Skip to content
News

Iranian Hackers Exploit Weak Passwords in US Water Systems

Iranian Hackers Exploit Weak Passwords in US Water Systems - Iranian hackers water systems
Iranian hackers exploited weak passwords on US water systems, seizing control of PLCs and disrupting supplies across a dozen states in 2026.

Iranian hackers are believed to be behind a wave of cyberattacks on US water systems, exploiting weak and default passwords on internet-connected devices to seize control of critical operations.

The disruption began on 26 July, when more than 30 water systems in Minnesota started showing symptoms of a coordinated cyberattack. Within a week and a half, the attacks had spread to at least a dozen states, causing widespread service disruptions, boil-water notices, pressure drops and flooding.

In a joint statement on 30 July, the Federal Bureau of Investigation and the Environmental Protection Agency described how malicious actors gained access to internet-connected devices, changed the IP addresses and passwords, and took control of operations. Multiple news reports attribute the attacks to Iranian hackers.

In most cases, facilities restored services within hours by switching to manual operations. Even so, experts warn the incidents expose alarming weaknesses in the security of critical infrastructure. Maurice E. Dawson, a professor at the Illinois Institute of Technology who studies critical infrastructure cybersecurity, said the situation is far worse than most people would assume.

Repeated warnings preceded the attacks

The attacks followed years of alerts. As far back as 2023, the Cybersecurity and Infrastructure Security Agency issued a warning about threats targeting water systems by exploiting internet-connected devices that used default passwords or no password at all.

In April 2026, the agency issued a further warning to water facilities about Iranian-affiliated actors potentially targeting US water and energy systems. The advisory was updated with additional guidance four days before the first Minnesota attack was reported, listing the specific devices observed being targeted and again urging operators to change device passwords from their defaults.

How the attackers gained access

The entry points in the recent attacks were industrial computers known as programmable logic controllers, or PLCs. Much like Wi-Fi routers, PLCs act as the central nervous system for complex industrial control systems.

They are found in virtually every industrial setting across the country, including food processing plants, water treatment facilities and electrical substations. Many have been in service for decades without security updates, making them attractive targets.

Once located, the passwords were either too weak or too obvious. Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition and a former CISA associate chief, described the systems as low-hanging fruit for attackers.

The guidance issued to water systems mirrors long-standing advice for individual internet users: change default credentials, use a VPN, and keep devices updated with the latest security patches. The specific devices identified as being targeted were named in the updated CISA advisory.

Source
Image: cnet.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals