Lead story
Iranian Hackers Hit Water Systems in 12 US States — and the Pumps Actually Stopped
Water utilities across at least 12 US states have reported cyberattacks on their operational technology, with the campaign now confirmed to include South Dakota and Georgia — the latter after Clayton County reported a pump station disruption. US officials have linked the activity to Iranian-affiliated hackers, and the scope keeps growing with each day's reporting.
This one is different from the usual breach-notification cycle. Most cyberattacks hit data: names, card numbers, medical records. What's being targeted here is the industrial control systems that move water through pipes. When a pump station goes offline, the downstream effect isn't a notification letter — it's a service disruption for households and businesses that can't be patched with a forced password reset.
What we know so far: The attacks appear to target operational technology (OT) — the programmable logic controllers and SCADA systems that manage physical infrastructure. These are notoriously difficult environments to defend. Many utilities run legacy equipment that predates modern security practices, runs unsupported software, and is difficult to patch without taking systems offline entirely.
Iran has form here. The 2021 Oldsmar, Florida water treatment incident — where an attacker briefly raised sodium hydroxide levels to dangerous concentrations — put US water sector security firmly on the map. CISA has issued repeated advisories since then, but water utilities are often small municipal operations without dedicated security staff or budgets.
Why 12 states matters: A coordinated campaign spanning more than a dozen states suggests either a well-resourced threat actor, a widely exploited common vulnerability across utility vendors, or both. The geographic spread also makes it harder for defenders to share intelligence quickly — each state's utility sector has its own regulatory structure, and federal coordination through CISA and the EPA's water security division has historically been slow.
The Australian angle is direct. Water infrastructure is explicitly covered under Australia's Security of Critical Infrastructure (SOCI) Act, which was significantly expanded in 2022 to include water and sewerage systems. Australian water utilities — including the major state-owned corporations like Sydney Water, Melbourne Water, and SA Water — are now required to have critical infrastructure risk management programmes in place. An active Iranian campaign against water OT overseas is precisely the threat scenario those obligations were designed to prepare for. The Australian Cyber Security Centre (ACSC) would typically issue a sector advisory off the back of a campaign like this, and operators should be reviewing their OT network segmentation and remote access controls now rather than waiting for one.
What to watch: Whether CISA publishes indicators of compromise tied to the specific intrusion vector — that will tell us whether this is opportunistic exploitation of a known vulnerability (fixable) or a more sophisticated campaign with custom tooling (much harder to remediate). The water sector's OT attack surface isn't shrinking, and Iran has both the motive and demonstrated capability to push further.
