News Room
16
Share
US Rewards $10M as Iranian Cyber Actors Target Critical Water and Energy Industrial Control Systems
criticalCritical Infrastructure

US Rewards $10M as Iranian Cyber Actors Target Critical Water and Energy Industrial Control Systems

US authorities and federal agencies have elevated alerts and offered $10 million bounties following aggressive Iranian cyber intrusions sabotaging industrial control equipment across municipal water utilities.

05 September 2026Last updated 05 September 20264 min readCISA / FBI / EPA Joint Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
North America
Confidence:
Confirmed
Source:
CISA / FBI / EPA Joint Intelligence
Read Time:
4 min

Executive Summary

Federal defense and cybersecurity agencies, including the FBI, EPA, and CISA, have intensified joint response measures following escalating Iranian-linked cyber sabotage operations directed at critical infrastructure across the United States. In the past 48 hours, federal authorities announced a $10 million reward under the Rewards for Justice program for information on Iranian actors tied to state-sponsored intrusions against operational technology (OT) systems. The activity follows widespread disruptions targeting municipal water and wastewater systems across multiple states, causing operational degradation, loss of view, and emergency manual overrides.

Threat Analysis

Adversaries have methodically targeted internet-exposed programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) equipment. Rather than conducting traditional passive cyber espionage, the actors demonstrated aggressive sabotage techniques. Upon obtaining remote unauthorized access, the actors rapidly modified system configurations, altered administrative passwords, and manipulated IP routing parameters. These disruptions directly forced local utilities into issuing precautionary boil-water notices and reverting critical municipal treatment equipment to manual physical operations.

Technical Details

The primary vector observed involves the exploitation of internet-facing operational technology assets, notably Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series controllers, alongside broader targeted telemetry against Siemens S7-series hardware. Operators frequently relied on unmonitored cellular modems installed by third-party integrators that bypassed standard enterprise attack-surface management perimeters.

Once administrative interfaces were accessed over exposed web portals or unauthenticated industrial protocols, operators were locked out of Human-Machine Interfaces (HMIs). Rockwell issued technical advisory SD1790 detailing recovery measures for MicroLogix 1400 systems subjected to unknown password changes. Restoration requires taking the controller completely offline, physically removing the 1747-BA memory backup battery to initiate an internal fault state, re-initializing network interfaces via local hardware panels, and re-flashing verified original project configurations via RSLogix 500.

Attribution Assessment

US intelligence and federal law enforcement have attributed the operational disruptions to state-sponsored and state-aligned Iranian cyber actors, notably units affiliated with the Islamic Revolutionary Guard Corps (IRGC). While threat actors employ opportunistic scanning tools to identify exposed industrial protocols, the subsequent deliberate modification of PLC firmware and operational state parameters reflects targeted malicious intent aimed at civilian water, wastewater, and distributed energy nodes.

Implications

The incidents underscore the extreme vulnerability of resource-constrained municipal utilities whose legacy OT environments interface directly with the public internet without network segmentation. As adversaries link regional geopolitical conflicts to domestic utility disruption, the cascading risk of sudden loss of automated pressure, chemical balance, and fail-safe monitoring poses immediate threats to municipal public health and safety.

Recommendations

  • Eliminate Direct Exposure: Disconnect all industrial controllers, RTUs, and HMIs from direct public internet exposure; route necessary external connections strictly through authenticated, zero-trust virtual private networks with mandatory multi-factor authentication (MFA).
  • Audit Cellular Backhauls: Conduct comprehensive inventories of field assets to locate and secure third-party cellular modems and vendor bypass links.
  • Harden Device Credentials: Change all factory-default credentials on field devices, disable unencrypted management protocols, and back up verified PLC program files in air-gapped physical storage.
  • Establish Manual Operating Plans: Ensure facility staff regularly drill operational transitions to offline, manual physical control procedures.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo