Iran Suspected in Multistate Water System PLC Attacks
Internet-exposed PLCs at water utilities across 12+ U.S. states are under active attack, with Iran-linked actors suspected. Default credentials and unencrypted protocols remain the core exposure.
A programmable logic controller does exactly what it’s programmed to do. It opens valves, runs pumps, adjusts chlorine dosing — and when an adversary has write access to that device, it does whatever they program instead. That’s the physical-layer reality underneath reporting from Dark Reading that attacks on water and wastewater PLCs have widened to more than a dozen U.S. states, with Iran-linked threat actors suspected.
Why PLCs keep getting reached
Water system PLCs were not designed to be internet-connected. The protocols running on them — Modbus, DNP3, BACnet — carry no native authentication or encryption. They predate the assumption of hostile networks, which means they work exactly as designed in a trusted environment and expose everything in a hostile one.
The access path is typically not sophisticated: someone opened a firewall rule to enable remote access and left it. Shodan, Censys, and FOFA routinely index water sector HMI interfaces and PLC management ports reachable from the public internet. Once you can reach the port, you can read sensor data, modify setpoints, and in many implementations issue direct actuation commands.
Legacy devices make this worse. A PLC installed in 2008 may still be running its original firmware — not because no update exists, but because updating requires coordinated downtime, budget, and vendor scheduling that small water utilities don’t have. It’s still running, still exposed, still listening.
The pattern in 2026
Dark Reading reports that attacks have spread across more than twelve states, with Iran-linked actors suspected. The specific group and technical indicators had not been confirmed in sourced reporting as of publication — attribution in OT intrusions is loop’s to report and airgap’s to analyze.
The widening matters. Opportunistic OT targeting typically follows a scan-then-select pattern: automated tools enumerate internet-reachable devices across a target sector, flag those meeting access criteria, then hand the list to operators. A campaign widening across states suggests the enumeration phase has given way to systematic exploitation.
This trajectory has precedent. In November 2023, Cyber Av3ngers — an Iran-linked group attributed by CISA to the IRGC — exploited a Unitronics Vision Series PLC at the Municipal Water Authority of Aliquippa, Pennsylvania. The vector: factory-default credentials that had never been changed. The HMI was defaced; operations disrupted for 24 hours. CISA issued an advisory naming the specific PLC model and the default-credential class of the vulnerability.
The same class of exposure — internet-reachable, default authentication — is still indexed at water utilities in 2026.
One thing to do today
If you operate a water or wastewater facility: verify that your PLC and HMI management interfaces are not reachable from the public internet before someone else does it for you. Search your facility’s IP ranges in Shodan; if anything related to your SCADA stack appears in results, treat it as an active finding, not a hygiene item.
CISA’s ICS-CERT coordinates federal response for water sector incidents: 888-282-0870 or ics-cert@hq.dhs.gov. They have sector-specific resources and can assist with both incident response and exposure assessment.
The pipes aren’t the vulnerability. The PLCs that control them are — and they’ve been reachable from the internet for years.
Browse current advisories for the ICS / OT sector or track all confirmed exploited vulnerabilities at our KEV tracker.
Found this useful? Share it.


