US water systems targeted in cyberattacks across seven states, FBI warns; Iranian hackers suspected
```html US Water Systems Targeted in Cyberattacks: FBI Warns of Iranian Hackers

Theindiapostdaily.com –
Federal Agencies Issue Warning About Water System Cyber Incidents
The Federal Bureau of Investigation and Environmental Protection Agency have jointly announced that malicious cyber actors have been systematically targeting internet-connected industrial control systems belonging to water utilities nationwide. These coordinated incidents span at least seven American states, with several facilities experiencing significant operational disruptions during the attacks.
According to a comprehensive Public Service Announcement released on July 30, the attackers have been actively exploiting internet-facing Operational Technology devices. The most frequently compromised equipment includes Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers, commonly referred to as PLCs in industrial settings.
Investigation Points Toward Iranian Suspects
Investigators are currently examining whether Iranian hackers orchestrated this wave of cyberattacks, CBS reported based on statements from US officials and sources knowledgeable about the situation. While authorities are exploring Iranian involvement, they have cautioned that the attacks have not been definitively attributed to any single nation. The assessment may evolve as additional technical evidence is gathered and analyzed.
Officials are also considering whether the perpetrators deliberately attempted to appear Iran-based in order to exploit heightened tensions between Washington and Tehran. This strategic misdirection could serve multiple purposes, including diverting attention from other potential threat actors or creating confusion during the investigation phase.
How the Cyber Incidents Disrupted Operations
Since July 27, utilities across multiple states have reported incidents involving the compromised PLCs. The cyber actors reportedly gained remote access to exposed controllers and modified device settings in several ways that affected daily operations.
Attackers changed IP addresses and passwords, locked operators out of monitoring and control systems, and modified PLC project files. At least one utility reported discrepancies in ladder logic.
The operational consequences varied depending on each PLC’s specific function within the facility. Some water utilities experienced:
- Loss of water pressure
- Flooding incidents
- Reduced visibility into connected equipment
- Disruptions to automated operations
The FBI emphasized that pressure loss in water systems could potentially allow untreated groundwater to seep into drinking water pipelines, creating public health concerns that extend beyond immediate operational impacts.
Broader Context of Iranian Cyber Activity
This investigation arrives amid heightened military tensions between the United States and Iran, raising concerns that cyber operations could accompany broader geopolitical conflicts. The timing suggests that these attacks may be part of a larger strategy to test critical infrastructure vulnerabilities.
Previous Iranian cyber campaigns targeting US critical infrastructure provide context for the current investigation. According to US authorities, hackers linked to Iran’s Islamic Revolutionary Guard Corps breached programmable logic controllers at several US water and wastewater facilities in 2023 by exploiting default credentials, as reported by the Cybersecurity and Infrastructure Security Agency.
In a separate case, the US Department of Justice charged an Iranian hacker for allegedly accessing the control system of a dam in Rye, New York, in 2013. This historical precedent demonstrates a pattern of Iranian interest in American water infrastructure.
While the FBI has so far observed attacks involving the specified Rockwell PLCs, it warned that similar risks may exist for other industrial control systems connected directly to the internet. The agencies noted that attackers exploited similar third-party network configurations across multiple organizations, suggesting a coordinated approach to identifying vulnerable targets.
Water utilities are being advised to review their network security configurations and ensure that all internet-facing devices have been properly secured. The ongoing investigation continues to gather technical evidence that will help determine the full scope and attribution of these incidents affecting US water systems targeted in cyberattacks.
