
Multistate Water Infrastructure Attacks Widen: Iran-Linked Actors Target Exposed PLCs Across 12 States
A coordinated cyber campaign targeting internet-exposed PLCs has disrupted water utilities in 12 US states. Federal investigators suspect Iranian state-sponsored actors are exploiting basic security hygiene failures.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
As of August 14, 2026, federal authorities and cybersecurity researchers have confirmed a significant expansion of cyberattacks targeting the U.S. Water and Wastewater Systems (WWS) sector. What began as a localized disruption in Minnesota has now spread to include utilities in Michigan, South Dakota, California, and Georgia, affecting more than 30 community water systems. While drinking water safety remains uncompromised, the attacks have forced several facilities into manual operations after malicious actors gained unauthorized access to Industrial Control Systems (ICS). The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI are currently investigating the scope of the intrusion, which appears to leverage vulnerabilities in internet-exposed Programmable Logic Controllers (PLCs).
Threat Analysis
The current campaign demonstrates a shift toward opportunistic targeting of critical infrastructure with low security maturity. The actors are not utilizing sophisticated zero-day exploits; instead, they are performing wide-scale scanning for PLCs—specifically those used in water pressure and chemical regulation—that are directly connected to the public internet without firewall protection or multi-factor authentication (MFA). In several instances, the attackers successfully modified PLC configurations, changed operator passwords to lock out legitimate staff, and altered IP addresses to disrupt remote monitoring capabilities. This activity mirrors previous TTPs (Tactics, Techniques, and Procedures) observed in regional conflicts where infrastructure is targeted to sow public distrust and operational friction.
Technical Details
The primary vector for these intrusions is the exploitation of unauthenticated remote access protocols on Unitronics and similar PLC brands. Many of the targeted devices were found to be using default manufacturer passwords (e.g., '1111') or had no password protection enabled for their web-based management interfaces. Once access is gained, the actors interact with the Human-Machine Interface (HMI) to manipulate setpoints. In the Braham, Minnesota incident, the treatment plant was briefly taken offline to prevent potential equipment damage. Furthermore, researchers have identified the use of simple automated scripts to identify these assets via search engines like Shodan and Censys, indicating that the barrier to entry for these attacks remains dangerously low for state-aligned groups.
Attribution Assessment
Intelligence gathered by Mandiant and federal partners suggests with high confidence that the actors are affiliated with Iranian state-sponsored groups, specifically those linked to the Islamic Revolutionary Guard Corps (IRGC). The attribution is based on the specific targeting of Israeli-made components within the U.S. water sector and the presence of digital signatures previously associated with the 'Cyber Av3ngers' persona. While the group's primary goal appears to be psychological impact and harassment rather than catastrophic kinetic destruction, the potential for accidental over-pressurization or chemical imbalance remains a critical concern.
Implications
The widening geographic footprint of these attacks highlights a systemic failure in OT (Operational Technology) security hygiene across rural and mid-sized utilities. The reliance on manual overrides is a temporary solution that increases the risk of human error and operational fatigue. If these vulnerabilities are not addressed, we anticipate similar campaigns targeting other under-defended sectors, such as small-scale power cooperatives and regional transportation signaling systems, which often share the same budgetary and technical constraints as the water sector.
Recommendations
Encrygma recommends that all OT operators immediately audit their external attack surface. First, ensure all PLCs and HMIs are removed from the public-facing internet and placed behind a secure VPN with MFA. Second, change all default administrative passwords and disable unnecessary remote management ports. Third, implement the 'ICS Five Critical Controls,' focusing on an ICS-aware incident response plan and a defensible architecture. Finally, operators should maintain up-to-date offline backups of PLC configurations to ensure rapid recovery in the event of a lockout.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
