Ethical Hacking News
Iranian hackers have been targeting US water infrastructure, with confirmed attacks now reaching at least 12 states across New Jersey and Alabama, bringing the same consistent pattern of limited disruptions despite attacks on critical systems. Experts emphasize the importance of cybersecurity measures to protect against such threats.
Iran-linked hackers are conducting a campaign of cyberattacks against critical infrastructure, targeting industrial control systems in the US. The attacks primarily focus on operational technology (OT) and industrial control systems, with disruptions minimal despite facility shutdowns. CISA warns that attackers are scanning for exposed systems, particularly those made by Rockwell Automation's PLCs. At least seven US states have been targeted so far, with several others issuing warnings to water utilities. States such as New Jersey and Alabama experienced temporary disruptions, while drinking water supply remained safe. Security experts emphasize the risk of hackers controlling water pressure, leading to flooding or reduced water flow.
Iran-linked hackers have been embarking on a campaign of cyberattacks against critical infrastructure, specifically targeting industrial control systems in several states across the United States, particularly New Jersey and Alabama.
The pattern observed thus far reveals that these attacks are targeting operational technology (OT) and industrial control systems. These facilities were forced to shut down systems as a precautionary measure, yet disruptions remained minimal in every case. Drinking water supply remained safe throughout all incidents reported so far.
A recent alert from the Cybersecurity and Infrastructure Security Agency (CISA) warns that these attacks are linked to Iranian hackers targeting PLCs and industrial control systems made by Rockwell Automation. The agency stresses the importance of removing such systems from direct internet exposure, as attackers are scanning for exactly that exposure and finding it.
Minnesota was first to confirm over 30 affected water systems, followed by Michigan, South Dakota, and Georgia, with two additional states now under attack.
In Alabama, the Childersburg Water, Sewer and Gas system reported a cyberattack targeting their industrial control systems on July 27, prompting officials to temporarily disconnect the system while additional safeguards are put in place.
The FBI has confirmed that at least seven states have been targeted so far as of July 30. Other states, including Wisconsin, Pennsylvania, and Washington, have issued warnings to water utilities without confirming attacks. New York has announced more than $9 million in grants to strengthen water sector cybersecurity.
In New Jersey, the City of Cape May Sewer Department and the Borough of Woodbine Water Department reported being targeted by hackers on Thursday, July 27, with both systems impacted for approximately 12 hours. The attack was carried out nearly simultaneously in the morning. Officials confirmed that no impact on water quality or safety occurred.
Security experts emphasize that once a local water system is compromised, hackers can control the water pressure, potentially leading to increased pressure causing flooding, decreased pressure resulting in reduced water flow, or even complete lack of water supply.
The incident highlights the growing threat of Iranian cyberattacks against critical infrastructure and underscores the need for robust cybersecurity measures to be put in place. It also serves as a reminder that even seemingly minor vulnerabilities can pose significant risks if left unchecked.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Looming-Threat-of-Iranian-Cyberattacks-on-US-Water-Infrastructure-ehn.shtml
https://securityaffairs.com/197012/hacking/iran-linked-hackers-target-more-us-water-infrastructure-in-new-jersey-and-alabama.html
Published: Tue Aug 11 13:38:25 2026 by llama3.2 3B Q4_K_M