When most people think about cyberattacks, they imagine stolen credit card numbers, locked computer screens, or hacked social media accounts. Few people imagine turning on their kitchen tap and wondering whether what comes out is safe to drink.
That scenario is no longer hypothetical. This week, federal authorities confirmed that a wave of cyberattacks targeting municipal water systems across the United States has spread to at least 12 states, and intelligence sources are pointing toward Iran as the likely culprit.
The water coming out of your tap is now a national cybersecurity issue, and it is worth understanding exactly how these attacks work and what they mean for communities like ours.
What Happened
The initial signs of the attack emerged between July 26 and 27, 2026, when authorities in Minnesota reported that hackers targeted about 30 water systems in their state. Within days the picture expanded dramatically.
Iran was likely behind a wave of recent cyberattacks on municipal water systems across the United States, two people familiar with the incidents told NBC News. The FBI reported that malicious cyber actors targeted water and wastewater utility companies in at least seven states over a four-day period, resulting in a loss of monitoring and control functionality. Officials in Michigan, Minnesota, and New Jersey have reported attacks.
By the time this column went to press, water system cyberattacks linked to Iran had spread to 12 states, forcing boil water notices and manual operations at affected utilities.
On July 30, 2026, the FBI and the Environmental Protection Agency issued a stark joint warning that malicious cyber actors were conducting cyberattacks targeting operational technology devices used to adjust water quality, chemical treatment levels, and water pressure. EPA Assistant Administrator Jeffrey Hall put the stakes plainly: “Cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience. A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust.”
How the Attacks Actually Work
This is where the story gets technically interesting and genuinely alarming in equal measure.
The attackers did not try to infiltrate the computers that utility offices use. Instead, they tried to seize control of small computers in equipment like pumps and valves that deliver drinking water to millions of people.
These small computers are called programmable logic controllers, or PLCs. They are the industrial control devices that manage the physical processes of a water treatment plant, opening and closing valves, adjusting chemical dosing, regulating pressure, and monitoring water quality in real time. The warning from the FBI and EPA specifically mentioned Rockwell Automation and Allen-Bradley PLCs, particularly the MicroLogix 1100 and 1400 series, although systems using PLCs from other brands were also advised to be cautious.
The method of attack was remarkably simple for something with such potentially serious consequences. Attackers scanned internet addresses for controllers, dashboards, and outside companies that provide remote access services, looking for targets linked directly to the internet. They then looked for a default or stolen password to log in, an unpatched vulnerability, or a misconfigured remote-access service. Sophisticated malware was not always necessary.
Once inside, the threat actors remotely modified the passwords and disconnected the systems by changing their IP addresses to lock out operators. The operational impacts reported to the FBI were loss of water pressure and flooding. At least one organization reported modifications to the PLC project files.
The utilities countered the attacks by shutting down the control computers and sending personnel out into the field to operate equipment manually. Utility officials said that water remained safe to drink.
Why This Keeps Happening
This is not the first time Iran-linked hackers have gone after American water infrastructure. In December 2023, multiple federal agencies warned that an Iran-linked hacking group called CyberAv3ngers, affiliated with Iran’s Islamic Revolutionary Guard Corps, was targeting Israeli-made programmable logic controllers used in U.S. water and wastewater systems across multiple states.
The 2026 attacks appear to represent an escalation of that campaign, likely tied to the broader conflict involving Iran that has unfolded this year. Iran has maintained an active state-sponsored cyber program for years with documented capabilities in wiper malware, distributed denial-of-service attacks, and espionage against critical infrastructure. Prior to the 2026 conflict, Iran had conducted cyberattacks on financial institutions and election-related targets and maintained proxy hacktivist networks for plausible deniability.
The deeper structural problem is that American water infrastructure is extraordinarily vulnerable. A volunteer defense program designed to help small utilities shore up their cybersecurity has reached only 21 of 50,000 unprotected small utilities, revealing a structural gap that no federal law currently requires water systems to fill.
Making matters worse, the Cybersecurity Information Sharing Act of 2015, the law that provides liability protections enabling private utilities to share threat intelligence with CISA and the FBI, will expire September 30, 2026, unless Congress acts. If that law lapses, water utilities lose the legal protections that allow them to share information about ongoing attacks with federal agencies and with each other without fear of legal liability. The law has already lapsed twice in the past year during government funding gaps.
What Communities Should Know
For most residents in York and Lancaster Counties, the immediate risk from these specific attacks is low. The targeted systems have primarily been in Minnesota, Michigan, New Jersey, and other states where affected utilities have reported that water remained safe. However, the broader warning from CISA and the FBI is directed at every water utility in the country regardless of size or location.
“These threat actors are targeting water entities of all sizes,” CISA warned. “Every utility, no matter the size, must assume it is a potential target and accelerate efforts to remove internet-exposed control systems, strengthen identity and remote access security, continuously monitor operational technology networks, and ensure facilities can safely transition to manual operations when cyber incidents occur.”
If your local water utility issues a boil water notice in the coming weeks, follow it without question. These notices exist precisely because utilities cannot always immediately determine whether a disruption to their control systems has affected water treatment. When in doubt, boil.
Beyond that, the most important thing residents can do is pay attention to local utility communications and support investment in cybersecurity infrastructure at the municipal level. Water cybersecurity is not a glamorous budget line item. But as this week’s events have shown, it is one of the most consequential.
Stay safe out there, and I will see you next week!
Feeling lost in the digital world? Dr. Tom is here to help!
References
- Cyber Magazine. “Iran-Linked Cyberattack on US Water Systems Explained.” August 2026. https://cybermagazine.com/news/iran-linked-cyberattack-on-us-water-systems-explained
- NBC News. “Iran Likely Behind Cyberattacks on U.S. Water Systems, Sources Say.” August 4, 2026. https://www.nbcnews.com/tech/security/iran-likely-cyberattacks-us-water-systems-sources-say-rcna590756
- TechTimes. “Iran Hackers Breach 12 States’ Water Systems While Power Grid Stays Protected by Law.” August 5, 2026. https://www.techtimes.com/articles/323097/20260805/iran-hackers-breach-12-states-water-systems-while-power-grid-stays-protected-law.htm
- The Hill. “America’s Water Systems Are Under Attack. Iran May Be to Blame.” August 2026. https://thehill.com/policy/defense/6012602-iran-linked-water-utility-hacks/
- Fortune. “Iranian Hackers and America’s Achilles Heel on Water: Default Passwords.” August 5, 2026. https://fortune.com/2026/08/05/iran-hackers-water-systems-plc-breach/
- The Guardian / AOL. “US Warns of Iran-Affiliated Cyber-Attacks on Critical Infrastructure Across Country.” August 2026. https://www.aol.com/news/us-warns-iran-affiliated-cyberattacks-232142353.html
- Federal Bureau of Investigation and Environmental Protection Agency. Joint Public Service Announcement I-073026-PSA: “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions.” July 30, 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet–facing-programmable-logic-controllers-causing-operational-disruptions

Sign up here to receive the Tega Cay Sun "day" Spectator every Sunday morning with all the news from the week directly to your inbox
Thomas Hyslip lives in Tega Cay with his wife and daughter. After 27 years in the U.S. Army and Federal Law Enforcement, he retired to pursue his passion for teaching. Tom is now an Assistant Professor of Instruction at the University of South Florida. In 2 short years he has won 10 awards from the South Carolina Press Association, including first place in column writing, education beat reporting and best podcast.


