Iran-linked hackers disrupt US water and energy PLCs
US agencies warned that Iran-affiliated hackers targeted internet-connected industrial controllers at water, energy, telecommunications, government, and other critical facilities. More than 100 US water systems were targeted in July. Recent attempts against US infrastructure were reportedly unsuccessful. APT IRAN claimed responsibility for a Texas AT&T outage, but AT&T blamed attempted cable theft.
- Started
- Mar 1, 2026
- Latest activity
- Sep 9, 2026
- Attributed to
- CyberAv3ngers and APT IRANLikely
- Where
- United States
- Sectors
- Water, Energy, Government
- Scale
- CISA said more than 100 internet-exposed water and wastewater systems were targeted in July.
Current status
On September 9, AT&T said the Texas outage was caused by attempted cable theft, while APT IRAN claimed responsibility and threatened further attacks.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
No US agency has publicly confirmed the campaign's attribution. APT IRAN's claims remain unverified, and AT&T denied that its Texas outage was a cyberattack.
Impact
Attackers remotely accessed internet-facing industrial controllers and changed device settings, network addresses, and passwords. Some facilities lost monitoring or control, causing pressure drops, flooding, manual operation, or temporary shutdowns. No widespread water-safety impact has been confirmed.
What to do
Operators should remove industrial controllers from direct internet access, especially those reachable through cellular modems, and place them behind secure gateways or firewalls. They should restrict remote access, check logs for suspicious traffic on ports 502, 102, 2222, and 44818, change default passwords, apply patches, and prepare manual controls for pumps, pressure, and chemical dosing. CISA also advises searching for exposed assets through vendors, contractors, and legacy infrastructure.
Timeline
-
Sep 9, 2026
AT&T said it found no evidence that the Texas outage was a cyberattack and attributed it to attempted cable theft. Service was restored.
Activefox4news.com -
Sep 9, 2026
APT IRAN claimed responsibility for a multi-hour AT&T internet outage in parts of Texas and threatened further attacks, but the claim was not verified.
Activethreatbeat.com -
Sep 9, 2026
APT IRAN claimed responsibility for a Texas AT&T outage and said it targeted telecommunications and an unknown Texas water utility. AT&T said it found no evidence of a cyberattack and attributed the outage to attempted cable theft. The outage was resolved.
Activechron.com -
Sep 5, 2026
New Hampshire's Department of Environmental Services said it knows of no impact to the state's own water systems from the nationwide campaign, even as it and other states continue to treat cybersecurity as a growing operational challenge for water suppliers.
Activeeagletribune.com -
Sep 5, 2026
New Hampshire's Department of Environmental Services said it is not aware of any impact to the state's water systems from the campaign.
Activenhpr.org -
Sep 5, 2026
New Hampshire's Department of Environmental Services said it is not aware of any impact to New Hampshire water systems from the broader campaign, even as the state's utilities continue to prepare defenses.
Activenhpr.org -
Sep 4, 2026
Forescout announced that it joined Project Watershed 250 to provide cyber defense resources to Texas water utilities.
Activefinance.yahoo.com -
Sep 3, 2026
A report citing NBC News said Iranian-affiliated groups had probed US water, energy, telecom, and government targets, with recent attempts unsuccessful and at least 75 automation devices compromised since 2023.
Activegadgetreview.com -
Sep 3, 2026
Recap coverage of the NBC report added that CyberAv3ngers, the Iran-linked group, is assessed to have compromised at least 75 automation devices in US critical infrastructure since 2023, and that US officials view the water-system intrusions as geopolitical signaling rather than an attempt at mass disruption.
Activegadgetreview.com -
Sep 3, 2026
Follow-up reporting described the hackers as still using basic techniques, probing exposed industrial controls on US water and energy systems across at least seven states, with no new confirmed disruption reported.
Activeyahoo.com -
Sep 2, 2026
NBC News reported that Iranian hackers had recently attempted attacks against US water, telecommunications, energy, and other infrastructure. Sources said the attempts were unsuccessful.
Activenbcnews.com -
Sep 2, 2026
NBC News reported, citing four people with access to government and industry threat information, that Iranian-affiliated hackers have also probed US telecommunications, energy, and government networks in recent weeks; the attempts have so far been unsuccessful. A Telegram channel calling itself APT IRAN separately threatened 'unexpected and critical events' against US infrastructure, with no evidence yet of a successful operation behind the claim.
Activenbcnews.com -
Sep 2, 2026
NBC News reported that Iranian hackers, or actors from the same campaign, had also made unsuccessful attempts against US telecommunications and energy targets, and that an Iranian hacking group posted a Telegram warning of coming 'unexpected and critical events' against American infrastructure.
Activenbcnews.com -
Sep 2, 2026
NBC News reported that Iranian hackers have targeted US telecommunications, energy, and other infrastructure beyond water systems in recent weeks, with attempts so far unsuccessful, and that an Iranian hacking group posted on Telegram warning of coming 'unexpected and critical events' against American infrastructure.
Activenbcnews.com -
Sep 2, 2026
An Iranian hacking group posted on a Telegram channel warning that it would target US energy, water, and telecommunications sectors, saying prior warnings had been ignored and that "unexpected and critical events" would follow.
Activemediaite.com -
Sep 2, 2026
NBC News reported that Iranian hackers have targeted US telecommunications, energy, and other infrastructure beyond water systems in recent weeks, citing four people with access to government and industry cyberthreat information; the attempts have so far been unsuccessful.
Activenbcnews.com -
Sep 2, 2026
NBC News reported, citing four people with access to government and industry threat information, that Iranian-linked hackers have continued attempting cyberattacks on US water, telecommunications, energy, and other infrastructure in recent weeks, with the attempts unsuccessful so far.
Activenbcnews.com -
Sep 1, 2026
The Environmental Protection Agency announced nearly $12 million for water-system cybersecurity and resilience in 10 cities, while Texas began its water-security pilot.
Activeyahoo.com -
Sep 1, 2026
Texas Governor Greg Abbott and the White House launched Project Watershed 250, a federal-state pilot pairing AI security tools with Texas water systems to find and fix cyber vulnerabilities before further attacks.
Activeyahoo.com -
Sep 1, 2026
Cybersecurity vendor Abnormal AI said it was joining Project Watershed 250 to provide added protection for Texas water utilities under the public-private pilot.
Activefinance.yahoo.com -
Aug 31, 2026
Texas and the White House launched Project Watershed 250, a pilot offering free cyber defense resources to Texas water utilities.
Activegov.texas.gov -
Aug 31, 2026
Texas announced Project Watershed 250, a six-month pilot with the Trump administration, Texas Cyber Command, and private companies including Microsoft, pairing AI and cybersecurity tools with Texas water systems; officials said it was not created specifically in response to the Minnesota attacks.
Activeyahoo.com -
Aug 31, 2026
CISA and the FBI still had not publicly attributed the July water-sector intrusions to any named group or country and did not respond to questions about attribution, GovInfoSecurity reported.
Activegovinfosecurity.com -
Aug 31, 2026
The White House Office of the National Cyber Director and Texas Governor Greg Abbott launched Project Watershed 250, a six-month pilot in San Antonio giving Texas water utilities free cybersecurity assessments and AI-enabled monitoring tools, in direct response to the ongoing suspected Iran-linked campaign.
Activeyahoo.com -
Aug 31, 2026
The Trump administration, Texas Governor Greg Abbott's office, and the Texas Cyber Command formally launched Project Watershed 250, a six-month water-sector cybersecurity pilot in San Antonio with the EPA, CISA, and private firms including Microsoft, Dragos, and Palo Alto Networks, aimed at finding and fixing vulnerabilities in water systems and eventually expanding the model nationwide. Officials said the water systems affected by the earlier attacks continued operating safely with no known public health effects.
Activenextgov.com -
Aug 30, 2026
After the US struck Iranian rocket launchers near the Strait of Hormuz and Iran fired missiles and drones at bases in Jordan and the UAE, ending a monthlong lull in the conflict, a Telegram channel calling itself APT IRAN warned of unexpected and critical events targeting US energy, water, and telecom systems, and said only six states, not the roughly 12 reported by officials, were hit in the July water attacks.
Activegovinfosecurity.com -
Aug 28, 2026
Britain's NCSC told all organizations to check for operational-technology vulnerabilities, citing recent disruptive cyber activity connected to the wider suspected Iran-linked campaign against industrial control systems.
Activecomputing.co.uk -
Aug 28, 2026
The Telegraph reported that Britain's water industry was placed on alert. The NCSC said it had seen increased targeting of industrial control systems across several sectors worldwide, including in the UK, but did not name an attacker.
Activeyahoo.com -
Aug 28, 2026
Britain's water industry was placed on high alert after the earlier reported Iran-linked shutdown of a small UK power plant, joining the UK energy sector, which had been placed on alert days earlier.
Activeyahoo.com -
Aug 28, 2026
Britain's water industry was put on high alert over suspected Iran-linked hacking activity, extending a warning first issued to UK energy companies after a small UK power plant was forced offline for four days; no new US water or energy victims were reported.
Activeyahoo.com -
Aug 28, 2026
An NBC Chicago investigation reported that federal law enforcement officials suggested Iranian hackers targeted pump routing devices at the James W. Jardine Water Purification Plant, the world's largest conventional drinking water plant, during last month's campaign. Chicago's water department said the attempt did not succeed, no ransom was paid, and treatment operations were never affected. The report separately noted an unrelated ransomware attack a year earlier locked the department's front-office computers for two months.
Activenbcchicago.com -
Aug 27, 2026
Chicago water officials said the Jardine water plant had blocked the latest intrusion attempt. The utility said it had changed factory passwords and was monitoring and updating them.
Activenbcchicago.com -
Aug 27, 2026
NBC Chicago's investigative team toured the Jardine water plant, the world's largest, and reported that Iranian-linked hackers had accessed pump routing devices at some breached facilities where factory-default passwords were never changed; Chicago officials said their own passwords were not default and are constantly monitored, and the plant was not breached.
Activenbcchicago.com -
Aug 27, 2026
NBC Chicago aired a follow-up investigation in which Chicago Water Commissioner Randy Conner said the city's Jardine filtration plant, the world's largest, raised its alert level after the nationwide water-utility attacks but that its defenses held; Conner separately disclosed an unrelated ransomware attack on the utility's administrative computers about a year earlier that locked front-office systems for two months without touching plant controls.
Activenbcchicago.com -
Aug 26, 2026
The Register quoted cybersecurity analysts saying the more-than-100-victim count shows a systemic vulnerability across small water utilities, while noting the federal government still has not formally attributed the campaign to Iran or any group.
Activetheregister.com -
Aug 26, 2026
Reuters reported the FBI and CISA are investigating a separate July breach at Micro-Comm, a small Kansas maker of water-system PLCs, claimed by a profit-motivated ransomware group called Barracuda; the company and outside coverage said this incident appears unrelated to the suspected Iranian campaign against water utilities.
Activenypost.com -
Aug 25, 2026
GovInfoSecurity reported that utilities or state agencies in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed they were among those hit, and that CISA still has not attributed the July activity to any government or group.
Activegovinfosecurity.com -
Aug 25, 2026
CISA published new guidance saying it observed more than 100 internet-exposed water and wastewater systems targeted in cyberattacks throughout July, hit most commonly through PLCs connected directly to a cellular modem, and gave a four-step process for utilities to find and reduce internet exposure.
Activegovinfosecurity.com -
Aug 25, 2026
Recap coverage of the July UK power plant outage said attackers reportedly targeted the plant's PLC and its backup power failover systems, that the UK government confirmed the incident but has not formally blamed Iran, and that no new US water or energy victims have been reported.
Activeyahoo.com -
Aug 25, 2026
The US Treasury Department sanctioned five Iranian nationals over a separate hacking and cryptocurrency-theft campaign against US energy companies, defense contractors, health care institutions, tech firms, financial institutions, and government offices dating to late 2023 and 2024. Treasury said CISA has not publicly attributed the water utility intrusions covered in this incident to Iran.
Activenextgov.com -
Aug 24, 2026
Further recap coverage described the UK incident as testing Britain's energy defenses against hostile-state cyber threats; no new US water or energy victims were reported.
Activeoilprice.com -
Aug 23, 2026
Follow-up coverage of the UK power plant shutdown continued, with reports noting UK officials said the country's wider electrical supply was never at risk even though the small plant was offline for four days.
Activenypost.com -
Aug 22, 2026
The Telegraph reported, citing sources, that Iran-linked hackers shut down a small UK power plant for four days, an incident described by other outlets as coinciding with the wave of Iran-affiliated attacks on US water utilities; this is a separate UK facility, not a confirmed part of the US water/energy campaign's victim count.
Activemiddleeasteye.net -
Aug 21, 2026
Forbes published a recap of the AA26-231A advisory warning that AI-generated exploit code is being used against Siemens controllers, with no new victims or attribution named.
Activeforbes.com -
Aug 20, 2026
AP recapped the campaign in a 'what we know so far' explainer, noting the government still had not formally attributed the attacks and no new US victims had been confirmed.
Activeyahoo.com -
Aug 20, 2026
Follow-up coverage of the AA26-231A advisory continued, recapping the AI-generated Siemens PLC exploit warning; no new victims, attribution, or closure were reported.
Activetechtimes.com -
Aug 19, 2026
Cybersecurity experts told GovInfoSecurity that more than three weeks after the July water-utility intrusions, they still cannot explain why attackers with full access to PLCs changed passwords and disabled alerts but did not attempt to damage pumps, burst pipes, or alter chemical treatment levels, and noted no destructive Iranian information-operation campaign accompanied the intrusions.
Activegovinfosecurity.com -
Aug 19, 2026
CISA, the FBI, NSA, the Department of Energy, and the EPA published advisory AA26-231A, the first government OT advisory to state that threat actors are using AI to write functional exploit scripts, in this case against internet-exposed Siemens S7 Series PLCs found via Censys and ZoomEye scans on port 102.
Activecisa.gov -
Aug 19, 2026
CISA, the FBI, and partner agencies issued a joint advisory warning that threat actors are using AI to generate exploitation scripts and evasion tools against internet-exposed Siemens S7 Series PLCs in water, energy, manufacturing, and food and agriculture facilities, calling this likely linked to the broader suspected-Iranian campaign but stopping short of formal attribution.
Activeinfosecurity-magazine.com -
Aug 18, 2026
The Christian Science Monitor reported the individual water utility attacks from the prior month were resolved quickly, but the incidents, only possibly linked to Iranian actors, exposed lasting cybersecurity gaps at small and rural utilities with limited resources.
Activecsmonitor.com -
Aug 16, 2026
The Atlantic reported that the Trump administration had not confirmed Iran's role, disclosed a full victim count, or said whether other breaches had occurred. The report named no new victims and gave no closure date.
Activetheatlantic.com -
Aug 14, 2026
Deseret News reported that Utah is among the roughly 12 affected states, citing an intelligence note reviewed by ABC News describing targeted reconnaissance against Utah water infrastructure with an internet signature linked to Iran, including nearly 500 attempted intrusions within 46 minutes in November 2025. A separate 2026 state audit found Utah drinking-water systems lack foundational cybersecurity protections.
Activedeseret.com -
Aug 14, 2026
TechCrunch published a recap confirming the US government has still not officially named a culprit, that the campaign has hit water utilities in Minnesota, Arkansas, Georgia, New Jersey, and Michigan, and that no widespread disruption to water supplies has been confirmed.
Activetechcrunch.com -
Aug 13, 2026
Foreign Policy reported no signs of major disruption or lasting damage to water supplies and said the US government had not formally attributed the attacks.
Activeforeignpolicy.com -
Aug 13, 2026
KSTP reported that APT IRAN and CyberAv3ngers claimed direct responsibility for the Minnesota attacks. The FBI and Minnesota IT Services said they were aware of the posts but did not confirm the claim. KSTP said local communities had reported no new issues.
Activekstp.com -
Aug 12, 2026
Rep. Josh Gottheimer said the attacks remained underway. Cape May and Woodbine had regained local control quickly, and water service was not interrupted.
Activegottheimer.house.gov -
Aug 12, 2026
NPR reported that the FBI investigation remained open. Dragos said it knew of unnamed victims outside the water sector, but gave no count.
Activenpr.org -
Aug 12, 2026
Detroit Free Press reported that Michigan treatment facilities found their passwords changed during the July attacks. State officials said there were no known public health effects.
Activefreep.com -
Aug 11, 2026
Newport News Waterworks said it was strengthening safeguards in response to the nationwide attacks. The utility said its controllers were not directly reachable from the internet.
Activepilotonline.com -
Aug 10, 2026
DEF CON Franklin and the National Rural Water Association launched the Water Watch Center, a program offering free cybersecurity help to small water utilities in response to the ongoing attacks.
Activedefenseone.com -
Aug 10, 2026
The Washington Post disclosed an affected water utility in western Arkansas and reported that US intelligence agencies were confident the Islamic Revolutionary Guard Corps was responsible, though no formal attribution had been made.
Activewashingtonpost.com -
Aug 9, 2026
Business Insider reported that the FBI had not identified the attackers or their motive and was tracking incidents reported in at least seven states since July 27.
Activeyahoo.com -
Aug 8, 2026
NewsNation reported that Clayton County Water Authority restored service within hours after its July attack and that officials had found no impact on drinking-water safety.
Activeyahoo.com -
Aug 7, 2026
NBC News reported that water utilities are turning to AI tools, volunteers, and smaller cybersecurity firms for help after federal cybersecurity assistance programs were cut, as the attacks continued.
Activenbcnews.com -
Aug 7, 2026
Cape May and Woodbine, New Jersey confirmed their water systems were targeted in the ongoing wave of attacks.
Active6abc.com -
Aug 7, 2026
Security researchers at Forescout found that 86 percent of the compromised PLCs across affected cities shared a single mobile carrier network, showing the same internet-exposure flaw repeated across many small utilities in the 12 affected states.
Activetechtimes.com -
Aug 6, 2026
Forescout research found more than 4,400 Rockwell PLCs exposed online overall, with 22 confirmed exposed in cities hit by the water attacks, and that direct network access alone let attackers change settings without needing to exploit a software flaw.
Activethehackernews.com -
Aug 5, 2026
Reporting said the water-system attacks linked to Iran had spread to a total of about 12 states, including Michigan, Georgia, and New Jersey, prompting boil-water notices and manual operation at some utilities.
Activetechtimes.com -
Jul 31, 2026
CISA urged the water sector broadly to take exposed operational technology off the internet, and the FBI and EPA said utilities in at least seven states had reported cyberattacks that week, with the apparent goal of affecting drinking water pressure and safety.
Activetechtimes.com -
Jul 30, 2026
A leaked Minnesota law enforcement memo pointed to Iran as a suspect in the attacks, though CISA's memo did not present direct evidence of attribution.
Activewired.com -
Jul 27, 2026
One Minnesota water treatment plant was taken offline and other utilities switched to manual operation as the attack continued.
Activemsn.com -
Jul 26, 2026
A coordinated cyberattack began hitting more than 30 municipal water utilities across Minnesota over the weekend, exploiting an unpatchable flaw in older PLCs.
Activemsn.com -
Jul 25, 2026
CISA, FBI, NSA, and the Department of Energy updated the advisory to add Schneider Electric and Siemens equipment to the target list.
Activesecurityaffairs.com -
Jul 19, 2026
CISA and FBI reporting describes the campaign hitting Rockwell Automation PLCs across water, energy, and government facilities.
Activecybersecuritynews.com -
Mar 1, 2026
Federal agencies say Iranian-affiliated actors began disrupting internet-exposed PLCs at US critical infrastructure sites.
Activesecurityaffairs.com
Sources
- Iran-linked attackers disrupting US water and energy systems SecurityAffairs Jul 25, 2026
- Iran-linked attackers disrupt U.S. water, energy, and government systems Cyber Security News Jul 19, 2026
- US government says Iran-linked hackers are disrupting American water and energy providers TechCrunch Jul 23, 2026
- Iranian hackers exploited unpatchable PLC flaw to breach 30 Minnesota water systems Tech Times (via MSN) Jul 29, 2026
- CISA urges water utilities to take exposed systems down after Minnesota hacks Nextgov/FCW Jul 31, 2026
- FBI: Water Hacks in Seven States Aimed at Contaminating Drinking Supplies Tech Times Jul 31, 2026
- A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran Wired Jul 30, 2026
- Water Utilities Hacked Across 12 States Cannot Secure What They Cannot See Tech Times Aug 7, 2026
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities The Hacker News Aug 6, 2026
- Water industry turns to AI and hackers for help after suspected Iran cyberattacks NBC News Aug 7, 2026
- Cape May, Woodbine targeted in water system hack 6abc Aug 7, 2026
- Trump blames Minnesota, not Iran, for cyberattack on water systems The Washington Post Jul 31, 2026 unverified
- Metro Atlanta water system hit by cyberattack possibly linked to Iran The Atlanta Journal-Constitution Aug 4, 2026
- Hackers are targeting US water systems. Here's what that means. Business Insider Aug 9, 2026
- US water systems in 12 states targeted in wave of cyberattacks NewsNation Aug 8, 2026 unverified
- US water systems in 12 states targeted in wave of cyberattacks NewsNation via Yahoo News Aug 8, 2026
- Hackers are targeting US water systems. Here's what that means. Business Insider via Yahoo News Aug 9, 2026
- Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks The Washington Post Aug 10, 2026 unverified
- Newport News Waterworks moves to upgrade security amid nationwide cyberattacks The Virginian-Pilot Aug 11, 2026
- Slotkin reveals how water system cyberattack hit Michigan. What she said Detroit Free Press Aug 12, 2026
- Are hacks of U.S. water facilities a new front in the Iran war? NPR Aug 12, 2026 unverified
- After Attacks in Jersey, Gottheimer Announces Bipartisan Federal Actions to Protect Water, Electric Systems, and Families from Cyber Attacks Office of Rep. Josh Gottheimer Aug 12, 2026
- Hacking group linked to Iran claims responsibility for cyberattack on Minnesota water systems, report says KSTP-TV Aug 13, 2026
- Why Hackers Keep Going After U.S. Water Supplies Foreign Policy Aug 13, 2026
Related reports
- Minnesota water systems hit by ransomware Jul 31, 2026
- Minnesota water systems hit by PLC cyberattacks Jul 29, 2026
- Iran-linked attackers disrupt U.S. water, energy, and government systems Jul 19, 2026
- Minnesota water systems hit by cyberattack Jul 12, 2026
- Cyber Av3ngers hacking U.S. power plants and water systems Jul 10, 2026