Suspected Iranian Hackers Targeted U.S. Water Utilities. Experts Say the Systems Are ‘Low-Hanging Fruit’
U.S. intelligence officials believe hackers linked to Iran's Islamic Revolutionary Guard Corps are behind the attacks.

A wave of suspected Iranian cyberattacks against U.S. water utilities is exposing long-standing vulnerabilities across one of the country's most critical infrastructure sectors, renewing warnings that thousands of local systems remain dangerously easy targets for foreign hackers.
At least a dozen states have been affected by the recent campaign, including Minnesota, where at least 30 water systems were targeted, according to a Washington Post report. U.S. intelligence officials believe hackers linked to Iran's Islamic Revolutionary Guard Corps are behind the attacks, though the government has not formally attributed the campaign.
The incidents have revived a years-long debate over whether cybersecurity standards should be mandatory for the nation's more than 150,000 water systems, many of which are operated by small municipalities with limited budgets and technical staff.
The warning signs have been building for years. In late 2022, Microsoft detected an intrusion into a water system in Guam that U.S. intelligence agencies later determined was orchestrated by China.
Officials were particularly concerned because Guam is home to strategically important U.S. military facilities, but the incident also highlighted the vulnerability of civilian water infrastructure.
Iranian-linked hackers have also previously targeted industrial control systems. Federal cybersecurity agencies have warned that IRGC-affiliated actors have exploited internet-connected equipment using default or weak passwords, including devices used by U.S. water and wastewater utilities.
CISA has recommended disconnecting operational technology from the public internet where possible, replacing default passwords, implementing multifactor authentication, and keeping internet-facing systems patched.
Following the 2021 Colonial Pipeline ransomware attack, the Biden administration moved to strengthen cybersecurity requirements across critical infrastructure, including pipelines and railroads.
In March 2023, the Environmental Protection Agency sought to require states to incorporate cybersecurity assessments into reviews of public water systems and address significant vulnerabilities. Arkansas, Iowa and Missouri sued, arguing that the EPA had exceeded its authority and imposed financial burdens on smaller communities. The policy was eventually withdrawn after a federal appeals court halted the effort.
Now, one of the states that challenged the EPA policy has been hit. A water utility in western Arkansas was targeted late last month as part of the suspected Iranian campaign, according to The Post. Some cybersecurity specialists argue that mandatory assessments could have eliminated many of the basic weaknesses attackers are exploiting.
"The level of effort and expense to fix these systems is not that much," Gus Serino, president of cybersecurity consultancy I&C Secure, told The Post. "It wouldn't remove all the risk, but would certainly remove most of the low-hanging fruit." The attacks are prompting a new push in Congress.
Sen. Adam Schiff, D-Calif., unveiled legislation Monday that would explicitly authorize the EPA to regulate cybersecurity in the water sector. The proposal would require utilities to conduct cybersecurity assessments and take corrective action when significant vulnerabilities are discovered.
Meanwhile, industry resistance appears to be softening. The American Water Works Association, the country's largest organization representing water utilities, is supporting separate legislation sponsored by Rep. Rick Crawford, R-Ark., that would establish an independent body to develop minimum cybersecurity requirements under EPA oversight.
"We need minimum requirements," Kevin Morley, AWWA's federal relations manager, told The Post. "It's time to step up the game."Not every utility is equally vulnerable. Cedar Rapids, Iowa, has largely protected its water infrastructure by keeping critical systems "air-gapped," meaning they are not connected to the internet.
Indiana, Maryland and New York have also enacted laws requiring cybersecurity risk assessments for water systems, and authorities are not aware of utilities in those states being compromised in the latest campaign, according to The Post.
Federal guidance underscores how basic defenses can make a significant difference. CISA recommends inventorying connected equipment, changing default passwords, restricting internet exposure, maintaining backups and developing incident-response plans.
For smaller communities, however, convincing operators that they could become geopolitical targets remains a challenge. "A lot of people don't take it serious until it happens to them," Chris Harris, CEO of the Arkansas Rural Water Association, told The Post. Small towns, he said, may wonder why Iran would care about them." They don't realize that they're attacking whatever they can."
© Copyright IBTimes 2026. All rights reserved.

























