>samit_hota
Back to security news

Security News · SN-2026-371

HIGHOPEN

Iranian Cyberattacks Target Internet-Exposed PLCs in US Water Systems

Affected: US Municipal Water and Wastewater Systems · Internet-Exposed PLCs

Samit Hota·
#news#data-breach#iranian

Overview

Cyberattacks targeting municipal water and wastewater facilities have expanded significantly, now affecting critical infrastructure across at least a dozen states. The campaign relies on widespread scanning to identify internet-exposed PLCs (Programmable Logic Controllers) that lack basic network segmentation or authentication controls. Iranian state-sponsored groups are heavily suspected in this campaign, continuing a established pattern of low-sophistication, high-visibility operations against vulnerable operational technology (OT) environments.

Attack Vector and Operational Impact

Programmable Logic Controllers serve as the primary operational backbone in industrial automation, controlling critical mechanics such as pump operations, valve actuation, and chemical dosing in water treatment plants. When these control units are connected directly to the public internet—frequently deployed this way for remote operational convenience—they become trivial targets for automated scanning platforms and opportunistic threat actors.

The primary vulnerability class here is architectural exposure and weak access control rather than a sophisticated software exploit. Many field-deployed PLCs utilize unauthenticated management protocols, web interfaces secured only by factory-default passwords, or cleartext communications.

Once an attacker discovers an exposed PLC, they can interact directly with the control logic. Depending on the device capabilities, threat actors can force system shutdowns, alter operational thresholds, or tamper with Human-Machine Interface (HMI) displays. For the small-to-medium utility providers typically affected, the immediate blast radius involves losing remote telemetry, forcing facilities into manual override modes, and straining local operations, even when secondary mechanical safeguards prevent physical safety incidents.

Suspected Threat Actor Mechanics

Iranian-aligned threat actors, including groups affiliated with the Islamic Revolutionary Guard Corps (IRGC), frequently employ low-barrier attack vectors against Western infrastructure targets. Rather than deploying custom malware or burning zero-day exploits, these actors scan public IP ranges using internet intelligence tools to locate exposed industrial hardware. Once located, they use basic credential abuse or known device defaults to tamper with device configurations, deface control screens, or disrupt baseline services to achieve maximum political impact for minimal effort.

Defensive Actions

Defending water system PLCs against this campaign requires immediately removing OT control interfaces from direct public exposure. Utility operators must audit their external IP space to ensure no PLCs, HMIs, or Remote Terminal Units (RTUs) are directly reachable over the internet; any required remote access must be routed through a secure firewall and an encrypted VPN enforced with multi-factor authentication, paired with immediate changes to all default vendor passwords.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call