Federal authorities are investigating a series of cyberattacks targeting water and wastewater utilities across the U.S., with officials examining whether Iranian hackers may be responsible for the campaign.
The attacks have affected utilities in at least seven states, according to the FBI and Environmental Protection Agency (EPA), though investigators cautioned that no final attribution has been made and that the assessment could change as additional technical evidence is analyzed.
Officials are also examining whether the attackers intentionally attempted to make the operation appear to originate from Iran in an effort to exploit heightened tensions between Washington and Tehran.
The investigation follows a joint Public Service Announcement issued by the FBI and EPA warning that malicious cyber actors have targeted internet-connected industrial control systems used by water and wastewater facilities.
According to the agencies, the attacks began around July 27 and have disrupted operations at some utilities.
The FBI said the attackers targeted internet-facing Operational Technology devices, particularly Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers, commonly known as PLCs.
Investigators said the attackers remotely accessed exposed PLCs, changed IP addresses and passwords, and prevented operators from monitoring or controlling connected equipment.
The FBI warned that while the observed incidents involved Rockwell controllers, similar vulnerabilities may exist across other industrial control systems connected directly to the public internet, per Mint.
Authorities said at least one affected utility discovered unauthorized modifications to PLC project files, including discrepancies in ladder logic used to automate system operations.
Investigators also believe similar third-party network configurations may have enabled attackers to compromise multiple organizations using comparable infrastructure.
The operational impacts have varied by facility but have included losses of water pressure, flooding incidents, reduced visibility into connected equipment, and disruptions to automated water system functions.
Federal officials warned that pressure loss could allow untreated groundwater to enter drinking water systems under certain conditions, potentially creating public health concerns.
The suspected Iranian connection comes as tensions between the U.S. and Iran remain elevated.
Authorities noted that Iranian-linked cyber actors have previously targeted U.S. critical infrastructure.
In 2023, hackers linked to Iran’s Islamic Revolutionary Guard Corps allegedly compromised programmable logic controllers at several U.S. water and wastewater facilities by exploiting default credentials, according to the Cybersecurity and Infrastructure Security Agency,
Federal prosecutors have also previously charged an Iranian hacker with allegedly accessing the control system of a dam in Rye, New York, in 2013.
The FBI and EPA are urging water utilities to disconnect industrial control systems from the public internet whenever possible, implement secure gateways and firewalls, use strong and unique passwords, restrict network access, review device configurations for unauthorized changes, maintain manual operating capabilities, and replace outdated equipment.
