Threat Intelligence

Iran-Linked Hackers Suspected in Widening Attacks on US Water Systems

Dark Reading · 11 Aug 2026
Key Takeaway If your business uses any internet-connected industrial or operational equipment, ensure it is never exposed directly to the internet without strong authentication and network segmentation.

A wave of cyberattacks against water utilities has expanded to affect systems in a dozen US states, according to Dark Reading. The attacks are targeting programmable logic controllers (PLCs) — the industrial devices that manage physical processes like water treatment — which are exposed to the internet without adequate security protections.

Investigators suspect the campaign may be linked to Iranian threat actors, though attribution in these cases is often difficult to confirm with certainty. The pattern highlights a persistent and growing risk: critical infrastructure operators, including smaller municipal utilities, often rely on legacy industrial equipment that was never designed with cybersecurity in mind and is increasingly connected to the internet for remote management.

While this incident specifically involves water systems, it serves as a broader warning for any organisation using internet-connected operational technology (OT) or industrial control systems (ICS). Attackers are actively scanning for exposed devices, and poor configuration — such as default passwords or unrestricted internet access — makes them easy targets, regardless of the attacker's origin or motive.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.