top of page

Lessons Learned from Iranian Hacking of US Water Treatment Plants and How to Enhance Preparedness

mstoffo
Sep 7
5 min read
Industrial water treatment plant at dusk with control panels and security fencing

In November 2023, hackers linked to Iran's Islamic Revolutionary Guard Corps (IRGC) broke into a water booster station in Aliquippa, Pennsylvania. The attack was not subtle. The screen of the compromised controller displayed a blunt message: "You have been hacked. Down with Israel." The device they targeted was internet-facing, secured only by the factory default password "1111."


That single incident was not an outlier. Between November 2023 and early 2024, at least 34 U.S. water and wastewater facilities were confirmed compromised in the same campaign. By mid-2026, the same threat actor group, known as CyberAv3ngers, had expanded their operations to more than 30 water systems across 12 states, including Minnesota, Michigan, New Jersey, and Alabama. Operators were locked out of their own systems. Sensors were tampered with. Boil-water notices were issued. The threat is real, active, and growing.


So what do we do with that information? Here are the top lessons learned and, more importantly, what you can do about them.



What Actually Happened: The Attack Profile


CyberAv3ngers is a hacking group officially attributed by the U.S. government to the IRGC Cyber-Electronic Command. Their method is straightforward and repeatable:


  • They scan the internet for exposed industrial controllers, specifically Programmable Logic Controllers (PLCs) and Human Machine Interfaces (HMIs).

  • They log in using default or weak passwords.

  • They lock operators out by changing credentials, alter sensor settings, and in some cases deploy custom malware called IOCONTROL.


The Aliquippa attack targeted a Unitronics PLC, an Israeli-made device, accessible directly over the public internet on port 20256. No specialized hacking tools were required. No zero-day exploits. Just a default password left unchanged and a device that should never have been exposed to the open internet.


In the 2026 Minnesota campaign, attackers modified Rockwell Automation controllers using a known, unpatchable authentication bypass vulnerability (CVE-2021-22681). The result: reduced water pressure, localized flooding, and public health warnings across dozens of communities.



Lessons Learned: What These Attacks Reveal


1. Default Passwords Are a Critical Failure Point


Every confirmed attack in this campaign exploited default or unchanged credentials. This is not a sophisticated vulnerability. It is basic hygiene that was skipped. The question for every water utility, and every facility that uses industrial control systems, is simple: have you actually changed the default passwords on every connected device?


Corrective action: CISA and the EPA now mandate that utilities immediately audit all internet-connected devices, change default credentials, and enable multi-factor authentication (MFA) wherever possible.


2. Critical Infrastructure Should Not Be Internet-Facing


Water treatment PLCs and HMIs have no business being directly accessible over the public internet. Remote access, when necessary, should be routed through a secure VPN or encrypted tunnel, not exposed on an open port. The convenience of remote monitoring is not worth the risk of a nation-state actor walking through the front door.


Corrective action: Federal advisories now require utilities to physically disconnect PLCs from public internet access and implement network segmentation between operational technology (OT) and information technology (IT) systems.


3. Manual Operation Capability Prevented Disaster


The single most important reason these attacks did not cause mass casualties is that operators could fall back to manual control. In Aliquippa, staff switched to manual operations immediately. The automated system was compromised, but trained humans could still run the plant. That redundancy was the difference between an incident and a catastrophe.


Corrective action: Every facility must regularly drill manual operations. Written procedures, trained personnel, and tested fallback processes are not optional. They are the last line of defense.


4. Small Systems Are Disproportionately Vulnerable


Water utilities serving fewer than 3,300 people are often run with minimal IT staff, no dedicated cybersecurity personnel, and aging equipment. These small systems represent a large share of U.S. drinking water infrastructure and are the easiest targets. Their limited budgets mean that even basic protections are sometimes missing.


Corrective action: CISA and EPA have published free, low-cost guidance specifically for small utilities. Regional water councils and state agencies now offer shared cybersecurity services. Awareness is the first step, followed by applying no-cost controls like disabling unused ports and restricting remote access.


5. Geopolitical Tensions Translate Directly Into Infrastructure Risk


The Aliquippa attack was triggered, in part, by the use of Israeli-made Unitronics equipment. The hackers were not targeting Aliquippa specifically. They were targeting a brand. This means the risk is not always about who you are. It is about what equipment you use and what political moment you are operating in. Supply chain origin is now a security consideration.


Corrective action: Utilities should maintain an accurate inventory of all connected hardware, including country of origin. Federal guidance now recommends evaluating equipment sourcing as part of risk assessments.



What This Means for You as a Prepared Individual


Even if you trust your local water utility, these attacks reveal a hard truth: the systems that deliver clean water to your tap are vulnerable in ways that could disrupt service with little warning. A cyberattack that locks operators out of a booster station can drop water pressure across an entire township. Sensor tampering can trigger boil-water notices that last days or weeks. You cannot control what happens upstream, but you can control your own readiness.


Store Water Now


FEMA recommends one gallon per person per day, for a minimum of three days. Aim for two weeks. Store in food-grade containers, away from direct sunlight. Rotate every six months. This is your first and most important buffer against any disruption to municipal supply.

Have a Filtration Backup


A quality gravity filter (such as a Berkey or Sawyer system) can treat water from alternative sources like streams, rainwater, or pools in an emergency. Pair it with water purification tablets as a secondary option. Filtration handles biological threats; tablets handle a broader range of contaminants.

Know Your Alert System


Sign up for your local utility's emergency notifications and your county emergency management alerts. Boil-water notices and service disruptions are often announced via text or app. If you receive one, act on it immediately, before your stored supply runs low.



Practical Steps You Can Take This Week


  • Inventory your current water storage. Do you have enough for 72 hours? Two weeks?

  • Purchase or inspect a water filtration system. Test it before you need it.

  • Register for emergency alerts from your local water utility and county government.

  • Identify a secondary water source near your home (creek, lake, rainwater collection) and know how to treat it.

  • If you run or manage a small business, ask your facilities team whether your building's water systems or industrial equipment use default passwords or public internet connections.



The Bigger Picture


The Iranian cyberattacks on U.S. water systems are not a fringe event. They are a preview. Nation-state actors have demonstrated both the capability and the willingness to target the infrastructure that keeps communities alive. The good news is that none of these attacks, so far, have caused mass casualties. Manual operations, alert operators, and rapid federal response have held the line.


But "held the line" is not the same as "solved the problem." The attacks are escalating in scale and sophistication, from defaced screens in 2023 to custom malware deployed across a dozen states in 2026. The window to prepare, both at the institutional level and the individual level, is open. Use it.


Water is not optional. Make sure you are never more than a few days from running out of options.

 
 
 

Recent Posts

See All

Comments


bottom of page