Iranian Hackers Target U.S. Water Systems Through Default Passwords and Exposed Controllers
Key Takeaways
- •Coordinated cyberattacks on July 26–27, 2026 targeted at least 30 municipal water systems in Minnesota, with similar attacks subsequently reported across multiple states including Michigan and New Jersey.
- •The attackers focused on seizing control of programmable logic controllers (PLCs) connected directly to the internet rather than infiltrating administrative office computers.
- •A joint FBI and EPA advisory confirmed that attackers remotely accessed Rockwell Automation MicroLogix PLCs and altered their IP addresses and passwords.
- •Despite being designated critical infrastructure, water utilities operate under no federal cybersecurity mandate comparable to the standards enforced on the electric grid.
- •Rural water systems serving fewer than 3,300 customers face disproportionate cybersecurity risks due to limited budgets, small staffs, and aging industrial equipment that may not support modern security features.

On July 26–27, 2026, hackers attempted to breach at least 30 municipal water systems in Minnesota. Since then, Michigan, New Jersey, and several other states have reported similar cyberattacks, according to sources familiar with the matter.
The attackers did not attempt to infiltrate the administrative computers used in utility offices. Instead, they sought to seize control of small embedded computers—programmable logic controllers (PLCs)—that regulate equipment such as pumps and valves responsible for delivering drinking water to millions of people.
Utility operators countered the attacks by shutting down the control computers and dispatching personnel into the field to operate equipment manually. Officials have stated that drinking water remained safe throughout the incidents.
The methods employed in these attacks are consistent with patterns typically seen in international cyber operations, according to cybersecurity researchers. Initial suspicion has centered on hackers allegedly aligned with Iran, as reported by Wired, though the U.S. government has not yet formally attributed the attacks to any specific actor or nation.
Water and wastewater systems are one of 16 critical infrastructure sectors designated by the federal government, and the attacks come amid a broader escalation of nation-state probing of U.S. industrial infrastructure. In February 2021, an attacker remotely accessed a water treatment plant in Oldsmar, Florida, and attempted to raise sodium hydroxide levels to dangerous concentrations before an operator intervened. In late 2023, Iranian-linked hackers seized control of a PLC at the Municipal Water Authority of Aliquippa, Pennsylvania. The 2026 incidents are notable for their scale—dozens of utilities targeted across multiple states in a coordinated window—rather than a single facility.
How Water System Controls Work
The United States has approximately 152,000 public drinking water systems, according to federal data. The vast majority serve fewer than 3,300 customers and operate with only a handful of staff, a structural reality that has long complicated sector-wide cybersecurity initiatives. Municipal water is typically drawn from lakes, reservoirs, rivers, or underground aquifers. Pumps move the water through pipes to a treatment plant, where it is filtered and disinfected. Additional pumps push the treated water into storage tanks and then through distribution pipes to homes and businesses. These systems can span many square miles.
Hackers targeted PLCs—small computers that operate a wide range of industrial equipment. These controllers read sensors measuring conditions such as water pressure, water chemistry, tank levels, and equipment status, and they automatically operate pumps, valves, and alarms. A household thermostat offers a useful analogy: it reads the temperature and instructs the heating or cooling system accordingly.
PLCs also transmit operational data to a utility's central computer system. Workers use dashboards to monitor the information and send commands back to the controllers. This two-way communication can travel through wired networks, radio or cellular links, or internet connections.
Many utilities operate with small staffs, making remote connections essential. They allow an employee to monitor a distant pump or tank, receive after-hours alarms, or enable a vendor to diagnose equipment without traveling to each site.
Controllers that use the internet may connect directly or go through protective firewalls, secure gateways, or virtual private networks (VPNs). Direct access is more vulnerable because fewer defensive barriers stand between the controller and potential attackers. A hacker can locate a controller by scanning the internet for its Internet Protocol (IP) address, then attempt to use a weak or stolen password or exploit a known security flaw.
To reach a controller protected by a secure gateway or encrypted service, a hacker would need to steal remote-access credentials, breach the gateway or private network, or compromise an operator's workstation to establish a foothold.
Attempted access can also be part of a longer-term strategy to collect intelligence, probe defenses, or establish persistent entry for a future operation.
Anatomy of an Attack
Attacks on industrial control systems typically follow a recognizable sequence. Infiltration often begins with reconnaissance: attackers scan internet addresses for exposed controllers, dashboards, and third-party remote-access services, searching for systems linked directly to the internet. Researchers routinely find thousands of water-sector PLCs and human-machine interfaces exposed on the public internet through tools like Shodan, a search engine for internet-connected devices.
Next, the attacker seeks a default or stolen password, an unpatched vulnerability, or a misconfigured remote-access service. Sophisticated malware is not always required. In 2023, U.S. officials reported that Iranian-linked hackers targeted internet-connected Unitronics PLCs used by water utilities. According to the Cybersecurity and Infrastructure Security Agency (CISA), some utilities were still using the manufacturer's default password.
In the final stage, the attacker exploits the access gained. This could involve changing a password, issuing commands, or attempting to alter the controller's software. Researchers at the National Institute of Standards and Technology (NIST) note that an intruder could replace legitimate control instructions with malicious commands. An attacker could also infiltrate an office computer through phishing and then pivot to the controller network.
Industrial equipment that has been in service for decades is especially vulnerable because it may not support modern security features. Utilities often delay updates to avoid interrupting operations.
Reports indicate that hackers accessed the Minnesota water systems through controllers communicating directly over the internet. A July 30 joint advisory from the FBI and the Environmental Protection Agency (IC3 PSA) stated that attackers remotely accessed Rockwell Automation MicroLogix PLCs connected directly to the internet and changed their IP addresses and passwords.
Defensive Measures
The most immediate protective step utilities can take is removing controllers and human-machine interface dashboards from direct internet exposure. Following the Minnesota attacks, CISA urged water utilities to place this equipment behind properly configured firewalls and other safeguards.
When remote access is necessary, utilities should route communications through a secure gateway or VPN, require multi-factor authentication, and enforce least-privilege access controls. Utilities should also change default passwords, disable unused remote-access services, and install vendor-approved updates.
In its guidance on internet-exposed dashboards, CISA recommends separating operational networks from email and other business systems to make lateral movement between the two more difficult.
Additionally, utilities should back up controller programs, log remote-access activity, and rehearse restoring systems and operating manually.
The EPA, which serves as the sector-specific agency for water under the federal critical infrastructure framework, has pressed Congress for statutory authority to enforce cybersecurity standards across the sector. At present, water utilities face no federal cybersecurity mandate comparable to those binding the electric grid, which is regulated by the North American Electric Reliability Corporation (NERC-CIP) standards. Legislation proposed in prior sessions of Congress to address this gap has not advanced.
The Resource Gap
Rural water utilities with limited budgets and staffing represent a significant vulnerability within the United States' critical infrastructure. A group of volunteer cybersecurity experts is providing guidance to water utilities, but their reach remains limited. Smaller utilities may require government funding or shared cybersecurity services to mount an adequate defense. Sector-specific information-sharing organizations such as the Water Information Sharing and Analysis Center (WaterISAC) offer threat alerts, but adoption among small systems remains uneven.
William Akoto is Assistant Professor of Global Security at the American University School of International Service. This article is republished from The Conversation under a Creative Commons license.