Iranian-linked hackers targeted more than 30 U.S. water utilities across multiple states this summer, disrupting operations and forcing some facilities to switch to manual controls. The attackers gained entry by exploiting technical vulnerabilities such as default passwords and open ports to lock internal operators out of their systems.
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have monitored the activity, which involves malicious actors targeting internet-facing programmable logic controllers. These devices are used to manage industrial processes at water and wastewater treatment facilities.
According to Tal Kollender, CEO of cybersecurity startup Remedio, the hackers used these entry points to change passwords and cut off digital access. This forced utility workers to physically operate pumps and valves. Kollender stated that the tactics used were not highly sophisticated and relied on long-standing security gaps that many municipal systems have not yet addressed.
The financial burden typically falls on municipal budgets, where water and wastewater services must compete for limited funds against schools and transportation. Small-business owners and renters in these districts may see long-term effects if local governments increase utility rates or taxes to fund the automated discovery and configuration enforcement tools recommended by experts. These systems require continuous monitoring to identify every device with an internet footprint, a process that many smaller utilities currently lack.
While CISA and the FBI provide warnings and publish indicators of these tactics, the actual implementation of security fixes remains the responsibility of individual utility operators. Without mandatory federal standards or increased local funding for cyber hygiene, experts suggest that municipal power, transit, and wastewater systems remain similarly vulnerable to automated scanning. The next steps for these utilities involve resetting passwords and closing exposed ports, though no specific federal deadline for these upgrades has been reported.
