Suspected Iranian hackers hit US water utilities
Starting July 26, 2026, hackers breached more than 30 water utility systems in Minnesota, with related activity reported in water systems across roughly a dozen other states by mid-August. On August 26, 2026, CISA said in a joint advisory with the NSA, FBI, DOE, and EPA that the intrusions had actually targeted more than 100 internet-exposed water and wastewater systems nationwide, though it stopped short of formally blaming any country. Investigators believe Iran-linked hackers, possibly the group CyberAv3ngers, exploited an unpatchable flaw in internet-exposed programmable logic controllers, forcing at least one treatment plant offline and pushing others to manual operation. NBC News reported September 2-3, 2026 that the same Iran-linked activity has expanded into ongoing probing of US energy, telecom, and government networks.
- Started
- Jul 26, 2026
- Latest activity
- Sep 10, 2026
- Attributed to
- CyberAv3ngers (Iran-linked, suspected)Suspected
- Where
- United States
- Sectors
- Water, Energy, Government
- Scale
- More than 30 water utilities in Minnesota, with related water-system incidents reported in at least seven to a dozen states
Current status
On September 10, the White House said its Texas water-security pilot would expand to other sectors and nationwide; no new intrusion, restoration, or closure was reported.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
No named government agency or the victims themselves have issued a formal public attribution of the water utility intrusions to Iran; US officials have said they believe Iran is likely responsible.
Impact
Attackers gained access to internet-exposed industrial controllers, changed control logic, and altered what operators saw on their screens, making abnormal behavior harder to spot; at least one Minnesota treatment plant was taken offline and several utilities switched to manual operation. On August 26, 2026, CISA said the intrusions had targeted more than 100 internet-exposed water and wastewater systems in total, but said the attacks have had little effect on the water actually delivered to communities, mainly causing outages and disruption while responders investigate. A September 10 response update announced broader security support, but confirmed no new water-system outages, plant shutdowns, or restorations.
What to do
Water utility IT and OT staff should take internet-exposed PLCs offline or restrict remote access immediately, change default passwords, block TCP port 102 at the network perimeter, route remote access through a VPN or secure gateway, and follow CISA guidance for securing industrial control systems. Project Watershed 250 will give participating Texas utilities free security testing and support from firms including Microsoft, Dragos, Fortinet, Palo Alto Networks, Zscaler, Forescout, and Tenable during a six-month pilot. The White House said on September 10 that the approach would expand nationwide, but gave no rollout date.
Timeline
-
Sep 10, 2026
National Cyber Director Sean Cairncross said the White House plans to apply the Texas Project Watershed 250 water-security pilot to other critical infrastructure sectors. He did not identify the sectors or give a launch date. No new water-system victim, outage, or restoration was reported.
Activenextgov.com -
Sep 9, 2026
The Telegram channel APT IRAN, which reporting links to CyberAv3ngers, claimed it caused a North Texas AT&T outage that left thousands of customers without internet, TV, or phone service, and said further attacks on US infrastructure were planned before September 11; AT&T said the outage was caused by a fiber problem, not a cyberattack, and no independent confirmation of a hack was found.
Activechron.com -
Sep 3, 2026
OpenAI announced a $1 billion commitment of subsidized access to its AI cybersecurity tools, including a Daybreak platform for frontline defenders, aimed partly at water utilities, power grid operators, and local governments with limited security budgets; the announcement was a general sector-support initiative and was not described as a direct response to the Minnesota water utility intrusions.
Activereuters.com -
Sep 3, 2026
The US State Department Rewards for Justice program offered up to $10 million for information on Amir Yaryab, who it says leads the Iranian Revolutionary Guard Cyber-Electronic Command unit controlling CyberAv3ngers and several other hacking groups; the announcement described those groups as targeting defense, shipping, travel, energy, financial, and telecom systems in the US, Europe, and the Middle East, but did not specifically name the water utility intrusions or issue a formal government attribution for them.
Activearabtimesonline.com -
Sep 3, 2026
Follow-up coverage of the NBC News reporting said CyberAv3ngers has compromised at least 75 US automation devices since 2023, that recent probing attempts have been unsuccessful, and that officials assess the activity as geopolitical signaling rather than an attempt at mass disruption, with no water contamination or sustained outages reported.
Activegadgetreview.com -
Sep 2, 2026
NBC News reported, citing four people with access to government and industry threat information, that Iran-linked groups have probed US water, energy, telecommunications, and government networks in a campaign that accelerated through mid-2026, and that a Telegram channel calling itself APT IRAN threatened 'unexpected and critical events' against US infrastructure, though no evidence of a successful operation behind that claim was found.
Activemsn.com -
Sep 1, 2026
Follow-up coverage of the Project Watershed 250 launch ceremony in San Antonio named the participating cybersecurity firms as Microsoft, Dragos, Fortinet, Palo Alto Networks, Zscaler, Forescout, and Tenable, with Texas Cyber Command coordinating the effort; no new victims or recovery milestones were reported.
Activekxan.com -
Aug 31, 2026
The White House launched Project Watershed 250, a six-month Texas pilot that will give participating water utilities no-cost security testing and support from federal, state, and private partners. A White House official said the program was not launched in response to the Minnesota attacks, and the report named no new victims or recovery milestone.
Activefoxnews.com -
Aug 29, 2026
An analysis piece explained the CISA/NSA/FBI/DOE/EPA advisory (AA26-231A) on Siemens S7-series PLCs in more detail, saying attackers use AI-generated Python scripts wrapping the snap7 library to scan for and interact with exposed controllers, and that this is characterized as reconnaissance and capability development with no confirmed process-disruption incidents reported since the August intrusions; the advisory did not name any threat actor.
Activeforkast.news -
Aug 28, 2026
Newsweek reported that national security analysts and a former DHS official warned Iran could use cyberattacks, including further strikes on U.S. water and power infrastructure, as an asymmetric tactic tied to its broader conflict with the U.S. and Israel, though the article described this as a risk assessment rather than reporting any new intrusion.
Activenewsweek.com -
Aug 27, 2026
A security analysis citing a joint CISA, NSA, FBI, DOE, and EPA advisory said attackers are now using AI-generated exploitation scripts along with open-source snap7 libraries to read and write data on internet-exposed Siemens S7 series PLCs, and that thousands of similar controllers from Siemens, Rockwell/Allen-Bradley, and Schneider Electric remain reachable from the internet nationwide; officials still had not formally attributed the campaign to any country.
Activeyahoo.com -
Aug 26, 2026
Politico and Nextgov reported the White House, through the Office of the National Cyber Director, plans to launch a program enlisting private cybersecurity firms to help water utilities with few resources improve their defenses, possibly announced the following week and piloted in Texas.
Activenextgov.com -
Aug 26, 2026
Reuters reported that a separate ransomware group calling itself Barracuda claimed a data breach at Micro-Comm, a small Kansas maker of water-system programmable logic controllers, but the FBI and the company said this breach was not connected to the suspected Iranian campaign against Minnesota and other states' water utilities.
Activereuters.com -
Aug 26, 2026
CISA said in an advisory that hackers had targeted more than 100 internet-exposed water and wastewater systems in the July intrusions, a larger scope than the more than 30 Minnesota utilities first reported, and said senior officials believe Iran is likely responsible but have not made a formal attribution.
Activetechcrunch.com -
Aug 25, 2026
The US Treasury Department sanctioned five Iranian nationals for a broader, separate Iran-linked hacking and data-theft campaign tied to Iran's Ministry of Intelligence and Security; the same report said CISA and the FBI have recently been helping water utilities in at least 12 states recover from the cyberattacks, but noted CISA has not publicly attributed those water intrusions to Iran.
Activedefenseone.com -
Aug 25, 2026
A former acting Principal Deputy National Cyber Director, Jake Braun, told Newsweek that Iran-linked attacks on US critical infrastructure are likely to continue and increase in severity, citing the UK plant incident as a sign of intent; no new intrusions or victims were reported.
Activeyahoo.com -
Aug 24, 2026
UK Energy Minister Michael Shanks was named publicly confirming the power-plant shutdown, describing the generator as tiny and isolated and stating there was no threat to the wider grid and nobody lost power.
Activefoxnews.com -
Aug 24, 2026
The UK government briefed energy company CEOs on protective steps after media reports of the Iran-linked power plant hack, confirming the cyberattack occurred but stating it posed no risk to the wider electricity system and stopping short of officially blaming Iran.
Activemsn.com -
Aug 23, 2026
Iran-linked hackers, named in press reports as CyberAv3ngers, were blamed for a four-day shutdown of a small UK power plant, with reporting describing it as part of the same wider wave of Iran-linked attacks that includes the still-active US water utility intrusions; no official closure or restoration announcement was found for the US water incidents themselves.
Activetheguardian.com -
Aug 21, 2026
New reporting said Iranian-backed hackers were using AI-generated exploitation tools against vulnerable Siemens PLCs in water systems nationwide.
Activeforbes.com -
Aug 1, 2026
CBS News reported investigators were probing whether Iranian hackers were behind activity affecting water systems in seven states, with formal attribution still pending.
Activecbsnews.com -
Jul 31, 2026
Minnesota officials said the source of the attacks was still being confirmed as water systems in multiple states reported similar activity.
Activewnem.com -
Jul 29, 2026
Investigators said the attackers exploited an unpatchable flaw to breach more than 30 Minnesota water systems, shutting down one plant and forcing manual operation elsewhere.
Activetechtimes.com -
Jul 27, 2026
Reports emerged that Iranian-affiliated hackers were accessing internet-exposed PLCs at US water, energy, and government sites and altering operator screens.
Emergingcybersecuritynews.com
Sources
- Iranian attackers disable US safety alarms in industrial systems Cyber Security News Jul 27, 2026
- Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems Tech Times Jul 29, 2026
- Officials warn about Iranian hackers as they investigate cyberattacks on Minnesota water systems WNEM-TV (AP) Jul 31, 2026
- Investigators believe Iranian hackers are likely behind cyberattack on Minnesota water systems: report Yahoo News Jul 31, 2026
- A brief timeline of Iranian cyberattacks on U.S. companies, political figures, water systems and more CBS News Aug 1, 2026
- Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water and Energy Tech Times Aug 20, 2026
- AI-Powered Iranian Cyberattacks Threaten Critical Infrastructure Forbes Aug 21, 2026 unverified
- Iran-linked hackers blamed for cyber-attack that shut down UK power plant The Guardian Aug 23, 2026
- Sources: Iran-linked hackers shut down a small UK power plant for four days, coinciding with a wave of Iran-affiliated attacks on US water utilities Techmeme Aug 23, 2026
- What we know so far about the hacking campaign against US water systems Yahoo News Aug 20, 2026
- A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran Wired Aug 14, 2026
- What we know about the alleged Iranian hacks on US water utilities TechCrunch Aug 14, 2026
- Report: Utah among 12 states whose water infrastructure was targeted by Iran Yahoo News Aug 17, 2026
- UK energy firms briefed after suspected Iran-linked power plant hack Financial Times Aug 23, 2026 unverified
- UK briefs energy chiefs after Iran-linked cyber attack reports Reuters via MSN Aug 24, 2026
- Iran-linked hackers shut down UK power plant for four days: report Moneycontrol Aug 23, 2026 unverified
- Government says no risk to wider energy system after small-scale site attacked Sky News Aug 23, 2026 unverified
- Mapping Iranian Cyberattacks on US Water Systems CSIS Aug 18, 2026
- Iran-Linked Cyberattack Tests Britain's Energy Defenses OilPrice.com Aug 24, 2026
- Iran-linked hackers suspected in UK power-plant shutdown after alleged Minnesota water attack Fox News Aug 24, 2026
- Ex-White House adviser sounds alarm over Iran's growing cyber war on US Newsweek (via Yahoo) Aug 25, 2026
- Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant Infosecurity Magazine Aug 24, 2026
- Treasury sanctions Iranian hackers tied to critical-infrastructure breaches Defense One / Nextgov-FCW Aug 25, 2026
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure The Hacker News Aug 20, 2026
Related reports
- Minnesota water systems hit by ransomware Jul 31, 2026
- Minnesota water systems hit by PLC cyberattacks Jul 29, 2026
- Iran-linked attackers disable industrial safety alarms Jul 27, 2026
- Iran-linked attackers disrupt U.S. water, energy, and government systems Jul 19, 2026
- Minnesota water systems hit by cyberattack Jul 12, 2026
- Cyber Av3ngers hacking U.S. power plants and water systems Jul 10, 2026