
Coordinated Iranian Cyber Campaign Hits Water Systems Across 12 U.S. States, Targeting Exposed PLCs
A widespread cyber campaign attributed to Iranian-affiliated actors has expanded to 12 U.S. states, compromising over 30 water utilities in Minnesota and Michigan. The attacks exploit internet-facing PLCs to disrupt operations.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- CISA/FBI Joint Intelligence Bulletin
- Read Time:
- 4 min
Executive Summary
As of August 6, 2026, a coordinated cyber campaign targeting the U.S. Water and Wastewater Systems (WWS) sector has escalated significantly. Intelligence reports from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI indicate that the number of affected states has risen to 12, with Minnesota and Michigan reporting the most substantial impacts. Over 30 utilities in Minnesota alone have confirmed breaches, including a treatment plant in Braham that was briefly forced offline. While water safety remains uncompromised, the scale of the disruption highlights critical vulnerabilities in the nation's decentralized infrastructure.
Threat Analysis
The current wave of attacks represents a strategic pivot by Iranian-affiliated threat actors from passive reconnaissance to active operational disruption. By targeting internet-facing Programmable Logic Controllers (PLCs), the adversaries have demonstrated the ability to manipulate human-machine interfaces (HMIs) and halt automated processes. This campaign appears timed to coincide with heightened geopolitical tensions, serving as a "proof of capability" to exert pressure on U.S. domestic stability. The attackers are not seeking financial gain but are instead focused on demonstrating the fragility of the U.S. critical infrastructure perimeter, particularly in rural and municipal sectors that lack robust defensive resources.
Technical Details
The primary vector for these intrusions involves the exploitation of internet-exposed PLCs, specifically those utilizing default administrative credentials or lacking multi-factor authentication (MFA). Attackers have been observed using automated scanning tools to identify devices listening on common industrial ports. Once access is gained, the actors modify configuration settings or deploy malicious firmware updates to disrupt the logic of the controller. In the Minnesota incidents, operators reported unauthorized changes to pump control parameters, necessitating a shift to manual override to maintain system pressure and chemical balance. The use of the Expansion–Exposure–Exploitation (E3) model by these actors suggests they are specifically hunting for legacy OT systems that have been recently connected to cloud environments without adequate segmentation.
Attribution Assessment
Encrygma analysts, in alignment with CISA and FBI findings, attribute this activity with high confidence to Iranian-affiliated groups, likely the "CyberAv3ngers" or a related Islamic Revolutionary Guard Corps (IRGC) unit. The tactics, techniques, and procedures (TTPs)—including the specific targeting of Israeli-made Unitronics PLCs and the use of political messaging on compromised HMI screens—are consistent with previous Iranian operations. The geographic spread across 12 states suggests a well-resourced, coordinated effort rather than opportunistic hacking.
Implications
The successful compromise of over 30 utilities in a single week underscores the systemic risk posed by the "IT/OT convergence" in small-to-medium municipal systems. These entities often lack the cybersecurity budget of major metropolitan utilities, making them "soft targets" for nation-state actors. The cascading risk is significant; a prolonged outage in water treatment could impact local healthcare facilities, fire suppression capabilities, and industrial manufacturing, creating a localized state of emergency. Furthermore, this demonstrates that critical infrastructure is now a primary theater for geopolitical signaling.
Recommendations
Encrygma recommends that all WWS operators immediately audit their networks for internet-facing industrial control equipment. Critical steps include:
- Disconnecting all PLCs and HMIs from the public-facing internet and placing them behind a secure VPN with MFA.
- Changing all default manufacturer passwords to complex, unique credentials immediately.
- Implementing robust logging for all remote access attempts to OT environments and monitoring for unauthorized SCOM/HMI changes.
- Conducting regular "manual mode" drills to ensure staff can maintain operations during a cyber-induced automated system failure.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian-Linked APTs Escalate Cyber-Sabotage Campaign Against US and European Critical Infrastructure

Iran-Linked Cyber Actors Escalate Attacks on UK and US Critical Infrastructure

