Iranian-Linked Cyberattacks Target U.S. Municipal Water and Wastewater Systems: 2026 Multistate Incident Analysis

Iranian-Linked Cyberattacks Target U.S. Municipal Water and Wastewater Systems: 2026 Multistate Incident Analysis

Executive Summary

Between April and August 2026, multiple U.S. municipal water and wastewater systems experienced coordinated cyberattacks attributed to Iranian-affiliated threat actors, according to joint advisories from the EPA, FBI, CISA, and NSA (https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian). The attacks targeted operational technology (OT) components, including programmable logic controllers (PLCs) and human machine interfaces (HMIs), across at least seven states, with over 30 facilities in Minnesota alone affected (https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210). Attackers exploited internet-exposed devices with weak or default credentials, resulting in configuration wiping, sensor tampering, and loss of monitoring and control capabilities. While no confirmed contamination of water supplies occurred, some incidents led to boil water notices and forced manual operations. The attacks caused operational disruption and financial loss, highlighting the water sector’s vulnerability to OT-targeted cyber threats. Attribution to Iranian-linked actors is based on technical patterns and sector targeting, though no specific malware or technical indicators have been publicly released as of this report. All claims are corroborated by primary sources, including federal advisories and independent news reporting.

Technical Information

The 2026 multistate water system attacks represent a significant escalation in the targeting of U.S. critical infrastructure by Iranian-affiliated cyber actors. The technical modus operandi involved direct exploitation of internet-facing operational technology (OT) devices, specifically PLCs and HMIs, which are essential for the automated control and monitoring of water treatment and distribution processes.

Attack Vector Analysis

Attackers gained initial access by remotely exploiting exposed OT devices. These devices were accessible from the public internet, often due to weak security configurations, default credentials, or the absence of password protection. Once access was obtained, attackers changed device IP addresses and passwords, effectively locking out legitimate operators and causing a loss of monitoring and control capabilities. In several cases, configuration data was wiped, and software-based tampering with mechanical sensors was observed, leading to operational disruption.

The attacks did not rely on custom malware or commodity toolkits; instead, they leveraged the inherent vulnerabilities of poorly secured OT environments. This approach allowed attackers to manipulate system parameters, such as water pressure, and disrupt human machine interfaces, which are critical for real-time system oversight.

MITRE ATT&CK Mapping

The observed techniques align with several MITRE ATT&CK tactics and techniques for both enterprise and industrial control systems (ICS):

  • T1190 - Exploit Public-Facing Application: Attackers exploited internet-exposed PLCs and HMIs.
  • T1133 - External Remote Services: Remote access was used to control OT devices.
  • T1078 - Valid Accounts: Default or weak credentials facilitated unauthorized access.
  • T1490 - Inhibit System Recovery: Configuration wiping inhibited system restoration.
  • T0813 - Manipulation of Control (ICS): Attackers tampered with mechanical sensors and system pressures.
  • T0814 - Loss of View (ICS): Loss of monitoring and control capabilities was a direct result of the attacks.

Impact and Sector-Specific Implications

The attacks resulted in operational disruption, financial loss, and, in some cases, public health advisories such as boil water notices. While no confirmed contamination occurred, the potential for introducing contaminants or damaging equipment was significant. The attacks eroded public trust and underscored the water sector’s attractiveness as a target for nation-state actors seeking to disrupt critical lifeline services.

Federal agencies emphasized the need for immediate reporting, rapid vulnerability correction, and adoption of cybersecurity best practices. The incidents also prompted increased regulatory scrutiny and highlighted the interdependence of water systems with other critical infrastructure sectors, including healthcare and emergency services.

Attribution Assessment

Attribution to Iranian-affiliated actors is supported by joint federal advisories and a pattern of similar attacks on U.S. critical infrastructure, as documented by the CSIS Significant Cyber Incidents timeline (https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents). While technical hallmarks and sector targeting are consistent with previous Iranian operations, no specific malware samples, command-and-control infrastructure, or unique tactics, techniques, and procedures (TTPs) have been publicly disclosed. As such, attribution remains at a medium-high confidence level, based on circumstantial and pattern analysis evidence.

Affected Versions & Timeline

The attacks targeted a range of municipal water and wastewater utilities across at least seven states, with confirmed incidents in Minnesota, Michigan, and South Dakota. Over 30 facilities in Minnesota were affected. The specific brands and versions of PLCs and HMIs targeted have not been publicly disclosed, but advisories indicate that commonly used OT devices with internet exposure and weak security were at risk.

Timeline of Key Events:

April 7, 2026: The EPA, FBI, CISA, and NSA issue a joint advisory warning of ongoing Iranian-affiliated cyber threats targeting U.S. water sector OT. Multiple sectors report configuration wiping, sensor tampering, and HMI disruption, resulting in operational and financial impacts (https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian).

July 22, 2026: CISA, FBI, and other agencies issue a public advisory warning of Tehran-linked hackers targeting U.S. critical infrastructure, including water systems (referenced in NBC News, https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210).

July 31, 2026: FBI and EPA warn that hackers have targeted municipal water systems in at least seven states, with more than 30 facilities in Minnesota breached (https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210).

August 3, 2026: NBC News updates with confirmation of incidents in Michigan and South Dakota, and details on technical methods (remote access, password/IP changes, loss of monitoring/control) (https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210).

Threat Activity

The threat actors demonstrated a clear understanding of OT environments and targeted municipal water utilities with the intent to disrupt operations. Attack methods included remote exploitation of internet-facing devices, manipulation of system parameters, and denial of operator access through credential and network configuration changes. The attacks were opportunistic, exploiting systemic weaknesses in OT security posture rather than deploying advanced malware.

No evidence of lateral movement or persistence mechanisms, such as backdoors or command-and-control malware, has been reported. The focus remained on direct manipulation of exposed devices to achieve immediate operational impact.

The pattern of activity is consistent with previous Iranian-linked campaigns targeting U.S. critical infrastructure sectors, including fuel storage and other lifeline services. The water sector’s reliance on legacy OT systems with limited security controls made it particularly vulnerable to these attacks.

Mitigation & Workarounds

Mitigation measures should be prioritized as follows:

Critical: Immediately remove all PLCs and HMIs from direct internet exposure by placing them behind secure gateways and firewalls. Disable remote access unless absolutely necessary and ensure all remote connections use strong, unique authentication.

High: Change all default and weak passwords on OT devices and implement robust password management policies. Regularly audit device configurations for unauthorized changes.

High: Implement network segmentation to isolate OT networks from IT and public networks. Use access control lists to restrict communications to authorized devices only.

Medium: Conduct regular vulnerability assessments and penetration testing of OT environments. Apply security patches and firmware updates to all OT devices as soon as they become available.

Medium: Provide cybersecurity awareness training for all personnel with access to OT systems, emphasizing the risks of internet exposure and credential reuse.

Low: Develop and routinely test incident response plans specific to OT environments, including procedures for manual operation in the event of a cyber incident.

Organizations are strongly encouraged to report suspicious or criminal activity to the FBI Internet Crime Complaint Center (IC3) at https://www.ic3.gov or to CISA via the Incident Reporting System.

Indicators of Compromise

The following caveat applies: Indicators of compromise (IOCs) are point-in-time and should be validated in your environment before enforcement. As of the time of writing, no public indicators of compromise have been released by federal agencies or independent sources in relation to the 2026 multistate water system attacks.

No public indicators of compromise were available at the time of writing.

References

EPA/FBI/CISA/NSA Joint Advisory (April 7, 2026): https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian

NBC News (July 31, 2026, updated August 3, 2026): https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210

CSIS Significant Cyber Incidents: https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents

About Rescana

Rescana’s Third-Party Risk Management (TPRM) platform enables organizations to continuously assess and monitor the cybersecurity posture of their critical suppliers and partners. Our platform provides actionable insights into supply chain exposures, supports compliance with regulatory requirements, and helps organizations identify and mitigate risks to operational technology environments. For more information or to discuss your organization’s risk management needs, contact us at info@rescana.com.