Iran-Linked Hackers Suspected in Widening Attacks on US Water Systems
A wave of cyberattacks against water utilities has expanded to affect systems in a dozen US states, according to Dark Reading. The attacks are targeting programmable logic controllers (PLCs) — the industrial devices that manage physical processes like water treatment — which are exposed to the internet without adequate security protections.
Investigators suspect the campaign may be linked to Iranian threat actors, though attribution in these cases is often difficult to confirm with certainty. The pattern highlights a persistent and growing risk: critical infrastructure operators, including smaller municipal utilities, often rely on legacy industrial equipment that was never designed with cybersecurity in mind and is increasingly connected to the internet for remote management.
While this incident specifically involves water systems, it serves as a broader warning for any organisation using internet-connected operational technology (OT) or industrial control systems (ICS). Attackers are actively scanning for exposed devices, and poor configuration — such as default passwords or unrestricted internet access — makes them easy targets, regardless of the attacker's origin or motive.