WarBrief Live | October 4, 2026 | Cybersecurity
Iranian-affiliated hackers are running the broadest cyber campaign against American critical infrastructure in years — and it has quietly widened from water utilities into the energy and telecommunications sectors. US federal agencies say the attackers’ method is embarrassingly simple: find industrial controllers left exposed on the public internet, log in with weak or default passwords, and lock out the operators. What began as a pattern of probing in the spring of 2026 became a summer of real intrusions across a dozen states, and by September the campaign’s sights had widened to the grids and networks the US economy runs on.
Key Takeaways
- A joint advisory from CISA, the FBI, NSA, EPA, the Department of Energy and US Cyber Command warns that Iranian-affiliated actors have been exploiting internet-exposed industrial controllers since at least March 2026.
- Water utilities in at least 12 states — including Minnesota, New Jersey and Georgia — were hit over the summer; CISA says more than 100 internet-exposed water systems were targeted in July 2026 alone.
- In early September, NBC News reported the campaign had widened to telecommunications and energy networks; the attackers’ attempted breaches have not yet succeeded, according to that reporting.
- Officials have not formally attributed the attacks to Iran: it remains the leading suspect, but investigators are also weighing whether a copycat actor is mimicking Iranian tactics.
- Defenses are basic and available: disconnect controllers from the internet, change default passwords, patch firmware and enforce multifactor authentication on remote access.
What happened: a campaign that widened across three sectors
The alarm bells started ringing in the spring. On April 7, 2026, six US agencies — CISA, the FBI, the NSA, the Environmental Protection Agency, the Department of Energy and US Cyber Command — issued a joint cybersecurity advisory designated AA26-097A, warning that Iranian-affiliated cyber actors had been actively exploiting internet-exposed programmable logic controllers (PLCs) across US critical infrastructure since at least March 2026. The advisory named three sectors as directly affected: water and wastewater systems, energy, and government services. Some victim organizations had already suffered operational disruption and financial loss.
That advisory kept expanding. A July 22 update broadened the target list beyond Rockwell Automation/Allen-Bradley controllers to include Schneider Electric and Siemens devices, and described a new technique: the attackers were using the vendors’ own legitimate engineering software to steal PLC project files from victim environments. At one confirmed American victim, the actors had gone further still — modifying ladder logic to disable safety shutdown and alarm functions, allowing unsafe conditions to develop without alerting operators. The North American Electric Reliability Corporation (NERC) said it was actively monitoring the electric grid in response.
Then came the summer wave. Around July 26–27, hackers targeted about 30 water systems in Minnesota. The FBI later reported that malicious actors had hit water and wastewater utilities in at least seven states over a four-day period, knocking out monitoring and control functions. Reuters reported in late July that investigators viewed the Minnesota incidents as likely the work of Iran-linked hackers; The New York Times reported that analysts viewed the operation as “likely executed by Iranian hackers,” while stressing the assessment was preliminary and could change as forensics matured.
The summer wave: Minnesota, New Jersey and Georgia
New Jersey’s incidents arrived in early August and showed the pattern in miniature. Two municipal water systems were targeted in cyberattacks the state said were widely thought to be the work of Iran. Automated systems were temporarily blinded, operators shifted to manual procedures, and — crucially — customers never lost service. The state’s New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) responded alongside the FBI and CISA. NBC10 Philadelphia later identified the affected systems as the Cape May Water and Sewer Department and the Woodbine Water Department; the hackers had reached monitoring systems but had not breached the computers that actually control water operations. Cape May City Manager Paul Deitrich described the intrusion as limited: the attackers, he said, “just went in and said, ‘Hi, we’re here,’ and left.”

Georgia saw similar scenes. The Clayton County Water Authority briefly issued a boil-water advisory when it was targeted; Columbus Water Works said it had detected an intrusion but that drinking water was unaffected. At one point, three Georgia utilities were running their plants by hand at the same time. By late summer, the count had grown: water-system attacks linked to Iran had spread to at least 12 states, and CISA stated that in July 2026 alone it had observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems sector — most commonly via PLCs connected directly to a cellular modem.
The federal response sharpened in tandem. On July 30, the FBI and the EPA issued a stark joint warning that malicious cyber actors were conducting cyberattacks targeting the operational technology devices used to adjust water quality, chemical treatment levels and water pressure. EPA Assistant Administrator Jeffrey Hall put the stakes plainly: “Cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience. A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust.”
How the attacks work: the exposed PLC problem
The technical picture is less a story of sophisticated hacking than of industrial neglect. The attackers did not break into office networks. Instead, they targeted the small industrial computers — programmable logic controllers, or PLCs — that open and close valves, adjust chemical dosing, regulate pressure and monitor water quality in real time. The method, according to the FBI-EPA warning, was simple: scan internet addresses for controllers, dashboards and remote-access services — the same internet-scanning exposure that puts infrastructure behind conflict zones at risk; log in with a default or stolen password; or exploit an unpatched vulnerability. No advanced malware required.
The conditions that made this possible were years in the making. The United States has roughly 150,000 to 170,000 public water systems, the vast majority of them small — many serving fewer than 10,000 people, run by staff who double as IT teams and field crews on tight budgets. Cellular modems offered cheap remote monitoring, so thousands of PLCs ended up sitting on the public internet with no firewall between them and whoever found them. Some still ran factory-default credentials; a 2023 pattern of Iran-linked attacks exploited Unitronics PLCs running the manufacturer’s default password. Michael Garcia, a former CISA associate chief who now directs policy for the Operational Technology Cybersecurity Coalition, called the targets “low-hanging fruit” — PLCs, he said, “were connected to the internet that shouldn’t have been connected to the internet.” Maurice E. Dawson of the Illinois Institute of Technology surveyed the broader picture and concluded: “We’re in a lot worse shape than you would think.”
Federal guidance has been blunt and consistent: disconnect critical control systems from the internet immediately, change default passwords, patch firmware, route remote access through secure gateways, enforce multifactor authentication and monitor traffic for anomalous changes. Utilities across the country began installing software fixes after the July warnings. The agencies stopped short of formal attribution to Tehran — investigators remain wary of false-flag operations — but noted that the tradecraft, the lack of ransom demands and the geopolitical context all pointed toward Iranian actors.
The campaign widens to energy and telecom
The story did not stop at water. In early September, NBC News reported that Iranian hackers had targeted not only US water systems but also America’s telecommunications, energy and other infrastructure in recent weeks. The attempted attacks focused on internet-connected automated systems and, according to that reporting, had “not been successful” so far — but they underscored what NBC described as Iran’s readiness to retaliate against the United States beyond its interests in the Middle East. A CSIS analysis published in June had already warned that the ongoing Iran conflict had substantially heightened retaliatory cyber risk to the US energy grid.
The telecom claims produced the summer’s most public confrontation. On the evening of Labor Day, a group calling itself APT IRAN claimed on Telegram that it was behind an AT&T outage across major Texas cities — Houston, Dallas, Fort Worth and Austin — and vowed to “intensify” critical infrastructure attacks in the run-up to the 25th anniversary of the September 11 attacks. The Houston Chronicle reported a surge of outage reports, and the Dallas Morning News reported the fiber outage affected over 7,000 families. But an AT&T spokesman said the company had “no evidence to support” the claim: “Our assessment indicates that attempted cable theft led to the outage,” the spokesman said, adding that service across Dallas was operating normally. A week later, APT IRAN backed off its 9/11 escalation threat and said it had targeted AT&T because of consumer dissatisfaction with the company — a rationale that sits oddly beside its original political messaging.

Meanwhile, reporting from Britain suggested the campaign’s reach may extend beyond the United States. The Telegraph reported in August that Iranian cyber operators had managed to shut down a British power plant for four days — a claim cited in analyses by Homeland Security Today and Lawfare, though the details remain thin. And the water sector’s supply chain came under its own spotlight: Reuters reported on August 26 that Micro-Comm, a Kansas manufacturer of PLCs used in wastewater facilities, had suffered a ransomware attack, with the group Barracuda claiming nearly 850,000 files. The company said no customer credentials or remote-access tools were taken, but the incident illustrated how the sector’s vulnerabilities extend beyond the utilities themselves.
The official response
Washington’s institutional response has been a steady drumbeat of advisories rather than a single dramatic move. The April joint advisory (AA26-097A) established the threat picture; the July 22 update expanded it to Siemens and Schneider Electric gear and added indicators of compromise; the July 30 FBI-EPA warning spoke directly to water operators; and CISA has kept updating sector guidance through the summer. The Center for Strategic and International Studies has been mapping the campaign publicly since August, and WarBrief’s intelligence desk continues to track, finding confirmed targets across nine states with no clear geographic or political pattern — the campaign hits small rural systems as often as larger ones.
Not every federal signal has pointed toward more resources. In April, TechCrunch reported that the Trump administration’s FY2027 budget proposal would slash CISA’s budget by approximately $707 million and eliminate roughly 860 positions — a proposal that drew sharp criticism from cybersecurity professionals who warned it would shrink exactly the agency tasked with defending against the threats described in the advisories. Congress must approve any budget; prior White House attempts to cut CISA funding faced pushback on Capitol Hill that narrowed the reductions. The tension between an escalating offensive cyber campaign and a potentially shrinking defensive agency has become one of the defining policy frictions of the crisis.
Why it matters for American households
For most Americans, the direct risk has so far been disruption rather than danger: temporary losses of monitoring, manual operations, boil-water advisories and short outages. No drinking water contamination has been attributed to these attacks, and officials stress that the breaches reached monitoring systems more often than control systems. But the pattern matters because of what it demonstrates — that a foreign adversary can reach into the control layers of essential services with commodity techniques — and because of what it foreshadows. Cyberattacks that begin with reconnaissance and password changes can, in theory, progress to tampering with chemical dosing or pressure controls; the ladder-logic sabotage case described in the July 22 advisory shows that line has already been approached.
The economic geography of the targets also matters. The campaign concentrates on small utilities that lack the budgets and staff for serious cybersecurity. Congress approved $1 billion in 2022 for a state and local cybersecurity grant program; that money has been spent, and reauthorization talks continue without resolution. For Tier-1 readers watching utility bills and local services, the practical takeaway is civic rather than personal: ask local officials whether your utility’s control systems are internet-exposed, whether default passwords have been changed, and whether remote access is gated behind multifactor authentication. Those three questions cover most of what the attackers have exploited.
Different perspectives
The attribution question remains the most contested part of the story. Iran denies involvement. Multiple US outlets, citing officials and analysts, describe Iran as the prime suspect — but the US government has not formally attributed the campaign to Tehran, and officials have been careful to keep their language conditional. American University scholar William Akoto, who researches cyber conflict, said the methods used are typical of international cyberattacks, but noted the government “has yet to attribute the attack to anyone.” Some officials have raised a more unsettling possibility: that a different foreign actor may be copying Iranian cyber tactics, either to probe US responses or to complicate Washington’s next move against Tehran.
Industry experts divide on what the campaign’s intent is. Matt Barnett, CEO of the Pennsylvania-based cybersecurity firm SEVN-X, argued the attacks are often aimed at testing systems for weaknesses and disrupting the American way of life — reconnaissance for a larger future operation rather than an end in itself. Others note the restraint: the attackers have not attempted to poison water or cause physical destruction, and the Tehran-pleasing signaling (claims of outages, Telegram threats) suggests at least part of the goal is demonstrating reach to domestic and international audiences. The absence of ransom demands is what distinguishes the activity from the criminal ransomware ecosystem — the recent KillSec takedown showed how the profit-driven underground operates, and this campaign does not look like that.
Defenders, meanwhile, see a solvable problem. The same analyses that document the exposure emphasize that the fixes are neither exotic nor expensive: remove the devices from the public internet, change the passwords, patch the firmware. The harder problem is institutional — thousands of independent utilities, thin expertise, tight budgets — and that is where the policy debate now sits, from grant reauthorization to whether federal minimum standards should apply to internet-connected operational technology.
What to watch next
Several markers will determine whether this campaign plateaus or escalates. First, watch for formal US government attribution: an official naming of Iran would unlock sanctions, indictments or retaliatory cyber operations, and would clarify whether Washington treats this as espionage, coercion or something more serious. Second, watch the energy sector: the April advisory already named energy providers as targets, NERC is monitoring the grid, and any confirmed disruption to electricity — rather than the water and telecom incidents so far — would mark a genuine escalation. Third, watch the federal funding picture: the FY2027 budget fight will determine whether CISA’s defensive capacity grows or shrinks while the threat grows. Fourth, watch for copycat or opportunistic actors: criminal groups have repeatedly piggybacked on nation-state attention, and the Micro-Comm supply-chain incident showed the ecosystem’s soft underbelly. Finally, watch the calendar: APT IRAN’s threats have repeatedly been tied to symbolic dates, and US officials remain alert around politically charged anniversaries.
For now, the campaign’s signature remains its modesty — not the sophistication of the attacks, but the simplicity of the failures that made them possible. The devices were never supposed to be reachable from a browser. Until that changes, the taps, the grid and the networks will keep offering the same low-hanging fruit.
Frequently asked questions
Have Iranian hackers actually breached US water systems?
Intrusions into US water utility systems are confirmed — in Minnesota, New Jersey, Georgia and other states — and US agencies have warned since April 2026 that Iranian-affiliated actors are behind a campaign targeting industrial controllers. But formal attribution to Iran has not been made: Iran is the leading suspect cited by officials and analysts, the US government has not formally named it, and Iran denies involvement. Treat “Iranian hackers” as the suspected, not proven, actor.
Was my tap water affected by these cyberattacks?
There is no confirmed case of drinking water contamination from this campaign. In the documented incidents, attackers reached monitoring systems or forced operators to switch to manual control; service was not interrupted in the New Jersey cases, and a boil-water advisory in Georgia’s Clayton County was issued as a precaution. Utilities say water quality monitoring remained intact or was restored quickly.
What is a PLC and why are hackers targeting it?
A programmable logic controller (PLC) is a small industrial computer that manages physical processes — opening and closing valves, adjusting chemical dosing, regulating pressure. Attackers target them because thousands sit directly on the public internet, often with weak or default passwords, allowing intruders to lock out operators or tamper with settings without sophisticated malware.
Why are small water utilities so vulnerable?
The US has roughly 150,000 to 170,000 public water systems, most of them small, run by thin staffs on tight budgets. Cheap cellular modems made remote monitoring affordable but left controllers internet-exposed; cybersecurity expertise and upgrade budgets are scarce. Federal grant money approved in 2022 has been spent, and reauthorization is unresolved.
Did Iranian hackers cause the AT&T outage in Texas?
Unconfirmed. A group calling itself APT IRAN claimed responsibility for a Labor Day outage affecting Texas cities, but AT&T said it had “no evidence to support” the claim and attributed the outage to attempted cable theft. The group later backed off its threat to escalate attacks around the September 11 anniversary.
Sources
- CISA: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (Advisory AA26-097A)
- TechCrunch: Iranian hackers are targeting American critical infrastructure, US agencies warn
- IOActive: Iranian-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric
- CSIS: Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure
- ABC News: 2 New Jersey municipal water systems targeted in cyberattacks
- NBC10 Philadelphia: Experts warn of growing threat after hackers hit NJ utilities
- ThreatBeat: Iran hackers claim Texas AT&T outage, vow to ‘intensify’ attacks before 9/11
- Homeland Security Today: The U.S. Needs a Strategy to Counter China’s Leverage in Cyberspace