Iranian threat actors have expanded attacks on water systems across multiple states, exploiting poorly secured programmable logic controllers exposed directly to the internet, according to Dark Reading reporting. The campaign targets operational technology infrastructure at water utilities with minimal security hardening.
Attackers accessed vulnerable PLCs controlling critical water distribution and treatment functions. Water systems typically operate legacy equipment designed before internet connectivity became standard, leaving many utilities with default credentials, unpatched firmware, and no network segmentation. These systems sit on the internet without proper firewalls or access controls, creating straightforward entry points for state-sponsored operators.
The attacks span a dozen states, though specific utility names remain undisclosed pending ongoing investigations. Iranian groups have previously targeted U.S. infrastructure in reconnaissance campaigns. This widening operational tempo indicates escalated targeting of civilian critical infrastructure.
Water utilities control systems that regulate chlorine injection, pump operations, and distribution networks. Direct PLC access enables attackers to manipulate chemical dosing, shut down service areas, or corrupt operational data. The threat extends beyond temporary outages to potential contamination incidents affecting public health.
Defenders should immediately inventory internet-exposed control systems and remove them from public networks. CISA and water sector partners recommend network segmentation, multifactor authentication for remote access, and firmware updates where available. Many water utilities lack funding for modernization, leaving them dependent on compensating controls like air-gapping critical systems and implementing robust monitoring.
The infrastructure remains fragmented across thousands of independent utilities with varying security maturity. Some systems cannot update without shutting down service to entire regions. This operational constraint forces many utilities to accept elevated risk rather than interrupt water supply.
Organizations operating water systems should treat this campaign as active threat intelligence. Attribution to Iranian operators elevates the profile from opportunistic exploitation to state-directed activity. Utilities without dedicated cybersecurity staff should engage third-party assessments and prioritize isolation of internet-accessible
