America’s Water Systems Left Wide Open By Default Passwords As Iranian Hackers Strike
Weak passwords on industrial equipment didn’t just invite trouble. They handed Iranian-linked attackers the keys to systems that deliver drinking water to millions of Americans.
Over recent weeks, more than 30 municipal water facilities in Minnesota faced coordinated intrusions. The trouble spread. At least a dozen states reported similar hits on water or wastewater operations. Pressure dropped without warning. Some communities issued boil-water notices. Flooding occurred in others. Operators scrambled to flip systems to manual control. Most restored service within hours. Yet the episode laid bare a stubborn flaw that security experts have flagged for years.
The attackers didn’t deploy fancy malware or zero-day exploits. They didn’t need to. Many of the programmable logic controllers, or PLCs, sitting on the public internet still used factory-default credentials. Change the IP address. Reset the password. Take command. Simple steps that produced real disruption.
CNET first highlighted how these weak passwords exposed the water supply to Iranian hackers. The piece quoted a joint statement from the FBI and EPA. “Malicious actors gained access to internet-connected devices, changed the IP addresses and passwords and took control of their operations. Iranian hackers are likely behind the attacks.”
That assessment aligns with earlier warnings. In April 2026, the Cybersecurity and Infrastructure Security Agency, along with the FBI and EPA, updated alerts about Iranian-affiliated actors targeting critical infrastructure. They pointed specifically to water systems. The timing proved uncomfortably close. The Minnesota wave began around July 26.
But this wasn’t the first time. Similar patterns emerged in 2023 when Iran-linked groups hit water utilities via Unitronics PLCs. Many still ran the manufacturer’s default password of “1111.” Facilities that had changed it blocked the attempts. The message was clear then. It remains clear now. Yet adoption lags.
Michael Garcia once served as associate chief at CISA. He now directs policy for the Operational Technology Cybersecurity Coalition. He called the targets “low-hanging fruit.” Garcia added that the PLCs “were connected to the internet that shouldn’t have been connected to the internet.” His words carry weight. They reflect years of frustrated advocacy.
Maurice E. Dawson teaches at the Illinois Institute of Technology. He surveyed the broader picture. “We’re in a lot worse shape than you would think.” Dawson noted the prevalence of older operating systems that rarely receive updates. Budget pressures at small utilities explain part of the gap. Many serve fewer than 10,000 people. There are roughly 156,000 public water systems nationwide. The vast majority fall into that small-category bucket.
And the federal response? Congress approved $1 billion in 2022 for a state and local cybersecurity grant program. That money has been spent. Reauthorization talks continue without resolution. Garcia pointed to the bottom line. “It comes down to cost.”
The recent incidents prompted fresh joint guidance. On July 30, the FBI, EPA and CISA issued updated warnings. They urged operators to disconnect vulnerable PLCs from the internet immediately. Switch to manual operations where possible. Monitor for anomalous changes in set points or pressure. The agencies stopped short of formal attribution to Tehran. Investigators remain wary of false-flag operations. Still, the tradecraft, the lack of ransom demands and the geopolitical context all point toward Iranian actors.
The New York Times reported that U.S. officials suspect Iran in the Minnesota attacks. Three state officials briefed on the probe cited the absence of financial motives and the specific techniques used. The timing coincides with heightened tensions between Washington and Tehran.
The Washington Post detailed how several states reported cyberattacks as spy agencies suspect Iran targeting water. At least seven states initially flagged incidents. The count later climbed toward a dozen. Some utilities saw untreated groundwater risks as pressure fell. Others managed to contain the effects before public health suffered.
Ron Fabela, an industrial control systems researcher, demonstrated the attack vector in interviews. He showed how exposed Rockwell Automation controllers could be located and compromised with minimal effort. Tools like Shodan make discovery trivial. Default credentials turn access into a foregone conclusion.
Earlier this year, an Iranian group called Handala claimed responsibility for breaches at California water systems in Bakersfield, Visalia and Chico. They posted screenshots of resident bills and claimed to hold five gigabytes of data. The utility, California Water Service, said no production or delivery systems were affected. Still, the claims added to a growing list of probes.
Fortune examined Iranian hackers and America’s Achilles heel on water: default passwords. The piece traced the pattern back through multiple campaigns. It noted that sophisticated tools aren’t always required. A quick scan for exposed devices, followed by a default login, often suffices.
Why do these exposures persist? Part of the answer lies in legacy equipment. Many PLCs were installed decades ago when internet connectivity seemed harmless or even convenient for remote monitoring. Vendors sometimes ship with simple defaults to ease initial setup. Operators forget or never receive training to alter them. Patch management proves difficult when systems control physical processes that cannot tolerate downtime.
Small utilities operate with thin staffs. One or two people may handle both treatment chemistry and information technology. Cybersecurity often loses out to immediate operational demands. Federal grants helped some modernize. Yet the funding cliff arrived before habits changed across the board.
The July incidents produced limited physical harm. No deaths. No widespread contamination. Operators acted fast. They isolated affected units. They issued precautionary notices. Residents in places like Maple Plain and Plymouth dealt with temporary boil-water orders. But the psychological impact registered. So did the policy questions.
President Donald Trump responded by criticizing Minnesota Governor Tim Walz’s administration. He avoided direct attribution to Iran in some remarks. Critics saw echoes of past disputes over foreign election interference. Intelligence assessments, however, continued to focus on Tehran-linked actors.
The BBC asked whether Iran hacked water systems in at least seven US states. Cyber experts told the outlet that the pattern fits Tehran’s playbook. The group has targeted Israeli-made equipment in the past. It has also used relatively basic methods to achieve outsized effects.
CBS News reported that at least 12 states saw cyberattacks on water systems possibly linked to Iran-backed hackers. Sources familiar with the investigations described a broad campaign. The desired outcome appeared to be loss of system pressure and potential contamination. The attackers stopped short of maximizing damage. That restraint itself raises questions about their ultimate goals.
So what happens next? CISA continues to push basic hygiene measures. Change default passwords. Use strong, unique credentials. Implement network segmentation. Avoid exposing operational technology directly to the internet. Deploy virtual private networks for any necessary remote access. Monitor logs for unusual activity.
Those steps sound familiar. They’ve appeared in advisory after advisory. Compliance remains uneven. Some utilities have hardened their defenses since the 2023 alerts. Others have not. The gap leaves the entire sector exposed.
FEMA offers parallel advice to the public. Stock one gallon of water per person per day. Store it properly. Know how to treat water by boiling if notices go out. Follow local utilities on social media for rapid updates. These measures buy time. They don’t solve the underlying problem.
Garcia offered a sobering summary. “This has been occurring for years. We’ve just been extremely fortunate that there hasn’t been a mass casualty event. But there is that potential.”
The recent wave serves as another data point in a long series. Default passwords on internet-facing controllers aren’t a theoretical risk. They’ve become a proven attack vector. Iranian actors have used them. Others could follow. The water sector’s decentralized nature makes comprehensive reform difficult. Yet the alternative grows harder to accept with each incident.
Industry groups and federal agencies plan further outreach. Training programs aim at smaller operators. Technology vendors explore secure-by-design initiatives. Congress may revisit the grant program. Progress will depend on sustained attention. Past experience suggests that attention fades until the next headline appears.
For now, the systems run again. Pressure readings stabilized. Residents in affected towns returned to normal routines. The lesson, however, lingers. Critical infrastructure that Americans take for granted can be rattled by credentials that a child could guess. Until that changes, the risk remains. And the next attempt may not stop at temporary disruption.
Popular Products
-
Adjustable Shower Chair Seat$107.56$53.78 -
Adjustable Laptop Desk$91.56$45.78 -
Sunset Lake Landscape Canvas Print$225.56$112.78 -
Adjustable Plug-in LED Night Light$61.56$30.78 -
Portable Alloy Stringing Clamp for Ra...$119.56$59.78