Iran-linked hackers have hit water utilities in at least seven US states, the FBI confirmed this week, expanding a campaign that already represents the broadest cyberattack on American industrial control systems in recent memory. In some cases, the attacks disabled digital controls and triggered boil-water notices, suggesting potential contamination.


The FBI alert did not name the affected states or detail the full extent of damage. But the bureau said it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency issued its own advisory, confirming that attacks had "resulted in boil-water notices" in some locations.
What the FBI is telling utilities to do now
At least SEVEN states hit in water systems CYBERATTACK linked to Iran
Both agencies urged utilities to take immediate defensive action. The core advice: remove programmable logic controllers (PLCs) from the public internet, replace default passwords with strong credentials, and set up allow-lists restricting which devices can connect to industrial equipment.
These PLCs are the bridge between software and physical infrastructure. When attackers compromise them, they can manipulate pumps, valves, and chemical dosing systems. The attacks follow a pattern CISA first documented in an April advisory, which identified Iran-affiliated hackers as the likely culprits.
A leaked memo obtained by WIRED confirmed the connection between those earlier warnings and the recent Minnesota utility attacks, where more than 30 water and wastewater systems were hit in a single week.
The attribution question
Iran remains the leading suspect. The hacking group CyberAv3ngers, linked to Iran's Islamic Revolutionary Guard Corps, has previously targeted US water utilities using Israeli-made Unitronics PLCs. The group exploited devices left exposed on the internet with factory-default passwords.
President Trump on Friday blamed Minnesota Democratic Governor Tim Walz's administration for the attacks. The response echoed his 2016 denial of Russia's role in hacking the Democratic National Committee, even after US intelligence agencies attributed that intrusion to the Kremlin.
Why water systems remain vulnerable
Water utilities, especially smaller municipal systems, have long been underfunded on cybersecurity. Many run decades-old equipment that was never designed with network security in mind. When these systems were connected to the internet for remote monitoring, they often kept default credentials.
“The threat actors compromised these PLCs made by Unitronics because the devices were publicly exposed to the internet with default passwords.”
— Eric Goldstein, Executive Assistant Director for Cybersecurity, CISA (November 2023)
The pattern has not changed. Attackers scan for exposed PLCs, try known default passwords, and often succeed. The fix is straightforward but requires resources many small utilities lack: network segmentation, credential management, and monitoring.
Logicity's Take
For AI builders and product teams, this is a case study in why critical infrastructure vendors cannot ship insecure defaults. The PLCs being exploited are not obscure. Unitronics is a known brand, and its products sit in thousands of facilities. Any team building industrial control software or IoT monitoring tools should treat 'secure by default' as non-negotiable. The pattern here, exposed devices plus factory passwords, is the same vulnerability class that AI-powered asset discovery tools from vendors like Qualys, Tenable, or CrowdStrike are designed to catch. If your product touches infrastructure, you are in the blast radius.
FBI also shopping for predictive AI
Separately, an FBI request for information posted in March reveals the bureau is seeking predictive modeling capabilities for its Threat Screening Center. The system would score incoming records for "pattern alignment" against existing datasets.
The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to focus on people defined broadly as anti-capitalist or hostile toward traditional views on family and religion. FBI Director Kash Patel told Congress the center had posted double-digit growth in biometric processing.
The implications are clear: AI is changing both sides of the security equation. Attackers use automated scanning to find vulnerable infrastructure. Defenders are adopting AI for threat detection. And law enforcement is now shopping for predictive systems that raise civil liberties questions beyond the technical.
Need Help Implementing This?
If your team builds products that connect to industrial systems or processes infrastructure data, reach out to Logicity for guidance on secure-by-default architecture and vendor evaluation frameworks.
Source: Feed: Artificial Intelligence Latest / Matt Burgess
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Ai In Business
AI Search Trust Problem: Why 85% of Users Doubt Results
New research reveals a massive gap between AI search adoption and user trust. Two-thirds of Americans use AI search tools, but only 15% trust the results. For businesses relying on AI-powered discovery, this trust deficit represents both a risk and an opportunity.





