Active Critical impact Industrial control systems Checked 8m ago

Iran-linked hackers disrupt US water and energy PLCs

US agencies warned that Iran-affiliated hackers targeted internet-connected industrial controllers at water, energy, telecommunications, government, and other critical facilities. More than 100 US water systems were targeted in July. Recent attempts against US infrastructure were reportedly unsuccessful. APT IRAN claimed responsibility for a Texas AT&T outage, but AT&T blamed attempted cable theft.

Started
Mar 1, 2026
Latest activity
Sep 9, 2026
Attributed to
CyberAv3ngers and APT IRANLikely
Where
United States
Sectors
Water, Energy, Government
Scale
CISA said more than 100 internet-exposed water and wastewater systems were targeted in July.

Current status

On September 9, AT&T said the Texas outage was caused by attempted cable theft, while APT IRAN claimed responsibility and threatened further attacks.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

No US agency has publicly confirmed the campaign's attribution. APT IRAN's claims remain unverified, and AT&T denied that its Texas outage was a cyberattack.

Impact

Attackers remotely accessed internet-facing industrial controllers and changed device settings, network addresses, and passwords. Some facilities lost monitoring or control, causing pressure drops, flooding, manual operation, or temporary shutdowns. No widespread water-safety impact has been confirmed.

What to do

Operators should remove industrial controllers from direct internet access, especially those reachable through cellular modems, and place them behind secure gateways or firewalls. They should restrict remote access, check logs for suspicious traffic on ports 502, 102, 2222, and 44818, change default passwords, apply patches, and prepare manual controls for pumps, pressure, and chemical dosing. CISA also advises searching for exposed assets through vendors, contractors, and legacy infrastructure.

Timeline

  1. Sep 9, 2026

    AT&T said it found no evidence that the Texas outage was a cyberattack and attributed it to attempted cable theft. Service was restored.

    Activefox4news.com
  2. Sep 9, 2026

    APT IRAN claimed responsibility for a multi-hour AT&T internet outage in parts of Texas and threatened further attacks, but the claim was not verified.

    Activethreatbeat.com
  3. Sep 9, 2026

    APT IRAN claimed responsibility for a Texas AT&T outage and said it targeted telecommunications and an unknown Texas water utility. AT&T said it found no evidence of a cyberattack and attributed the outage to attempted cable theft. The outage was resolved.

    Activechron.com
  4. Sep 5, 2026

    New Hampshire's Department of Environmental Services said it knows of no impact to the state's own water systems from the nationwide campaign, even as it and other states continue to treat cybersecurity as a growing operational challenge for water suppliers.

    Activeeagletribune.com
  5. Sep 5, 2026

    New Hampshire's Department of Environmental Services said it is not aware of any impact to the state's water systems from the campaign.

    Activenhpr.org
  6. Sep 5, 2026

    New Hampshire's Department of Environmental Services said it is not aware of any impact to New Hampshire water systems from the broader campaign, even as the state's utilities continue to prepare defenses.

    Activenhpr.org
  7. Sep 4, 2026

    Forescout announced that it joined Project Watershed 250 to provide cyber defense resources to Texas water utilities.

    Activefinance.yahoo.com
  8. Sep 3, 2026

    A report citing NBC News said Iranian-affiliated groups had probed US water, energy, telecom, and government targets, with recent attempts unsuccessful and at least 75 automation devices compromised since 2023.

    Activegadgetreview.com
  9. Sep 3, 2026

    Recap coverage of the NBC report added that CyberAv3ngers, the Iran-linked group, is assessed to have compromised at least 75 automation devices in US critical infrastructure since 2023, and that US officials view the water-system intrusions as geopolitical signaling rather than an attempt at mass disruption.

    Activegadgetreview.com
  10. Sep 3, 2026

    Follow-up reporting described the hackers as still using basic techniques, probing exposed industrial controls on US water and energy systems across at least seven states, with no new confirmed disruption reported.

    Activeyahoo.com
  11. Sep 2, 2026

    NBC News reported that Iranian hackers had recently attempted attacks against US water, telecommunications, energy, and other infrastructure. Sources said the attempts were unsuccessful.

    Activenbcnews.com
  12. Sep 2, 2026

    NBC News reported, citing four people with access to government and industry threat information, that Iranian-affiliated hackers have also probed US telecommunications, energy, and government networks in recent weeks; the attempts have so far been unsuccessful. A Telegram channel calling itself APT IRAN separately threatened 'unexpected and critical events' against US infrastructure, with no evidence yet of a successful operation behind the claim.

    Activenbcnews.com
  13. Sep 2, 2026

    NBC News reported that Iranian hackers, or actors from the same campaign, had also made unsuccessful attempts against US telecommunications and energy targets, and that an Iranian hacking group posted a Telegram warning of coming 'unexpected and critical events' against American infrastructure.

    Activenbcnews.com
  14. Sep 2, 2026

    NBC News reported that Iranian hackers have targeted US telecommunications, energy, and other infrastructure beyond water systems in recent weeks, with attempts so far unsuccessful, and that an Iranian hacking group posted on Telegram warning of coming 'unexpected and critical events' against American infrastructure.

    Activenbcnews.com
  15. Sep 2, 2026

    An Iranian hacking group posted on a Telegram channel warning that it would target US energy, water, and telecommunications sectors, saying prior warnings had been ignored and that "unexpected and critical events" would follow.

    Activemediaite.com
  16. Sep 2, 2026

    NBC News reported that Iranian hackers have targeted US telecommunications, energy, and other infrastructure beyond water systems in recent weeks, citing four people with access to government and industry cyberthreat information; the attempts have so far been unsuccessful.

    Activenbcnews.com
  17. Sep 2, 2026

    NBC News reported, citing four people with access to government and industry threat information, that Iranian-linked hackers have continued attempting cyberattacks on US water, telecommunications, energy, and other infrastructure in recent weeks, with the attempts unsuccessful so far.

    Activenbcnews.com
  18. Sep 1, 2026

    The Environmental Protection Agency announced nearly $12 million for water-system cybersecurity and resilience in 10 cities, while Texas began its water-security pilot.

    Activeyahoo.com
  19. Sep 1, 2026

    Texas Governor Greg Abbott and the White House launched Project Watershed 250, a federal-state pilot pairing AI security tools with Texas water systems to find and fix cyber vulnerabilities before further attacks.

    Activeyahoo.com
  20. Sep 1, 2026

    Cybersecurity vendor Abnormal AI said it was joining Project Watershed 250 to provide added protection for Texas water utilities under the public-private pilot.

    Activefinance.yahoo.com
  21. Aug 31, 2026

    Texas and the White House launched Project Watershed 250, a pilot offering free cyber defense resources to Texas water utilities.

    Activegov.texas.gov
  22. Aug 31, 2026

    Texas announced Project Watershed 250, a six-month pilot with the Trump administration, Texas Cyber Command, and private companies including Microsoft, pairing AI and cybersecurity tools with Texas water systems; officials said it was not created specifically in response to the Minnesota attacks.

    Activeyahoo.com
  23. Aug 31, 2026

    CISA and the FBI still had not publicly attributed the July water-sector intrusions to any named group or country and did not respond to questions about attribution, GovInfoSecurity reported.

    Activegovinfosecurity.com
  24. Aug 31, 2026

    The White House Office of the National Cyber Director and Texas Governor Greg Abbott launched Project Watershed 250, a six-month pilot in San Antonio giving Texas water utilities free cybersecurity assessments and AI-enabled monitoring tools, in direct response to the ongoing suspected Iran-linked campaign.

    Activeyahoo.com
  25. Aug 31, 2026

    The Trump administration, Texas Governor Greg Abbott's office, and the Texas Cyber Command formally launched Project Watershed 250, a six-month water-sector cybersecurity pilot in San Antonio with the EPA, CISA, and private firms including Microsoft, Dragos, and Palo Alto Networks, aimed at finding and fixing vulnerabilities in water systems and eventually expanding the model nationwide. Officials said the water systems affected by the earlier attacks continued operating safely with no known public health effects.

    Activenextgov.com
  26. Aug 30, 2026

    After the US struck Iranian rocket launchers near the Strait of Hormuz and Iran fired missiles and drones at bases in Jordan and the UAE, ending a monthlong lull in the conflict, a Telegram channel calling itself APT IRAN warned of unexpected and critical events targeting US energy, water, and telecom systems, and said only six states, not the roughly 12 reported by officials, were hit in the July water attacks.

    Activegovinfosecurity.com
  27. Aug 28, 2026

    Britain's NCSC told all organizations to check for operational-technology vulnerabilities, citing recent disruptive cyber activity connected to the wider suspected Iran-linked campaign against industrial control systems.

    Activecomputing.co.uk
  28. Aug 28, 2026

    The Telegraph reported that Britain's water industry was placed on alert. The NCSC said it had seen increased targeting of industrial control systems across several sectors worldwide, including in the UK, but did not name an attacker.

    Activeyahoo.com
  29. Aug 28, 2026

    Britain's water industry was placed on high alert after the earlier reported Iran-linked shutdown of a small UK power plant, joining the UK energy sector, which had been placed on alert days earlier.

    Activeyahoo.com
  30. Aug 28, 2026

    Britain's water industry was put on high alert over suspected Iran-linked hacking activity, extending a warning first issued to UK energy companies after a small UK power plant was forced offline for four days; no new US water or energy victims were reported.

    Activeyahoo.com
  31. Aug 28, 2026

    An NBC Chicago investigation reported that federal law enforcement officials suggested Iranian hackers targeted pump routing devices at the James W. Jardine Water Purification Plant, the world's largest conventional drinking water plant, during last month's campaign. Chicago's water department said the attempt did not succeed, no ransom was paid, and treatment operations were never affected. The report separately noted an unrelated ransomware attack a year earlier locked the department's front-office computers for two months.

    Activenbcchicago.com
  32. Aug 27, 2026

    Chicago water officials said the Jardine water plant had blocked the latest intrusion attempt. The utility said it had changed factory passwords and was monitoring and updating them.

    Activenbcchicago.com
  33. Aug 27, 2026

    NBC Chicago's investigative team toured the Jardine water plant, the world's largest, and reported that Iranian-linked hackers had accessed pump routing devices at some breached facilities where factory-default passwords were never changed; Chicago officials said their own passwords were not default and are constantly monitored, and the plant was not breached.

    Activenbcchicago.com
  34. Aug 27, 2026

    NBC Chicago aired a follow-up investigation in which Chicago Water Commissioner Randy Conner said the city's Jardine filtration plant, the world's largest, raised its alert level after the nationwide water-utility attacks but that its defenses held; Conner separately disclosed an unrelated ransomware attack on the utility's administrative computers about a year earlier that locked front-office systems for two months without touching plant controls.

    Activenbcchicago.com
  35. Aug 26, 2026

    The Register quoted cybersecurity analysts saying the more-than-100-victim count shows a systemic vulnerability across small water utilities, while noting the federal government still has not formally attributed the campaign to Iran or any group.

    Activetheregister.com
  36. Aug 26, 2026

    Reuters reported the FBI and CISA are investigating a separate July breach at Micro-Comm, a small Kansas maker of water-system PLCs, claimed by a profit-motivated ransomware group called Barracuda; the company and outside coverage said this incident appears unrelated to the suspected Iranian campaign against water utilities.

    Activenypost.com
  37. Aug 25, 2026

    GovInfoSecurity reported that utilities or state agencies in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed they were among those hit, and that CISA still has not attributed the July activity to any government or group.

    Activegovinfosecurity.com
  38. Aug 25, 2026

    CISA published new guidance saying it observed more than 100 internet-exposed water and wastewater systems targeted in cyberattacks throughout July, hit most commonly through PLCs connected directly to a cellular modem, and gave a four-step process for utilities to find and reduce internet exposure.

    Activegovinfosecurity.com
  39. Aug 25, 2026

    Recap coverage of the July UK power plant outage said attackers reportedly targeted the plant's PLC and its backup power failover systems, that the UK government confirmed the incident but has not formally blamed Iran, and that no new US water or energy victims have been reported.

    Activeyahoo.com
  40. Aug 25, 2026

    The US Treasury Department sanctioned five Iranian nationals over a separate hacking and cryptocurrency-theft campaign against US energy companies, defense contractors, health care institutions, tech firms, financial institutions, and government offices dating to late 2023 and 2024. Treasury said CISA has not publicly attributed the water utility intrusions covered in this incident to Iran.

    Activenextgov.com
  41. Aug 24, 2026

    Further recap coverage described the UK incident as testing Britain's energy defenses against hostile-state cyber threats; no new US water or energy victims were reported.

    Activeoilprice.com
  42. Aug 23, 2026

    Follow-up coverage of the UK power plant shutdown continued, with reports noting UK officials said the country's wider electrical supply was never at risk even though the small plant was offline for four days.

    Activenypost.com
  43. Aug 22, 2026

    The Telegraph reported, citing sources, that Iran-linked hackers shut down a small UK power plant for four days, an incident described by other outlets as coinciding with the wave of Iran-affiliated attacks on US water utilities; this is a separate UK facility, not a confirmed part of the US water/energy campaign's victim count.

    Activemiddleeasteye.net
  44. Aug 21, 2026

    Forbes published a recap of the AA26-231A advisory warning that AI-generated exploit code is being used against Siemens controllers, with no new victims or attribution named.

    Activeforbes.com
  45. Aug 20, 2026

    AP recapped the campaign in a 'what we know so far' explainer, noting the government still had not formally attributed the attacks and no new US victims had been confirmed.

    Activeyahoo.com
  46. Aug 20, 2026

    Follow-up coverage of the AA26-231A advisory continued, recapping the AI-generated Siemens PLC exploit warning; no new victims, attribution, or closure were reported.

    Activetechtimes.com
  47. Aug 19, 2026

    Cybersecurity experts told GovInfoSecurity that more than three weeks after the July water-utility intrusions, they still cannot explain why attackers with full access to PLCs changed passwords and disabled alerts but did not attempt to damage pumps, burst pipes, or alter chemical treatment levels, and noted no destructive Iranian information-operation campaign accompanied the intrusions.

    Activegovinfosecurity.com
  48. Aug 19, 2026

    CISA, the FBI, NSA, the Department of Energy, and the EPA published advisory AA26-231A, the first government OT advisory to state that threat actors are using AI to write functional exploit scripts, in this case against internet-exposed Siemens S7 Series PLCs found via Censys and ZoomEye scans on port 102.

    Activecisa.gov
  49. Aug 19, 2026

    CISA, the FBI, and partner agencies issued a joint advisory warning that threat actors are using AI to generate exploitation scripts and evasion tools against internet-exposed Siemens S7 Series PLCs in water, energy, manufacturing, and food and agriculture facilities, calling this likely linked to the broader suspected-Iranian campaign but stopping short of formal attribution.

    Activeinfosecurity-magazine.com
  50. Aug 18, 2026

    The Christian Science Monitor reported the individual water utility attacks from the prior month were resolved quickly, but the incidents, only possibly linked to Iranian actors, exposed lasting cybersecurity gaps at small and rural utilities with limited resources.

    Activecsmonitor.com
  51. Aug 16, 2026

    The Atlantic reported that the Trump administration had not confirmed Iran's role, disclosed a full victim count, or said whether other breaches had occurred. The report named no new victims and gave no closure date.

    Activetheatlantic.com
  52. Aug 14, 2026

    Deseret News reported that Utah is among the roughly 12 affected states, citing an intelligence note reviewed by ABC News describing targeted reconnaissance against Utah water infrastructure with an internet signature linked to Iran, including nearly 500 attempted intrusions within 46 minutes in November 2025. A separate 2026 state audit found Utah drinking-water systems lack foundational cybersecurity protections.

    Activedeseret.com
  53. Aug 14, 2026

    TechCrunch published a recap confirming the US government has still not officially named a culprit, that the campaign has hit water utilities in Minnesota, Arkansas, Georgia, New Jersey, and Michigan, and that no widespread disruption to water supplies has been confirmed.

    Activetechcrunch.com
  54. Aug 13, 2026

    Foreign Policy reported no signs of major disruption or lasting damage to water supplies and said the US government had not formally attributed the attacks.

    Activeforeignpolicy.com
  55. Aug 13, 2026

    KSTP reported that APT IRAN and CyberAv3ngers claimed direct responsibility for the Minnesota attacks. The FBI and Minnesota IT Services said they were aware of the posts but did not confirm the claim. KSTP said local communities had reported no new issues.

    Activekstp.com
  56. Aug 12, 2026

    Rep. Josh Gottheimer said the attacks remained underway. Cape May and Woodbine had regained local control quickly, and water service was not interrupted.

    Activegottheimer.house.gov
  57. Aug 12, 2026

    NPR reported that the FBI investigation remained open. Dragos said it knew of unnamed victims outside the water sector, but gave no count.

    Activenpr.org
  58. Aug 12, 2026

    Detroit Free Press reported that Michigan treatment facilities found their passwords changed during the July attacks. State officials said there were no known public health effects.

    Activefreep.com
  59. Aug 11, 2026

    Newport News Waterworks said it was strengthening safeguards in response to the nationwide attacks. The utility said its controllers were not directly reachable from the internet.

    Activepilotonline.com
  60. Aug 10, 2026

    DEF CON Franklin and the National Rural Water Association launched the Water Watch Center, a program offering free cybersecurity help to small water utilities in response to the ongoing attacks.

    Activedefenseone.com
  61. Aug 10, 2026

    The Washington Post disclosed an affected water utility in western Arkansas and reported that US intelligence agencies were confident the Islamic Revolutionary Guard Corps was responsible, though no formal attribution had been made.

    Activewashingtonpost.com
  62. Aug 9, 2026

    Business Insider reported that the FBI had not identified the attackers or their motive and was tracking incidents reported in at least seven states since July 27.

    Activeyahoo.com
  63. Aug 8, 2026

    NewsNation reported that Clayton County Water Authority restored service within hours after its July attack and that officials had found no impact on drinking-water safety.

    Activeyahoo.com
  64. Aug 7, 2026

    NBC News reported that water utilities are turning to AI tools, volunteers, and smaller cybersecurity firms for help after federal cybersecurity assistance programs were cut, as the attacks continued.

    Activenbcnews.com
  65. Aug 7, 2026

    Cape May and Woodbine, New Jersey confirmed their water systems were targeted in the ongoing wave of attacks.

    Active6abc.com
  66. Aug 7, 2026

    Security researchers at Forescout found that 86 percent of the compromised PLCs across affected cities shared a single mobile carrier network, showing the same internet-exposure flaw repeated across many small utilities in the 12 affected states.

    Activetechtimes.com
  67. Aug 6, 2026

    Forescout research found more than 4,400 Rockwell PLCs exposed online overall, with 22 confirmed exposed in cities hit by the water attacks, and that direct network access alone let attackers change settings without needing to exploit a software flaw.

    Activethehackernews.com
  68. Aug 5, 2026

    Reporting said the water-system attacks linked to Iran had spread to a total of about 12 states, including Michigan, Georgia, and New Jersey, prompting boil-water notices and manual operation at some utilities.

    Activetechtimes.com
  69. Jul 31, 2026

    CISA urged the water sector broadly to take exposed operational technology off the internet, and the FBI and EPA said utilities in at least seven states had reported cyberattacks that week, with the apparent goal of affecting drinking water pressure and safety.

    Activetechtimes.com
  70. Jul 30, 2026

    A leaked Minnesota law enforcement memo pointed to Iran as a suspect in the attacks, though CISA's memo did not present direct evidence of attribution.

    Activewired.com
  71. Jul 27, 2026

    One Minnesota water treatment plant was taken offline and other utilities switched to manual operation as the attack continued.

    Activemsn.com
  72. Jul 26, 2026

    A coordinated cyberattack began hitting more than 30 municipal water utilities across Minnesota over the weekend, exploiting an unpatchable flaw in older PLCs.

    Activemsn.com
  73. Jul 25, 2026

    CISA, FBI, NSA, and the Department of Energy updated the advisory to add Schneider Electric and Siemens equipment to the target list.

    Activesecurityaffairs.com
  74. Jul 19, 2026

    CISA and FBI reporting describes the campaign hitting Rockwell Automation PLCs across water, energy, and government facilities.

    Activecybersecuritynews.com
  75. Mar 1, 2026

    Federal agencies say Iranian-affiliated actors began disrupting internet-exposed PLCs at US critical infrastructure sites.

    Activesecurityaffairs.com

Sources

Related reports