Agonist / Blog Platform How it works Blog
EN TR
Advisory Analysis

Iran-Linked Water Utility Hacks Reach New Jersey and Alabama - Same Playbook, Same Gaps

The list of US states hit by ICS attacks tied to Iran keeps growing, but the entry point hasn't changed: exposed remote access on equipment nobody thought was reachable from the internet.

August 11, 2026 5 min read OT Threat Intelligence
EN TR

Add New Jersey and Alabama to the list of states where water utilities have found their control systems poked, prodded, or defaced by attackers with ties to Iran, and the map now covers well over a dozen states. The headline keeps changing. The technique underneath it hasn’t, and that’s the part worth sitting with.

Same door, different address

Go back to the wave of incidents that started hitting small water authorities a couple of years ago and the pattern is almost boringly consistent: a human-machine interface, often on a small commercial PLC line, left reachable from the open internet, still running a default password, nudged into an unsafe state by someone who never needed custom malware to get in. No zero-day, no supply chain compromise, just a login screen that shouldn’t have been exposed in the first place. Every new state added to the tally is another version of that same story with a different municipal logo on it.

That keeps working because water utilities are structurally set up to be easy targets. Most municipal systems run lean - a handful of operators covering plants, pump stations, and distribution networks with no dedicated security staff, and equipment specified and installed a decade or two before “attack surface” was part of anyone’s job description. Remote access exists because someone genuinely needs to check a tank level at 2 a.m. from a phone, and the fastest way to do that got left running long after the project that justified it wrapped up. Nobody circles back to decommission convenience.

The part that should worry operators more

What should concern water sector leadership isn’t the sophistication of the attackers - there isn’t much - it’s how many utilities still don’t actually know whether their own segmentation holds up. Plenty of systems will tell an auditor their control network is isolated from the internet and from corporate IT. Far fewer have ever tried to prove it by attempting to reach a controller from outside that boundary the way an attacker actually would. The gap between “we believe this is segmented” and “we tested that this is segmented, today, after the last change” is exactly where these incidents keep landing.

Federal advisories issued after the earlier rounds of attacks pushed the obvious fixes: get HMIs off the public internet, change default credentials, put multifactor authentication in front of remote access, and separate operational networks from everything else. That guidance is still correct. The states now joining the list are proof that correct advice sitting in a PDF doesn’t fix a network unless someone goes and checks that it’s actually been applied - and checks again after the next vendor visit, firmware update, or new remote-access tool quietly gets added for convenience.

Small utilities don’t need more guidance documents. They need an affordable, repeatable way to verify that the specific control supposedly keeping an attacker off a specific PLC is actually doing its job, without taking a treatment plant offline to find out. That’s the unglamorous work that has to happen between advisories, and it’s the work most of these incidents suggest never happened at all.

Source: https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/

ICSOT Security

More from the blog