The Plain Record

Neutral daily news — clear headlines, complete facts.

National

Iranian-Linked Hackers Target Over 30 U.S. Water Utilities

Iranian-linked hackers exploited default passwords and open ports to lock operators out of more than 30 U.S. water utilities this summer.

Published August 25, 2026 at 12:00 PM EDT

The short answer

Iranian-linked hackers exploited default passwords and open ports to lock operators out of more than 30 U.S. water utilities this summer. Iranian-linked hackers targeted more than 30 U.S. water utilities across multiple states this summer, disrupting operations and forcing some facilities to switch to manual controls.

Iranian-Linked Hackers Target Over 30 U.S. Water Utilities

The Facts

Who
Iranian-linked hackers, U.S. water utilities, FBI, CISA
What
Cyberattacks on US water infrastructure
When
Summer 2026
Where
Multiple states across the United States
Why
To exploit security vulnerabilities like default passwords and open ports to disrupt municipal infrastructure.

Iranian-linked hackers targeted more than 30 U.S. water utilities across multiple states this summer, disrupting operations and forcing some facilities to switch to manual controls. The attackers gained entry by exploiting technical vulnerabilities such as default passwords and open ports to lock internal operators out of their systems.

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have monitored the activity, which involves malicious actors targeting internet-facing programmable logic controllers. These devices are used to manage industrial processes at water and wastewater treatment facilities.

According to Tal Kollender, CEO of cybersecurity startup Remedio, the hackers used these entry points to change passwords and cut off digital access. This forced utility workers to physically operate pumps and valves. Kollender stated that the tactics used were not highly sophisticated and relied on long-standing security gaps that many municipal systems have not yet addressed.

The financial burden typically falls on municipal budgets, where water and wastewater services must compete for limited funds against schools and transportation. Small-business owners and renters in these districts may see long-term effects if local governments increase utility rates or taxes to fund the automated discovery and configuration enforcement tools recommended by experts. These systems require continuous monitoring to identify every device with an internet footprint, a process that many smaller utilities currently lack.

While CISA and the FBI provide warnings and publish indicators of these tactics, the actual implementation of security fixes remains the responsibility of individual utility operators. Without mandatory federal standards or increased local funding for cyber hygiene, experts suggest that municipal power, transit, and wastewater systems remain similarly vulnerable to automated scanning. The next steps for these utilities involve resetting passwords and closing exposed ports, though no specific federal deadline for these upgrades has been reported.

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. See our editorial standards, or report a correction.

← Back to the front page

Questions readers ask

What happened: Iranian-Linked Hackers Target Over 30 U.S. Water Utilities?

Iranian-linked hackers targeted more than 30 U.S. water utilities across multiple states this summer, disrupting operations and forcing some facilities to switch to manual controls. The attackers gained entry by exploiting technical vulnerabilities such as default passwords and open ports to lock internal operators out of their systems.

Who is involved?

Iranian-linked hackers, U.S. water utilities, FBI, CISA

When did this happen?

Summer 2026

Where did this happen?

Multiple states across the United States

Why does this matter?

To exploit security vulnerabilities like default passwords and open ports to disrupt municipal infrastructure.