Executive Summary
In July and August 2026, municipal water utilities in New Jersey and Alabama were targeted in a series of cyberattacks that exploited vulnerabilities in internet-exposed operational technology (OT) systems. These incidents, widely attributed to Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated cyber actors, resulted in the temporary loss of automated monitoring and control capabilities at affected utilities. Operators responded by shifting to manual operations, and there was no disruption to water service or compromise of water safety. The attacks are part of a broader pattern of increasing cyber threats against U.S. water and wastewater systems, with federal agencies such as the EPA, FBI, CISA, and NSA issuing joint advisories and increasing enforcement actions. The sector remains at high risk due to widespread non-compliance with basic cybersecurity requirements, including failure to change default passwords, use of shared logins, and lack of incident response planning. No technical indicators of compromise (IOCs) such as malware hashes or command-and-control infrastructure have been publicly disclosed as of the time of writing.
Technical Information
The cyberattacks targeting water utilities in New Jersey and Alabama in 2026 leveraged vulnerabilities in internet-exposed OT systems, specifically targeting Human Machine Interfaces (HMIs) and other process control components. These systems, which are critical for the automated monitoring and management of water treatment and distribution, were accessible from the public internet and lacked adequate access controls and network segmentation. The attackers exploited these weaknesses to disrupt automated operations, forcing utilities to revert to manual processes.
According to official advisories and news reports, the attack techniques included configuration wiping, software-based tampering with mechanical sensors, and disruption of HMIs. These actions temporarily blinded operators, limiting their ability to monitor or manage water systems remotely. The attacks did not result in the compromise of customer data or personal information; the focus was strictly on operational disruption.
The MITRE ATT&CK for ICS (Industrial Control Systems) framework provides a useful mapping for the observed techniques. The relevant tactics and techniques include:
- Initial Access: External Remote Services (T0886), where attackers exploit internet-exposed OT systems to gain unauthorized access.
- Impair Process Control: Inhibit Response Function (T0814), involving the disabling or blinding of automated monitoring and control systems.
- Impair Process Control: Manipulation of Control (T0831), which covers tampering with sensor data or HMI functions.
- Impair Process Control: Modify Parameter (T0832), referring to configuration wiping or altering operational parameters.
No specific malware families, tool names, or technical artifacts (such as file hashes or command-and-control domains) have been publicly disclosed in connection with these incidents. The attacks are described as exploiting vulnerabilities in "widely used utility software," but the software in question has not been named in public sources.
The attacks are widely attributed to Iranian Government IRGC-affiliated cyber actors, with advisories also warning of threats from Russian and Chinese state-sponsored groups, including Volt Typhoon and Vanguard Panda. The EPA, FBI, CISA, and NSA issued a joint advisory in April 2026 specifically warning of ongoing Iranian-affiliated cyber threats targeting U.S. water and wastewater systems. The tactics, techniques, and procedures (TTPs) observed in these incidents are consistent with previous campaigns attributed to Iranian actors, including targeting of internet-exposed OT, HMI disruption, and configuration wiping.
Sector-specific targeting patterns indicate that the water sector is a repeated target for state-sponsored actors due to its criticality and historically weak cybersecurity posture. Over 70% of inspected water systems were found in violation of basic cybersecurity requirements, such as failure to change default passwords, use of shared logins, and lack of incident response planning. Attacks have targeted both large and small utilities, with a focus on operational disruption rather than data theft.
The technical evidence supporting attribution to Iranian-affiliated actors is primarily based on pattern analysis and multiple U.S. government advisories, rather than direct technical artifacts. The confidence level for this attribution is medium-high, given the consistency of TTPs and the alignment with previous Iranian-attributed campaigns.
Affected Versions & Timeline
The attacks exploited vulnerabilities in widely used utility software and internet-exposed OT/HMI systems. Specific software versions have not been publicly disclosed. The timeline of verified events is as follows:
April 7, 2026: The EPA, FBI, CISA, and NSA issue a joint advisory warning of Iranian-affiliated cyber threats to water systems (https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian).
May 2024–July 10, 2026: The EPA increases enforcement and issues updated guidance following a series of cyberattacks on water systems (https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities).
August 5, 2026: New Jersey state officials confirm two municipal water systems were targeted in cyberattacks, with no disruption to service (https://abc7news.com/post/new-jersey-water-utilities-targeted-cyberattacks-widely-believed-linked-iran/19629579/).
The attacks affected automated control and monitoring systems, HMIs, and mechanical sensors. There is no evidence of customer data or personal information compromise; the focus was on operational disruption.
Threat Activity
The threat activity observed in these incidents is characterized by the exploitation of internet-exposed OT/HMI systems, leading to the temporary loss of automated monitoring and control. The attackers used techniques such as configuration wiping, software-based tampering with mechanical sensors, and disruption of HMIs to blind operators and force a shift to manual operations. These actions align with known tactics of Iranian Government IRGC-affiliated cyber actors, as well as Russian and Chinese state-sponsored groups.
The attacks did not result in the compromise of water safety or customer data, but they highlight the sector's vulnerability to operational disruption. The pattern of targeting OT and HMI systems is consistent with previous campaigns by Iranian and Russian actors against critical infrastructure. The sector remains at high risk due to widespread non-compliance with basic cybersecurity requirements.
Mitigation & Workarounds
Mitigation and workarounds recommended by the EPA, CISA, and FBI include the following prioritized actions:
Critical: Immediately reduce exposure of OT and IT systems to the public internet by implementing network segmentation and access controls. Change all default passwords and ensure unique credentials for each user. Conduct a comprehensive inventory of all OT and IT assets to identify and remediate vulnerable systems.
High: Develop and exercise cybersecurity incident response and recovery plans. Regularly backup OT and IT systems and verify the integrity of backups. Conduct regular cybersecurity assessments to identify and address vulnerabilities.
Medium: Provide cybersecurity awareness training for all staff, with a focus on recognizing phishing attempts and social engineering tactics. Review and update Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs) to ensure they address current cyber threats.
Low: Engage with federal and state resources, such as the EPA's Cybersecurity Technical Assistance Program and CISA's Incident Reporting System, for additional support and guidance.
Organizations are encouraged to report suspicious or criminal activity to the FBI Internet Crime Complaint Center (IC3) at ic3[.]gov or to CISA via its Incident Reporting System.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. No technical indicators of compromise (malware hashes, C2 domains, or attack infrastructure) have been published in the referenced sources as of July 2026. The only domains referenced are for reporting and information purposes.
Type | Indicator | Reported (date) | Source
|
Domain | ic3[.]gov | 2026-04-07 | https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian |
Domain | www[.]epa[.]gov | 2026-04-07 | https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian |
References
EPA Enforcement Alert (July 10, 2026): https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities
ABC7 News (August 5, 2026): https://abc7news.com/post/new-jersey-water-utilities-targeted-cyberattacks-widely-believed-linked-iran/19629579/
EPA/FBI/CISA/NSA Joint Advisory (April 7, 2026): https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian
MITRE ATT&CK for ICS: https://attack.mitre.org/matrices/ics/
About Rescana
Rescana provides a third-party risk management (TPRM) platform that enables organizations to continuously assess and monitor the cybersecurity posture of their vendors and critical infrastructure partners. Our platform supports the identification of exposed operational technology assets, tracks compliance with regulatory requirements, and facilitates rapid response to emerging threats in the supply chain and critical infrastructure sectors.
We are happy to answer questions at info@rescana.com.



