Skip to content

Iran Cyberattacks and U.S. Critical Infrastructure: What You Need to Know

Iranian cyber threats against U.S. water, energy and telecom infrastructure are escalating. Here’s what’s happening, what’s at risk and how defenders should respond.

When cybersecurity practitioners gather for CYBR.SEC.CON 2026 the week after next, a lot of discussion will focus on the rapidly escalating attacks against U.S. critical infrastructure. The last two weeks have been especially bad with attacks on multiple water utilities inside the U.S.

Full CYBR.SEC.CON 2026 coverage:

CYBR.SEC.CON 2026: News, Speakers, Agenda & Coverage
Follow CYBR.SEC.CON 2026 in Houston with the latest news, speakers, keynotes, agenda, cybersecurity tracks, AI.SEC.CON highlights, interviews and event coverage.

Iran has attempted cyberattacks against a range of U.S. critical infrastructure in recent weeks, targeting water systems, telecommunications, energy and other infrastructure, according to NBC News reporting citing four people familiar with the matter. The attempts have so far been unsuccessful, but they come as tensions between Washington and Tehran escalate and Iranian hackers threaten additional attacks against American infrastructure.

That is the latest development in a story CYBR.SEC.Media has been following throughout the summer: Iranian-affiliated threat actors going after the operational technology that helps keep water flowing, electricity running and other essential services functioning.

The immediate targets and circumstances have changed. The underlying weakness has not.

Internet-exposed programmable logic controllers. Weak or default credentials. Poorly secured remote access. Aging operational technology. Small infrastructure operators with limited cybersecurity staff and budgets.

The attack surface has been visible for years. The difference now is the geopolitical environment surrounding it.

Related:

Project Watershed 250 Targets Water Cybersecurity
Dragos CEO Robert M. Lee has repeatedly warned that under-resourced water utilities cannot defend themselves against growing cyber threats alone. A new federal-state-industry initiative in Texas aims to start closing that gap.
CISA Warns Iranian Cyber Campaign Threatens Exposed PLCs
The July 22 update to AA26-097A expands the scope of Iranian PLC attacks and lays out urgent mitigation steps for water, energy, and government operators.
Water Utility Attacks in Multiple States Show the Cost of One Old Vulnerability
The latest wave of intrusions at municipal water systems follows the same playbook as Unitronics and Oldsmar because no one is closing the door.

Iran's critical infrastructure campaign is widening

The latest reported Iranian activity goes beyond water.

NBC News reported that the recent attempts included targets in the water, energy and telecommunications sectors. An Iranian hacking group has also threatened "unexpected and critical events" affecting American energy, water and telecommunications infrastructure.

The reported attempts have not produced major disruptions. But focusing only on whether the latest attack succeeded risks missing the larger point.

Iranian-affiliated cyber actors have already demonstrated both the intent and ability to target operational technology.

In April, CISA, the FBI, NSA, EPA, Department of Energy and U.S. Cyber Command warned that Iranian-affiliated actors were exploiting internet-connected PLCs across water and wastewater systems, energy, government facilities and municipal environments.

By July, the warning had grown substantially more serious.

As CYBR.SEC.Media reported at the time, CISA expanded the scope of known targeting beyond Rockwell Automation equipment to Schneider Electric and Siemens devices, warning about the danger to potentially all internet-exposed PLCs.

The attacks were no longer theoretical exercises. Federal agencies said Iranian-affiliated activity had disrupted PLCs across multiple U.S. critical infrastructure sectors through attempts to download malicious project files and manipulate information on human-machine interface and SCADA displays.

And then came the water attacks.

More than 100 water systems targeted

What initially appeared to be a campaign against a few dozen municipal water systems turned out to be substantially larger.

CISA later disclosed that malicious actors targeted more than 100 internet-exposed water and wastewater systems during July alone. Federal authorities said attackers were targeting PLCs connected directly to cellular modems, changing passwords and IP addresses and, in some cases, forcing utilities into manual operations or triggering boil-water notices.

The FBI and EPA said utilities in at least seven states reported incidents beginning July 27 involving Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. Operational effects included loss of pressure and flooding. At least one victim found altered PLC project files and discrepancies in ladder logic.

Reporting has since put the campaign's reach at at least 12 states, with more than 30 municipal water facilities targeted in Minnesota alone. U.S. intelligence officials have reportedly suspected Iranian involvement, although the U.S. government has stopped short of formally attributing the broader water campaign.

CYBR.SEC.Media's earlier analysis of the water attacks highlighted what made the campaign particularly frustrating: Much of this was not sophisticated, never-before-seen tradecraft.

It was another iteration of an old problem.

Attackers found exposed PLCs, SCADA-connected equipment and remote-management interfaces and used relatively basic access techniques to tamper with settings, change passwords and interfere with operators' ability to control equipment.

We've seen versions of this movie before, from Oldsmar to the Iranian-linked Unitronics attacks of 2023.

The attackers keep changing.

The open door keeps looking remarkably similar.

Project Watershed 250 is an attempt to close it

That helps explain the timing and importance of Project Watershed 250, the new six-month pilot launched this week in Texas.

The initiative brings federal agencies, Texas Cyber Command and private cybersecurity companies together to provide cybersecurity resources to water utilities that often cannot afford them on their own. The pilot includes red-team exercises intended to uncover vulnerabilities and cybersecurity and AI technologies designed to help utilities strengthen their defenses.

Dragos is participating, which is particularly notable given CEO Robert M. Lee's repeated warnings about the economics of water cybersecurity.

Lee has argued that roughly 97% of water utilities lack the resources necessary to adequately address the problem. Some have no cybersecurity staff. Some don't have a dedicated IT person. Even free security technology can be difficult to deploy when an organization lacks the people or hardware required to run it.

"This is an economics issue not a lack of caring," Lee wrote recently.

As CYBR.SEC.Media reported in our look at Project Watershed 250, that distinction matters.

A municipal water authority doesn't have the security budget of a Fortune 500 company. Yet it can find itself defending against the same nation-state adversaries.

Project Watershed 250 is an attempt to change that equation by putting federal, state and private-sector resources behind utilities instead of simply issuing another advisory telling them what they should be doing.

The guidance isn't complicated. Doing it is.

There is another uncomfortable theme running through the federal advisories and attacks we've covered.

We largely know what needs to be done.

CISA, the FBI and EPA have repeatedly urged operators to remove PLCs and other OT devices from direct internet exposure, place them behind secure gateways and firewalls, strengthen credentials and strictly control which systems can communicate with controllers.

Operators should also secure remote-access paths, review PLC project files for unauthorized changes, maintain verified offline copies of known-good logic, monitor OT protocols and traffic for suspicious activity and pay particular attention to connections coming from infrastructure that has no legitimate reason to communicate with the environment.

The July CISA update also underscored something that deserves more attention: Attackers may manipulate what operators see on HMI and SCADA displays.

That means resilience cannot depend solely on trusting the screen. Operators need ways to compare displayed information against field instruments, historian data and other independent sources.

In OT, cyber resilience ultimately has to include the ability to keep operating when the digital environment cannot be trusted.

This is bigger than water

Water has become the clearest example because municipal utilities combine enormous societal importance with uneven cybersecurity resources and plenty of aging equipment.

But the latest Iranian activity reinforces why treating this as a "water cybersecurity problem" is too narrow.

The same broad conditions exist elsewhere across U.S. critical infrastructure: legacy equipment, remote connectivity, third-party access, internet-exposed devices and environments where availability has historically taken precedence over security.

Now those weaknesses sit inside an escalating geopolitical conflict.

That does not mean an Iranian cyberattack is about to turn off the lights or poison drinking water across America. The recent reported attempts against U.S. infrastructure were unsuccessful, and even the widespread water campaign produced limited operational effects rather than a national public-health catastrophe.

But unsuccessful attacks are still useful information.

They reveal what adversaries are interested in, what they are willing to touch and where they may try again.

Critical infrastructure takes center stage at CYBR.SEC.CON

All of this will provide an unusually timely backdrop when the cybersecurity community gathers in Houston Sept. 15-16 for CYBR.SEC.CON 2026.

Operational technology and critical infrastructure security are among the conference's specialized areas of focus, and the subject reaches all the way to the keynote stage. Entergy VP and CISO Ann Delenela will deliver "Keeping the Lights On — A Leadership Playbook Forged in Adversity, Built for the Age of AI," bringing three decades of experience defending critical infrastructure into a discussion about security, resilience and leadership.

The timing could hardly be better.

Because the critical-infrastructure conversation has moved beyond whether hostile governments are interested in these systems. They are.

Iranian-affiliated actors have targeted them. Water utilities have been disrupted. Federal agencies have warned repeatedly about exposed PLCs. More than 100 water systems were targeted in a single month. And the latest reporting suggests Iranian hackers are continuing to look across water, energy, telecommunications and other American infrastructure for opportunities.

The harder question now is whether defenders can close those opportunities faster than adversaries can find them.

Project Watershed 250 is one attempt to do that. The guidance from CISA, the FBI and EPA provides another piece. And the conversations happening among OT defenders, infrastructure operators and security leaders at CYBR.SEC.CON will inevitably return to the same basic reality:

America's critical infrastructure doesn't need another warning that somebody might come knocking. They're already at the door.

HOU.SEC.CON CTA

Latest