Thursday, 6 August 2026

Opening the Digital Floodgates

What the US water-system attacks reveal about exposed OT and strategic cyber risk
Illuminated water pipeline representing cybersecurity risks and protection measures for US water infrastructure. - image generated with AI

The cyberattacks on US water systems in late July were not simply another breach story. They were a demonstration of how ordinary remote connectivity can become strategic leverage when it reaches the technology controlling a physical process.

On 26-27 July, operational technology (OT) at more than 30 community water systems in Minnesota were targeted, in what the state described as, a coordinated cyberattack. Early accounts captured the initial picture: automated systems were disrupted, some operators moved to manual control and federal agencies warned utilities nationally. The picture has since widened. The FBI and Environmental Protection Agency have confirmed reports from water and wastewater organisations in at least seven states; later reporting, based on multiple official sources, puts the possible reach at around twelve states. Publicly disclosed activity now includes Minnesota, nine systems in Michigan, incidents in Georgia and South Dakota, and two municipal systems in New Jersey.

The consequences varied. Operators lost remote visibility or control, facilities switched to manual procedures and one Minnesota plant temporarily stopped operating. In Georgia, reduced pressure led to a precautionary boil-water notice; across the wider activity, the FBI has received reports of pressure loss and flooding. No confirmed contamination has been reported, and public-health safeguards generally held. That should reassure the public, but not the operators of essential services. A data breach exposes information. An OT compromise can remove an operator's ability to see, decide or act while the physical process continues.

The attack path is the message

The FBI says the recent incidents involved internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLC’s). After gaining remote access, the actors changed IP addresses and passwords, depriving operators of monitoring and control. The Bureau also noted similarities in third-party network configurations across several victims, creating the potential to replicate success across multiple customers.

There is no public evidence that the July incidents required a novel cyber weapon or zero-day vulnerability. The more important issue is architectural: control devices and cellular modems were reachable from the internet, sometimes through connections installed by vendors or integrators that were absent from routine asset inventories. Normal engineering functionality then became the attack mechanism.

In operational environments, sophistication should be measured by the effect achieved, not by the novelty of the code used.

This is also a scale problem. In April, a Censys point-in-time scan identified 5,219 internet-exposed Rockwell/Allen-Bradley devices globally, with almost three quarters in the United States and a substantial concentration on cellular networks. An exposed controller is not proof of compromise, but it is a searchable opportunity. Attackers do not need to select every victim individually when the internet can supply the target list.

Attribution requires discipline

As of 6 August, US authorities have not formally attributed the July incident wave to Iran or to a named group. US officials and investigators reportedly assess Iranian involvement as likely, and the timing and methods are consistent with activity described in a multi-agency warning about Iranian-affiliated targeting of critical infrastructure. Consistency, however, is not confirmation. The same exposed architecture could be exploited by another state, a proxy, a criminal group or an actor deliberately imitating Iranian tradecraft.

The Iran hypothesis is nevertheless credible. Four days before the Minnesota attacks, US agencies updated Joint Cybersecurity Advisory AA26-097A, documenting an Iranian-affiliated campaign against internet-connected PLCs. The advisory links this activity historically to the CyberAv3ngers ecosystem, also known as the Shahid Kaveh Group, which the US associates with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command. The US Treasury sanctioned six IRGC-CEC officials in 2024 following earlier attacks on PLCs used in water and other critical infrastructure.

Talan's own March 2026 report ‘Iran's Heightened Cyber Threat profile’ assessed that retaliatory cyber activity would be used for signalling and coercion, that proxy or hacktivist branding would complicate attribution, and that opportunistic targeting of internet-exposed OT was credible wherever weak remote access, and unmanaged field devices persisted. The July events validate that risk pathway. They do not, by themselves, prove the identity of the actor. Good intelligence must be able to hold both judgements at once.

A more consequential technical escalation

The wider Iranian-affiliated campaign is more technically concerning than password changes alone. The 22 July advisory expanded observed targeting from Rockwell equipment to Schneider Electric Modicon M340 and Siemens S7-1200 PLCs. US agencies observed actors using legitimate vendor engineering software from leased infrastructure to extract controller project files. Investigators subsequently identified modified or deleted logic, altered HMI and SCADA display data, and changes capable of disabling critical shutdowns and alarms, allowing unsafe conditions to develop without notifying operators.

These findings have not been publicly tied to every July water-system incident and should not be presented as though they have. They do show the escalation path available once an actor moves from finding a controller to understanding its process logic. Project-file theft gives an adversary the information needed to replace indiscriminate disruption with tailored manipulation. Loss of view can become loss of control; loss of control can become a safety, environmental or public-health event.

The questions leaders should now ask

The lesson travels beyond the United States because the equipment, integrators and remote-support patterns are global. The UK's NCSC secure-connectivity principles for OT reinforce the immediate priorities: remove inbound exposure, broker remote access through controlled gateways, reduce its duration, and find external connections before an adversary does.

Boards and operational leaders should require evidence-based answers to five questions: 

  • Can we identify every internet, cellular, radio and supplier connection into OT, including undocumented or temporarily enabled paths?
  • Is remote access brokered, strongly authenticated, allowlisted, monitored and limited to an authorised maintenance window? 
  • Can engineers compare running controller logic with a trusted baseline and restore from a verified, offline copy? 
  • Can the service move safely to local or manual operation, and when was that capability last exercised under realistic conditions?
  • Are external attack-surface findings, supplier access, threat intelligence and cyber-physical consequence modelling fused into one risk picture?

The apparent simplicity of these attacks should not be mistaken for low capability. In critical infrastructure, strategic effect can come from exploiting ordinary weaknesses repeatedly and at scale. The decisive measure of resilience is not whether an organisation owns more security tools; it is whether it can detect the loss of trust in its control environment, contain it and maintain a safe service before digital interference becomes physical consequence.

At Talan, this is the purpose of intelligence-led cyber-physical risk analysis: combining OSINT, external attack-surface discovery, product and vulnerability intelligence, supplier context, MITRE ATT&CK for ICS and EMB3D-informed threat modelling to show not only who may be active, but which access paths and failure modes matter most. The real warning from the US water incidents is therefore not that Iran may be able to reach exposed infrastructure. It is that exposed infrastructure can turn geopolitical intent into operational effect with very little warning.

Linked capabilities

Data Privacy

Discover

Cybersecurity

Discover

Cyber Threat Intelligence

Discover