US Water Systems Hit by Suspected Iranian Cyber Attacks

djwhite1551 pts0 comments

US Water Systems Hit by Suspected Iranian Cyber Attacks

SubscribeSign in

US Water Systems Hit by Suspected Iranian Cyber Attacks<br>Is Iran behind the recent cyberattacks on US water systems? An assessment of the evidence, vulnerabilities, and risk of further escalation.

OPFOR Journal<br>Aug 02, 2026

Share

This week, a series of cyber intrusions bearing the hallmarks of Iranian cyber actors targeted water and wastewater systems across multiple US states. This situation report assesses the nature of the attacks, the broader strategic context pointing to Iranian involvement, and what it says about the growing threat of Iranian attacks on the US homeland and US cyber vulnerabilities.

OVERVIEW:

On July 28, Minnesota IT Services, the central information technology agency for the State of Minnesota, announced that it was coordinating with regional and federal agencies to respond to a significant cyber attack launched on July 26 targeting more than 30 municipal water supplies.<br>The attacks, which locked out users and compromised the ability of operators to monitor and control their systems, caused publicly reported outages in several towns and cities including Braham, Plymouth, South St. Paul and Maple Plain.<br>Two days later, on July 30, multiple federal agencies issued public advisory warnings of malicious cyber actors targeting Water and Wastewater Sector public utilities. The Cybersecurity and Infrastructure Security Agency (CISA) warned that it was observing a dramatic increase in intrusions targeting the large industrial computers known as programmable logic controllers (PLCs) used to automate operational processes by water and wastewater systems. According to CISA:<br>“These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”

CISA further advised that affected municipalities institute a boil water advisory.<br>The same day, the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) provided a more detailed warning, stating that since July 27, seven states had reported cyber attacks targeting operational technology used in water and wastewater systems. The announcement specifically warned that attacks had affected Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs. According to the FBI, the attacks risked significant damage to water systems and included “loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”

Rockwell MicroLogix 1400 series Programmable Logic Controller. Source: Rockwell Automation.<br>While the advisories did not explicitly name Iran, and Minnesota’s IT Services declined to attribute the attacks to any international actor, the attacks mirror tactics, techniques, and procedures used by Iranian cyber actors and follow other recent Iranian cyber attacks on US targets.

OPFOR Journal is a reader-supported publication. Subscribe for free to receive new posts like this one, or consider becoming a paid subscriber to support our work.

Subscribe

BIGGER PICTURE:

This week’s attacks follow previous warnings that Iranian cyber actors have been attempting to conduct cyber operations to disrupt US critical infrastructure, specifically in the Water and Wastewater Sector.<br>Attacks Bear Hallmarks of Iranian Involvement

Anticipating the growing Iranian cyber threat, on April 7, 2026, CISA, the FBI, the National Security Agency (NSA), the Environmental Protection Agency (EPA), the Department of Energy, United States Cyber Command, and the Department of the Treasury issued an advisory explicitly warning that Iranian cyber actors had been observed actively trying to compromise Rockwell Automation PLC programs employed by water and wastewater systems.<br>The advisory noted that an Iranian threat actor affiliated with the Cyber-Electronic Command of Iran’s Islamic Revolutionary Guard Corps (IRGC-CEC) known as “CyberAv3ngers” (aka UNC5691/Shahid Kaveh Group) had previously engaged in attacks on PLCs used by water and wastewater systems. As noted in the Homeland Security Brief - April 2026 , between October and early November 2023, CyberAv3ngers compromised a series of PLCs regulating water pressure for the Municipal Water Authority of Aliquippa in western Pennsylvania, causing disruptions in service to 6,000 customers.<br>More recently, on June 11, 2026, a second Iranian cyber threat group, the “Handala Hack Team”, published evidence of an apparent intrusion into the networks of California Water Service (Cal Water). Handala passes itself off as a pro-Palestinian,...

water cyber attacks iranian systems wastewater

Related Articles