Iranian Hackers Target Water Utilities Across 12 U.S. States
Hackers linked to Iran's Islamic Revolutionary Guard Corps targeted over 30 U.S. water utilities, exploiting default passwords to hijack control systems across 12 states.
Hackers linked to the Islamic Revolutionary Guard Corps (IRGC), specifically the group APT33, targeted more than 30 municipal water utilities across at least 12 U.S. states during the summer of 2026. The affected regions include Minnesota, Michigan, Georgia, New Jersey, South Dakota, Utah, and Arkansas. The attackers exploited basic security vulnerabilities, such as open ports and factory-default passwords in software and programmable logic controllers, to hijack control dashboards and disable safety interlocks.
These breaches forced several municipalities to revert to manual pumps and valves to maintain operations. The Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and the Environmental Protection Agency issued joint warnings that the attacks could lead to biological contamination or toxic chlorine overflows. Federal officials characterized the campaign as asymmetric warfare intended to undermine public confidence in critical infrastructure, noting that attackers are using artificial intelligence to scan for vulnerabilities faster than defenders can remediate them.
The cyber assault follows a February U.S.-Israeli operation that killed Iranian Supreme Leader Ayatollah Ali Khamenei. In response to these and other infrastructure threats, Donald Trump released the Cyber Strategy for America to reinforce digital defenses for critical supply chains and facilities. Experts warn the attack playbook may expand to other municipal systems, including power, transit, and wastewater.