Active High impact Industrial control systems Checked 8h ago

Suspected Iranian hackers hit US water utilities

Starting July 26, 2026, hackers breached more than 30 water utility systems in Minnesota, with related activity reported in water systems across roughly a dozen other states by mid-August. On August 26, 2026, CISA said in a joint advisory with the NSA, FBI, DOE, and EPA that the intrusions had actually targeted more than 100 internet-exposed water and wastewater systems nationwide, though it stopped short of formally blaming any country. Investigators believe Iran-linked hackers, possibly the group CyberAv3ngers, exploited an unpatchable flaw in internet-exposed programmable logic controllers, forcing at least one treatment plant offline and pushing others to manual operation. NBC News reported September 2-3, 2026 that the same Iran-linked activity has expanded into ongoing probing of US energy, telecom, and government networks.

Started
Jul 26, 2026
Latest activity
Sep 10, 2026
Attributed to
CyberAv3ngers (Iran-linked, suspected)Suspected
Where
United States
Sectors
Water, Energy, Government
Scale
More than 30 water utilities in Minnesota, with related water-system incidents reported in at least seven to a dozen states

Current status

On September 10, the White House said its Texas water-security pilot would expand to other sectors and nationwide; no new intrusion, restoration, or closure was reported.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

No named government agency or the victims themselves have issued a formal public attribution of the water utility intrusions to Iran; US officials have said they believe Iran is likely responsible.

Impact

Attackers gained access to internet-exposed industrial controllers, changed control logic, and altered what operators saw on their screens, making abnormal behavior harder to spot; at least one Minnesota treatment plant was taken offline and several utilities switched to manual operation. On August 26, 2026, CISA said the intrusions had targeted more than 100 internet-exposed water and wastewater systems in total, but said the attacks have had little effect on the water actually delivered to communities, mainly causing outages and disruption while responders investigate. A September 10 response update announced broader security support, but confirmed no new water-system outages, plant shutdowns, or restorations.

What to do

Water utility IT and OT staff should take internet-exposed PLCs offline or restrict remote access immediately, change default passwords, block TCP port 102 at the network perimeter, route remote access through a VPN or secure gateway, and follow CISA guidance for securing industrial control systems. Project Watershed 250 will give participating Texas utilities free security testing and support from firms including Microsoft, Dragos, Fortinet, Palo Alto Networks, Zscaler, Forescout, and Tenable during a six-month pilot. The White House said on September 10 that the approach would expand nationwide, but gave no rollout date.

Timeline

  1. Sep 10, 2026

    National Cyber Director Sean Cairncross said the White House plans to apply the Texas Project Watershed 250 water-security pilot to other critical infrastructure sectors. He did not identify the sectors or give a launch date. No new water-system victim, outage, or restoration was reported.

    Activenextgov.com
  2. Sep 9, 2026

    The Telegram channel APT IRAN, which reporting links to CyberAv3ngers, claimed it caused a North Texas AT&T outage that left thousands of customers without internet, TV, or phone service, and said further attacks on US infrastructure were planned before September 11; AT&T said the outage was caused by a fiber problem, not a cyberattack, and no independent confirmation of a hack was found.

    Activechron.com
  3. Sep 3, 2026

    OpenAI announced a $1 billion commitment of subsidized access to its AI cybersecurity tools, including a Daybreak platform for frontline defenders, aimed partly at water utilities, power grid operators, and local governments with limited security budgets; the announcement was a general sector-support initiative and was not described as a direct response to the Minnesota water utility intrusions.

    Activereuters.com
  4. Sep 3, 2026

    The US State Department Rewards for Justice program offered up to $10 million for information on Amir Yaryab, who it says leads the Iranian Revolutionary Guard Cyber-Electronic Command unit controlling CyberAv3ngers and several other hacking groups; the announcement described those groups as targeting defense, shipping, travel, energy, financial, and telecom systems in the US, Europe, and the Middle East, but did not specifically name the water utility intrusions or issue a formal government attribution for them.

    Activearabtimesonline.com
  5. Sep 3, 2026

    Follow-up coverage of the NBC News reporting said CyberAv3ngers has compromised at least 75 US automation devices since 2023, that recent probing attempts have been unsuccessful, and that officials assess the activity as geopolitical signaling rather than an attempt at mass disruption, with no water contamination or sustained outages reported.

    Activegadgetreview.com
  6. Sep 2, 2026

    NBC News reported, citing four people with access to government and industry threat information, that Iran-linked groups have probed US water, energy, telecommunications, and government networks in a campaign that accelerated through mid-2026, and that a Telegram channel calling itself APT IRAN threatened 'unexpected and critical events' against US infrastructure, though no evidence of a successful operation behind that claim was found.

    Activemsn.com
  7. Sep 1, 2026

    Follow-up coverage of the Project Watershed 250 launch ceremony in San Antonio named the participating cybersecurity firms as Microsoft, Dragos, Fortinet, Palo Alto Networks, Zscaler, Forescout, and Tenable, with Texas Cyber Command coordinating the effort; no new victims or recovery milestones were reported.

    Activekxan.com
  8. Aug 31, 2026

    The White House launched Project Watershed 250, a six-month Texas pilot that will give participating water utilities no-cost security testing and support from federal, state, and private partners. A White House official said the program was not launched in response to the Minnesota attacks, and the report named no new victims or recovery milestone.

    Activefoxnews.com
  9. Aug 29, 2026

    An analysis piece explained the CISA/NSA/FBI/DOE/EPA advisory (AA26-231A) on Siemens S7-series PLCs in more detail, saying attackers use AI-generated Python scripts wrapping the snap7 library to scan for and interact with exposed controllers, and that this is characterized as reconnaissance and capability development with no confirmed process-disruption incidents reported since the August intrusions; the advisory did not name any threat actor.

    Activeforkast.news
  10. Aug 28, 2026

    Newsweek reported that national security analysts and a former DHS official warned Iran could use cyberattacks, including further strikes on U.S. water and power infrastructure, as an asymmetric tactic tied to its broader conflict with the U.S. and Israel, though the article described this as a risk assessment rather than reporting any new intrusion.

    Activenewsweek.com
  11. Aug 27, 2026

    A security analysis citing a joint CISA, NSA, FBI, DOE, and EPA advisory said attackers are now using AI-generated exploitation scripts along with open-source snap7 libraries to read and write data on internet-exposed Siemens S7 series PLCs, and that thousands of similar controllers from Siemens, Rockwell/Allen-Bradley, and Schneider Electric remain reachable from the internet nationwide; officials still had not formally attributed the campaign to any country.

    Activeyahoo.com
  12. Aug 26, 2026

    Politico and Nextgov reported the White House, through the Office of the National Cyber Director, plans to launch a program enlisting private cybersecurity firms to help water utilities with few resources improve their defenses, possibly announced the following week and piloted in Texas.

    Activenextgov.com
  13. Aug 26, 2026

    Reuters reported that a separate ransomware group calling itself Barracuda claimed a data breach at Micro-Comm, a small Kansas maker of water-system programmable logic controllers, but the FBI and the company said this breach was not connected to the suspected Iranian campaign against Minnesota and other states' water utilities.

    Activereuters.com
  14. Aug 26, 2026

    CISA said in an advisory that hackers had targeted more than 100 internet-exposed water and wastewater systems in the July intrusions, a larger scope than the more than 30 Minnesota utilities first reported, and said senior officials believe Iran is likely responsible but have not made a formal attribution.

    Activetechcrunch.com
  15. Aug 25, 2026

    The US Treasury Department sanctioned five Iranian nationals for a broader, separate Iran-linked hacking and data-theft campaign tied to Iran's Ministry of Intelligence and Security; the same report said CISA and the FBI have recently been helping water utilities in at least 12 states recover from the cyberattacks, but noted CISA has not publicly attributed those water intrusions to Iran.

    Activedefenseone.com
  16. Aug 25, 2026

    A former acting Principal Deputy National Cyber Director, Jake Braun, told Newsweek that Iran-linked attacks on US critical infrastructure are likely to continue and increase in severity, citing the UK plant incident as a sign of intent; no new intrusions or victims were reported.

    Activeyahoo.com
  17. Aug 24, 2026

    UK Energy Minister Michael Shanks was named publicly confirming the power-plant shutdown, describing the generator as tiny and isolated and stating there was no threat to the wider grid and nobody lost power.

    Activefoxnews.com
  18. Aug 24, 2026

    The UK government briefed energy company CEOs on protective steps after media reports of the Iran-linked power plant hack, confirming the cyberattack occurred but stating it posed no risk to the wider electricity system and stopping short of officially blaming Iran.

    Activemsn.com
  19. Aug 23, 2026

    Iran-linked hackers, named in press reports as CyberAv3ngers, were blamed for a four-day shutdown of a small UK power plant, with reporting describing it as part of the same wider wave of Iran-linked attacks that includes the still-active US water utility intrusions; no official closure or restoration announcement was found for the US water incidents themselves.

    Activetheguardian.com
  20. Aug 21, 2026

    New reporting said Iranian-backed hackers were using AI-generated exploitation tools against vulnerable Siemens PLCs in water systems nationwide.

    Activeforbes.com
  21. Aug 1, 2026

    CBS News reported investigators were probing whether Iranian hackers were behind activity affecting water systems in seven states, with formal attribution still pending.

    Activecbsnews.com
  22. Jul 31, 2026

    Minnesota officials said the source of the attacks was still being confirmed as water systems in multiple states reported similar activity.

    Activewnem.com
  23. Jul 29, 2026

    Investigators said the attackers exploited an unpatchable flaw to breach more than 30 Minnesota water systems, shutting down one plant and forcing manual operation elsewhere.

    Activetechtimes.com
  24. Jul 27, 2026

    Reports emerged that Iranian-affiliated hackers were accessing internet-exposed PLCs at US water, energy, and government sites and altering operator screens.

    Emergingcybersecuritynews.com

Sources

Related reports