All posts

Iran-linked hackers hit water systems in 7 US states

Huma ShaziaAugust 17, 2026 at 9:16 PM4 min read
Iran-linked hackers hit water systems in 7 US states

Iran-linked hackers have hit water utilities in at least seven US states, the FBI confirmed this week, expanding a campaign that already represents the broadest cyberattack on American industrial control systems in recent memory. In some cases, the attacks disabled digital controls and triggered boil-water notices, suggesting potential contamination.

Iran-linked hackers hit water systems in 7 US states
Source: Feed: Artificial Intelligence Latest
Water towers targeted by Iran-linked cyberattacks across seven US states
7 States Water Systems Hit by Cyberattacks Likely Tied to Iran

The FBI alert did not name the affected states or detail the full extent of damage. But the bureau said it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency issued its own advisory, confirming that attacks had "resulted in boil-water notices" in some locations.

Advertisements

What the FBI is telling utilities to do now

At least SEVEN states hit in water systems CYBERATTACK linked to Iran

Both agencies urged utilities to take immediate defensive action. The core advice: remove programmable logic controllers (PLCs) from the public internet, replace default passwords with strong credentials, and set up allow-lists restricting which devices can connect to industrial equipment.

These PLCs are the bridge between software and physical infrastructure. When attackers compromise them, they can manipulate pumps, valves, and chemical dosing systems. The attacks follow a pattern CISA first documented in an April advisory, which identified Iran-affiliated hackers as the likely culprits.

70%
Percentage of water utilities inspected by EPA found to have significant cybersecurity vulnerabilities (2024)

A leaked memo obtained by WIRED confirmed the connection between those earlier warnings and the recent Minnesota utility attacks, where more than 30 water and wastewater systems were hit in a single week.

The attribution question

Iran remains the leading suspect. The hacking group CyberAv3ngers, linked to Iran's Islamic Revolutionary Guard Corps, has previously targeted US water utilities using Israeli-made Unitronics PLCs. The group exploited devices left exposed on the internet with factory-default passwords.

President Trump on Friday blamed Minnesota Democratic Governor Tim Walz's administration for the attacks. The response echoed his 2016 denial of Russia's role in hacking the Democratic National Committee, even after US intelligence agencies attributed that intrusion to the Kremlin.

Why water systems remain vulnerable

Water utilities, especially smaller municipal systems, have long been underfunded on cybersecurity. Many run decades-old equipment that was never designed with network security in mind. When these systems were connected to the internet for remote monitoring, they often kept default credentials.

The threat actors compromised these PLCs made by Unitronics because the devices were publicly exposed to the internet with default passwords.

— Eric Goldstein, Executive Assistant Director for Cybersecurity, CISA (November 2023)

The pattern has not changed. Attackers scan for exposed PLCs, try known default passwords, and often succeed. The fix is straightforward but requires resources many small utilities lack: network segmentation, credential management, and monitoring.

ℹ️

Logicity's Take

For AI builders and product teams, this is a case study in why critical infrastructure vendors cannot ship insecure defaults. The PLCs being exploited are not obscure. Unitronics is a known brand, and its products sit in thousands of facilities. Any team building industrial control software or IoT monitoring tools should treat 'secure by default' as non-negotiable. The pattern here, exposed devices plus factory passwords, is the same vulnerability class that AI-powered asset discovery tools from vendors like Qualys, Tenable, or CrowdStrike are designed to catch. If your product touches infrastructure, you are in the blast radius.

FBI also shopping for predictive AI

Separately, an FBI request for information posted in March reveals the bureau is seeking predictive modeling capabilities for its Threat Screening Center. The system would score incoming records for "pattern alignment" against existing datasets.

The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to focus on people defined broadly as anti-capitalist or hostile toward traditional views on family and religion. FBI Director Kash Patel told Congress the center had posted double-digit growth in biometric processing.

The implications are clear: AI is changing both sides of the security equation. Attackers use automated scanning to find vulnerable infrastructure. Defenders are adopting AI for threat detection. And law enforcement is now shopping for predictive systems that raise civil liberties questions beyond the technical.

ℹ️

Need Help Implementing This?

If your team builds products that connect to industrial systems or processes infrastructure data, reach out to Logicity for guidance on secure-by-default architecture and vendor evaluation frameworks.

Source: Feed: Artificial Intelligence Latest / Matt Burgess

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.