On April 7, 2026, the U.S. Environmental Protection Agency, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency issued a joint advisory warning of an Iranian-affiliated threat targeting water sector OT systems. The agencies described a range of observed techniques: configuration wiping, software-based manipulation of mechanical sensors, disruption of human-machine interfaces (HMIs), and operational interruptions that caused direct financial loss. The advisory was notable for its emphasis on physical consequences, not just data exposure, signaling a shift in how federal officials are framing the risk to utilities.
Since July 27, utilities in at least seven states had reported incidents. Attackers remotely accessed exposed programmable logic computers (PLCs), changed IP addresses and passwords, and stripped organizations of their ability to monitor or control their own equipment. At least one utility also discovered modified PLC project files after identifying discrepancies in ladder logic, suggesting that some attackers may be positioning for longer-term access rather than immediate disruption.
CISA separately confirmed a significant increase in water-sector PLC targeting and stated that the activity had already resulted in boil-water notices and sustained manual operations at affected facilities. The agency also clarified that utilities of all sizes were being targeted, pushing back against any assumption that smaller systems are beneath an attacker's interest.
Water infrastructure carries a unique vulnerability profile. Many utilities operate legacy control systems that were designed for reliability and longevity, not for connectivity or security. As those systems have gradually been connected to IT networks and remote access tools, particularly during and after the COVID-19 pandemic, the attack surface has expanded without a corresponding investment in security controls. The result is a sector where internet-facing PLCs and HMIs remain common, default credentials are still in use at some facilities, and network segmentation between IT and OT environments is inconsistent.
Iranian-affiliated groups are not the only threat actors with a demonstrated interest in U.S. water systems. In 2021, an attacker remotely accessed a water treatment plant in Oldsmar, Florida, and briefly attempted to increase sodium hydroxide levels to dangerous concentrations. In 2023 and 2024, the Cyber Army of Russia Reborn and Volt Typhoon, a Chinese state-sponsored group, were both linked to intrusion activity targeting water and wastewater utilities. CISA and the EPA have cited persistent underinvestment in cybersecurity as a systemic challenge across the sector, with many small and mid-size utilities lacking dedicated IT or security staff.
The federal advisories from 2026 reflect a pattern that has been building for years. What changed is the frequency and the confirmed operational impact. Boil-water notices, pressure loss, and forced manual control represent exactly the kind of community-level disruption that threat actors are seeking to achieve.
Our Advice Moving Forward
Federal guidance from CISA, the FBI, and the EPA has been consistent on the immediate steps utilities should take. Acting on these recommendations is not optional for organizations that want to maintain operational continuity.
The underlying challenge for many utilities is organizational capacity. Understanding the risk is one thing. Executing a systematic review of OT connectivity, verifying backup integrity, segmenting networks, and hardening remote access requires time, technical expertise, and often external support that smaller utilities do not have in-house. If your utility or organization needs help assessing OT and IT security posture, reviewing remote access controls, or building a cybersecurity baseline that meets federal guidance, InfoPathways can help. Contact us to schedule a security assessment or to learn more about our managed cybersecurity services for critical infrastructure and regulated industries.