity to Iranian-Backed Actors

A widespread cyber campaign targeting municipal water systems has expanded to 12 U.S. states, exploiting vulnerabilities in industrial control systems. Federal agencies warn of persistent Iranian-affiliated activity.

08 August 2026Last updated 20 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
United States
Confidence:
High Confidence
CVE:
CVE-2026-61893, CVE-2026-13584
Source:
Mandiant
Read Time:
5 min

Executive Summary

As of August 8, 2026, the FBI and CISA have confirmed that a coordinated cyber campaign targeting U.S. water and wastewater systems (WWS) has expanded to include facilities in at least 12 states, including Minnesota and Michigan. The attacks, which began gaining significant momentum in late July, specifically target internet-facing Programmable Logic Controllers (PLCs). While operational disruptions have been localized, the breadth of the campaign represents one of the most significant challenges to municipal infrastructure security in recent years.

Threat Analysis

The campaign demonstrates a shift toward targeting "low-hanging fruit" within the critical infrastructure sector—specifically smaller municipal utilities with limited cybersecurity budgets. The actors are conducting broad scans for specific industrial hardware exposed to the public internet. Once identified, they utilize default credentials or known vulnerabilities to gain unauthorized access. The primary objective appears to be psychological impact and operational harassment rather than large-scale kinetic destruction, though the potential for the latter remains a significant concern for federal investigators.

Technical Details

The primary targets are Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. Attackers are exploiting these devices by accessing their web-based management interfaces, which are often left exposed on port 80 or 443 without robust authentication. Once inside, the actors have been observed changing device IP addresses, modifying logic settings, and resetting administrative passwords, effectively locking out legitimate operators. In some instances, the attackers have displayed political messages on the Human-Machine Interface (HMI) screens. Additionally, recent intelligence suggests the potential use of "Bit2Watt" style techniques to manipulate power draw, though this has not yet been confirmed in the water sector breaches.

Attribution Assessment

Evidence collected by Mandiant and federal agencies strongly points to Iranian-affiliated threat actors, specifically those operating under the banner of "Cyber Av3ngers" or similar IRGC-linked groups. The tactics, techniques, and procedures (TTPs) align with previous Iranian operations targeting Israeli and U.S. infrastructure. The timing of the escalation suggests a retaliatory or signaling component related to ongoing geopolitical tensions in the Middle East.

Implications

The successful compromise of utilities in 12 states highlights a systemic vulnerability in the U.S. water sector. Many of these facilities rely on legacy OT equipment that was never intended to be internet-facing. The inability of operators to regain control of their PLCs necessitates manual overrides, which can lead to service delays and increased risk of chemical imbalances in water treatment processes. Furthermore, this campaign serves as a proof-of-concept for nation-state actors looking to test the resilience of U.S. domestic infrastructure.

Recommendations

Encrygma recommends that all OT operators immediately audit their networks for internet-facing PLCs. Specific actions include: 1) Implementing multi-factor authentication (MFA) for all remote access to OT environments. 2) Changing all default passwords on Rockwell Automation and Mitsubishi Electric hardware. 3) Disconnecting PLCs from the public internet and utilizing hardware-enforced VPNs for necessary remote monitoring. 4) Applying patches for CVE-2026-61893 and CVE-2026-13584 as identified in recent CISA advisories.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo