Iranian Incursions into State Water Systems Decades in the Making

We’ve known about these vulnerabilities a very long time.

9

Comments

NYT (“Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran“):

The scope of cyberattacks on U.S. water systems has grown to include at least seven states and may be far wider, officials and experts warned, as the authorities raced to safeguard the nation’s water supply against an assault that increasingly appeared to be the work of Iran.

While there were no indications that any water supply had been altered or made unsafe to drink, state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure. Minnesota first publicly reported the attacks, and now Michigan says its systems have also been targeted.

The attack has little precedent, experts said, but has long been the stuff of nightmares and sensationalized Hollywood thrillers: an apparent cyberattack by a foreign power during a time of war that could, at least in theory, jeopardize the health and safety of Americans.

Officials cautioned that they had not definitively determined that Iran was responsible for the attack and that the investigation was still preliminary. But they said Iran had stepped up cyberattacks since the U.S. and Israel launched a war against the country five months ago, and had previously targeted similar water systems and other critical infrastructure in the U.S. There seemed no financial motive, making a criminal attack less likely.

[…]

Alex Orleans, a former U.S. government cybersecurity contractor who specializes in tracking Iranian hacking groups, said Tehran had been engaging in a wide variety of hacking operations against U.S., Israeli and Middle Eastern targets since the start of the war in February. But the intrusions into the U.S. water systems appeared to be a significant escalation.

“What’s unprecedented here is that we’re seeing direct, tangible effects to live industrial control systems inside U.S. critical infrastructure,” said Mr. Orleans, who is now the chief of threat intelligence at Sublime Security, an email protection company.

The U.S. Cybersecurity and Infrastructure Security Agency, in an advisory issued Thursday, said the hackers were “targeting water entities of all sizes” and recommended facilities unplug vulnerable controllers from the internet. The hacking activity, it added, had “resulted in boil water notices and sustained manual operations.”

The agency has for months been warning the public that Iran may seek to compromise water utilities and other critical infrastructure.

Former intelligence officials and cybersecurity experts said the hackers were likely engaging in opportunistic behavior rather than selecting specific cities and towns to infiltrate. That means that potentially any facility using the vulnerable internet-connected operational systems was at risk.

Iran, Mr. Orleans said, was likely looking to infiltrate as many victims networks as possible throughout the states before they can protect against “the opportunistic tradecraft that the U.S. government has offered multiple, explicit warnings about.”

This is not surprising. Indeed, Iranian forces have been exploiting these vulnerabilities for years—well before this war was launched. A September 2025 CSIS report, “A Playbook for Winning the Cyber War: Part 5: Evaluating U.S. Cyber Strategy,” noted,

Characterizing cyber governance as “pluralistic” is a diplomatic way of saying it is decentralized or even chaotic. Defense in the United States is multilayered, but rather than overlap and create redundancies, the layers leave significant gaps. The United States has very little by way of an overall defensive umbrella. DOD is responsible for securing its own networks (the Department of Defense Information Networks, or DODIN), and by necessity, that defense is fairly strong. By contrast, civilian non-Title 10, non-Title 50 agencies—from the Department of Commerce to the National Archives—are responsible for funding and executing their own cyber defense, and that defense is chronically underfunded.

[…]

At the state, local, tribal, and territorial (SLTT) level, the picture is far bleaker. States only recently began to realize that they are a target, thanks to the Russian attempts to interfere in the 2016 election and an ongoing epidemic of ransomware attacks. Only a handful of federal programs exist to assist SLTT governments …

[…]

Critical infrastructure is where this gap is most stark. In much of the United States, local authorities or private entities run water, power, and some transportation. For example, in the water sector, there are approximately 50,000 water utilities, or an estimated 153,000 systems, 94 percent of which are run by local or private entities. After Iran attacked several water facilities in 2023, the Associated Press reported that one oft-heard excuse was “it’s difficult to invest in cybersecurity when upkeep of pipes and other water infrastructure is already underfunded.” The net effect is a deeply vulnerable set of critical infrastructure facilities


In late 2023, actors affiliated with the IRGC–Quds Force attacked a municipal water authority in Pennsylvania, along with others from across the country, because the water authority used software from Unitronics, an Israeli software firm. The attack compromised systems, displaying the image on the next page on the water authority’s screens. The hackers disabled a water pressure monitor in at least one system, prompting the authority to switch to manual operation. It was not a sophisticated attack; default passwords and lax security were enough. [emphases mine]

The problem is decades old. Writing in Foreign Affairs in October 2025 (“The End of Cybersecurity: America’s digital defenses are failing – But AI Can Save them”), former Director of the Cybersecurity and Infrastructure Security Agency at the State Department Jen Easterly observed,

In November 1988, the Morris worm—an experimental computer program written by a curious graduate student—unintentionally crippled the early Internet and exposed for the first time the serious consequences of poorly designed software. Nearly 40 years later, the world still runs on fragile code riddled with the same kinds of flaws and defects. Amid frequent news reports about hacks and leaks, a key truth is often overlooked: the United States does not have a cybersecurity problem. It has a software quality problem. The multibillion-dollar cybersecurity industry largely exists to compensate for insecure software.

The impact of persistent weaknesses in U.S. software is playing out in real time. Since at least 2021, for instance, hackers connected to China’s Ministry of State Security and People’s Liberation Army have exploited the same types of flaws that the Morris Worm feasted on decades ago. These groups—referred to as Salt Typhoon and Volt Typhoon—have taken advantage of unpatched systems, poorly secured routers, and devices built for connectivity rather than resilience to infiltrate telecommunications networks, transportation systems, and power utilities. And just this year, Russian Federal Security Service hackers exploited an unpatched flaw in networking devices to compromise thousands of routers and switches connected to U.S. infrastructure. As more institutions, from hospitals to ports, rely on software to function, unsafe code is a growing threat to the United States.

These vulnerabilities endure because software vendors face few incentives to prioritize security. It remains cheaper and faster to shift the costs of insecurity downstream to customers. And because much of the code that underpins critical infrastructure is decades old, rewriting it securely has long been too expensive and time-consuming to make business sense.

The silver lining is that our systems’ diffusion brings resiliency in addition to vulnerability. Thousands of independently operated, poorly-maintained systems are indeed problematic. But they have to be hacked individually.

9 responses to “Iranian Incursions into State Water Systems Decades in the Making”

  1. But they have to be hacked individually.

    Experience with script-kiddies and botnets suggests that’s not as reassuring as you suggest: each water control system has to be hacked individually, but lists of addresses of access points are forever, scripts can do most of the work, and there are lots of available processors all over the country to run the scripts.

    A few decades ago, the Bell System reached the obvious conclusion that remote access to the software that ran the telephony switches was convenient and sped response times for problems. They also decided that it was risky as hell, and chose to spend the money to build a physically separate control network. Air-gapped from the other private and public networks the Bell System operated. At Bell Labs, if you were even suspected of breaking the rule against interconnecting networks, you were escorted empty-handed to the front door and denied access while the investigation was conducted.

    As a final thought, the long, long tail of small and tiny systems doesn’t matter. Take out New York, LA, Chicago, and Houston and it’s already a massive disaster.

    4
    1. @michael cain: Yes, fair points all. Easterly thinks AI scripts can be used to mass-update codes that are currently vulnerable. I fear the offense will always have the advantage on that score.

      1
  2. I’m sure Fatso is correct, Mike Walz is behind this.
    /snark
    No matter what the existing vulnerabilities are I’m sure the incompetence and unseriousness of the administration is extremely helpful.

    1. @Daryl I think you mean Tim Walz? Mike Waltz is the UN Ambassador.

      1. Thank you for correcting me.
        Mike Waltz is a useless buffoon.

        BTW…your photo appears as my avatar, for your sake I hope that’s only on my phone!!!

        1. It’s here on my laptop, Daryl

        2. @daryl I tracked the bug down to a plug-in

  3. “it’s difficult to invest in cybersecurity when upkeep of pipes and other water infrastructure is already underfunded.”

    I love how we are one of the main drivers of our own demise and that somehow we’ve decided maintenance and upkeep are a socialist plot.

    1
  4. Somebody suggested that was a warning by the government of Iran:
    The US can bomb desalination plats, but they can screw with US water in retaliation.