
FBI says Iranian hackers may be behind attacks on water systems in seven states, targeting Rockwell PLCs and disrupting operations. Public health risk if pressure loss occurs.
Alpha Score of 45 reflects weak overall profile with moderate momentum, weak value, moderate quality. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
Investigators are probing whether a wave of cyberattacks targeting water and wastewater utilities across at least seven US states is the work of Iranian hackers, CBS cited US officials as saying. The FBI and Environmental Protection Agency issued a joint warning July 30, saying malicious actors had exploited internet-connected Rockwell Automation programmable logic controllers (PLCs) at facilities in multiple states, disrupting operations.
The attackers gained remote access to exposed Rockwell MicroLogix 1100 and 1400 series PLCs, the agencies said. They changed device IP addresses and passwords, locked operators out of monitoring systems, and modified PLC project files. At least one utility reported discrepancies in ladder logic, the programming that governs equipment behavior. The operational impact varied: some facilities lost visibility into connected equipment, and the FBI warned that pressure loss in water systems could allow untreated groundwater to seep into drinking water pipelines, creating public health concerns.
The attacks have been ongoing since July 27, according to the agencies. While authorities are examining possible Iranian involvement, they cautioned that the attacks have not been definitively attributed and the assessment could change as more technical evidence is collected. Officials are also investigating whether the attackers deliberately attempted to appear Iran-based to exploit heightened tensions between Washington and Tehran.
The FBI said the attacks affected industrial control systems that manage essential functions within water and wastewater treatment facilities. The warning noted that similar risks may exist for other industrial control systems connected directly to the internet, not just the Rockwell PLCs targeted this time.
The suspected Iranian connection is being examined against the backdrop of previous cyber campaigns. In 2023, hackers linked to Iran's Islamic Revolutionary Guard Corps breached PLCs at several US water facilities by exploiting default credentials, according to the Cybersecurity and Infrastructure Security Agency. In a separate case, the US Department of Justice charged an Iranian hacker for allegedly accessing the control system of a dam in Rye, New York, in 2013.
The targeted Rockwell Automation PLCs are widely used in industrial settings. Rockwell Automation, the manufacturer, has an Alpha Score of 55 out of 100, reflecting mixed sentiment among analysts and investors. The company's stock page shows that the industrial automation sector faces ongoing cybersecurity scrutiny as critical infrastructure attacks become more frequent.
What would reduce the risk? Utilities can disconnect PLCs from the internet, enforce strong password policies, segment networks, and monitor for unauthorized access. The FBI and EPA urged water system operators to review their OT device exposure and implement the mitigations outlined in the joint advisory.
What would make the situation worse? A definitive attribution to Iran could escalate geopolitical tensions, potentially triggering retaliatory cyber operations. Broader exploitation of similar third-party network configurations across multiple organizations could expand the attack surface. The FBI said it is still collecting technical evidence and has not ruled out other actors.
The investigation continues as the FBI and EPA work with affected utilities to restore operations and secure systems. No group has claimed responsibility.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.