Over 30 U.S. Water Utilities Hit in Coordinated Cyberattack — CISA and FBI Issue Urgent Warning

The security of America’s drinking water is back in the crosshairs. This week, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint advisory confirming that more than 30 water and wastewater systems across the United States have been targeted in a sustained hacking campaign. The attackers, according to the agencies, are linked to Iran’s Islamic Revolutionary Guard Corps (IRGC) and have been actively breaking into operational technology (OT) environments for months.

The implications are serious. In multiple cases, the intruders successfully changed passwords on critical devices, tampered with industrial controllers, and triggered local service disruptions. While no drinking water contamination has been reported, the advisory describes a deliberate attempt to cross the line from digital intrusion into physical sabotage. For the average person who just turns on a tap and expects clean water, the news is a sharp reminder that critical infrastructure lives on the internet — and that there are adversaries actively looking to poison the well.

Cybersecurity analysts monitoring a coordinated cyberattack targeting U.S. water utilities in an industrial control room with critical infrastructure security dashboards.

What Actually Happened

The campaign wasn’t a single smash-and-grab. CISA and the FBI say the threat actors spent months scanning the open internet for vulnerable industrial control systems, then systematically broke into poorly defended targets. They specifically hunted for Human-Machine Interfaces (HMIs) and Programmable Logic Controllers (PLCs) — the screens and small computers that let operators monitor water treatment processes, adjust chemical levels, and control pumps — that were left exposed without proper authentication.

Once inside, the hackers escalated their access. In several water facilities they changed PLC passwords, effectively locking out the legitimate operators. In others they modified set points, altered pump run cycles, and even interrupted the logging mechanisms meant to record such changes. The result wasn’t a catastrophic poisoning, but something just as unnerving: unexplained pressure drops, unexpected chemical imbalance alerts, and brief service interruptions that confused local staff until forensics uncovered the root cause.

A senior CISA official, speaking on background, described the operation as a reconnaissance and pre-positioning campaign — the digital equivalent of an enemy soldier mapping out a building’s electrical panel and water valves long before any overt attack. The FBI’s assessment is that the group behind this activity, publicly tracked by private sector researchers as “CyberAv3ngers” or a closely related IRGC unit, has been refining its ability to disrupt physical processes inside U.S. critical infrastructure for at least two years.

Why Water Systems Are So Exposed

If you’ve never thought about cybersecurity at your local water plant, you’re not alone. Most small and medium-sized water utilities operate with tight budgets, aging equipment, and IT teams that might be a single person who handles everything from email to server patches. Industrial control systems at these plants were historically isolated from the internet — but over the last decade, the drive toward remote monitoring and efficiency pushed more devices online, often with default passwords still in place.

Understanding SCADA and PLCs

To understand the risk, it helps to grasp two terms. SCADA stands for Supervisory Control and Data Acquisition; it’s the central brain that collects data from sensors and lets operators control valves, pumps, and chemical dosing from a computer screen. PLCs are the field-level workhorses — small, ruggedized computers that execute physical commands, like starting a pump when a tank level drops. When a PLC gets exposed to the open internet with no password or a default “1234” login, anyone who can find it can potentially manipulate physical processes.

Finding them is trivial. Websites like Shodan.io index internet-connected devices, including industrial controllers. Attackers routinely scan for specific makes and models — Unitronics Vision series PLCs were a particular focus of this campaign — and automate break-in attempts. In the current wave, CISA confirmed that many compromised devices were using factory-default credentials or had their management interfaces accessible via unencrypted HTTP connections visible to the entire internet.

The Iranian Connection and What They Want

Attributing cyberattacks is never simple, but the FBI and CISA express high confidence that this activity originates from actors affiliated with the Iranian government. The group’s past operations — such as compromising Unitronics PLCs at multiple U.S. water facilities in late 2023 and defacing them with anti-Israel messages — left a distinct technical and geopolitical signature. Those earlier intrusions appeared more geared toward psychological impact; the new campaign feels more methodical and operational.

Why target water? It’s a soft target with outsized psychological effect. Disrupting water service, even temporarily, erodes public trust. And from an adversary’s perspective, hitting dozens of small systems simultaneously can generate national headlines without the hard work of penetrating a heavily defended military network. This campaign fits a pattern of escalating, low-simmer conflict that rarely leads to mass casualties but keeps homeland security officials up at night.

What CISA and the FBI Are Telling Operators to Do

The advisory doesn’t mince words. CISA’s number one recommendation is blunt: Disconnect any industrial control system device from the public internet if it does not absolutely need to be exposed. If remote access is necessary, it should be routed through a properly configured VPN with multi-factor authentication, not a PLC’s built-in web server sitting naked on a broadband connection.

Beyond that immediate step, the agencies outline several must-do actions for every water and wastewater utility:

  • Change all default passwords immediately. This sounds obvious, but time and again audits find PLCs and HMIs with credentials like “admin/admin.” Use strong, unique passwords and store them in a secure vault.
  • Segment your network. Industrial devices should live on a separate subnet that cannot be directly reached from the internet or the business office network. Firewalls with strict allowlists should block all traffic except what’s absolutely necessary.
  • Enable logging and monitor it. The attackers in this campaign turned off logging in some facilities. Operators need centralized log collection that can’t be disabled from the compromised device itself. Even simple checks for unexpected password changes or configuration modifications could have caught this activity earlier.
  • Keep firmware and software updated. Many PLCs and HMIs were running outdated firmware with known vulnerabilities. Patching may be harder in an OT environment where uptime is critical, but the alternative is leaving a known open door.
  • Apply application allowlisting. If a PLC or HMI only ever runs the water treatment program, configure it to block anything else from executing. This limits damage even if an attacker logs in.
  • Implement multi-factor authentication everywhere possible. While some legacy industrial gear doesn’t support MFA, any system that does — jump servers, VPN gateways, remote desktop portals — must enforce it.
  • Conduct incident response drills. The utilities that recovered fastest had a plan. At a minimum, know how to physically isolate compromised devices and fall back to manual controls if the SCADA screen goes dark.

For homeowners and business owners, the guidance is simpler but no less important: recognize that critical services rely on cybersecurity that is often fragile. Support local bond measures that fund infrastructure modernization, and don’t ignore basic cyber hygiene in your own networks — compromised home routers and business Wi-Fi are sometimes used as launching pads for larger attacks.

Cyberattack on water utilities response team inspecting a water treatment facility during a critical infrastructure cybersecurity incident.

The Bigger Picture

This campaign is not an isolated incident. It’s part of an uncomfortable trend where nation-state actors and criminal gangs alike have realized that critical infrastructure is full of internet-facing devices no one remembered to secure. Water, energy, transportation, healthcare — the same story repeats. In the last two years alone, the U.S. has seen a ransomware attack that forced a water treatment plant to operate in manual mode, a highly publicized breach of a water facility in Oldsmar, Florida (where an attacker attempted to spike sodium hydroxide levels), and multiple advisories about Chinese and Russian scanning activity against energy grids.

The response from Washington has been a mix of mandates and incentives. The Environmental Protection Agency (EPA) recently moved to require cybersecurity risk assessments for water systems serving more than 3,300 people, though litigation has slowed implementation. CISA continues to offer free vulnerability scanning and incident response services to critical infrastructure operators who ask. The challenge remains scale — there are roughly 150,000 public water systems in the country, the vast majority of them small and under-resourced.

What makes this particular alert worth taking seriously is the volume. Thirty-plus successful intrusions in a single campaign signals an adversary that has found a repeatable, reliable way in. The fact that they have moved from simply defacing screens to actively modifying control logic — even if destructively minor so far — changes the risk calculus. It’s no longer about espionage or cyber vandalism; it’s about demonstrating the ability to reach out from a keyboard and turn valves in the real world.

A Sobering Reminder

If there’s one lesson from this round of attacks, it’s that the most sophisticated nation-state hackers often don’t need to use zero-day exploits when default passwords still litter the industrial internet. The vulnerabilities being exploited are not exotic. They are the cybersecurity equivalent of leaving the front door unlocked with a neon “Welcome” sign.

Water plant operators, city managers, and the boards overseeing these utilities need to treat this moment as a fire drill that isn’t a drill. The advisory from CISA and the FBI is unusually direct in tone — more “do this immediately” than “consider evaluating.” That urgency alone should capture attention. The next time an Iranian hacking team logs into an unprotected PLC, the outcome might be more than a temporary pressure fluctuation. It might be water that isn’t safe to drink, or a pump that doesn’t spin when it’s needed most.

Nobody wants to explain that to their community after the warning was publicly available. The time to harden water infrastructure isn’t after the contamination notice goes out — it’s right now.