Federal Agencies Issue Urgent Warning: Foreign Hackers Are Targeting the Computers That Run Water Systems
SecureCyber Threat Alert | July 22, 2026 | Source: Joint Cybersecurity Advisory AA26-097A
The Short Version
Seven federal agencies, including the FBI and CISA, updated an urgent joint advisory on July 22, 2026. Hackers affiliated with Iran are breaking into internet-connected industrial control equipment at US water and wastewater systems, local governments, and energy providers. In some cases they changed how the equipment operates while making the operator screens show normal readings. Some victims experienced operational disruption and financial loss. If any of your control equipment can be reached from the internet, this advisory applies to you.
What Happened
Most water plants, lift stations, and treatment facilities run on small industrial computers called PLCs. Think of a PLC as the autopilot of your plant. It opens valves, starts pumps, manages chemical feeds, and keeps everything inside safe limits without a human touching anything. The screens your operators watch, the HMI and SCADA displays, are the dashboard that shows what the autopilot is doing.
According to the advisory, attackers found PLCs that were connected directly to the internet, often through cellular modems used for remote monitoring. They connected from overseas using the same legitimate programming software that vendors and integrators use every day. No exotic hacking tools required. The equipment was reachable, so they reached it.
Once inside, they downloaded the control programs, modified them, and pushed the changes back to the equipment. At one US victim, the FBI found that the altered program kept the plant appearing to run normally while quietly overriding the instructions responsible for keeping operations within safe limits. The changes also disabled shutdown and alarm logic. In plain terms: they tampered with the furnace, disconnected the smoke detectors, and repainted the thermostat so it always reads 68.
Who Is Behind It
The agencies assess this is the work of Iranian-affiliated threat actors and connect the activity to groups like CyberAv3ngers, which is tied to Iran's Islamic Revolutionary Guard Corps. This is the same crowd behind the November 2023 campaign that compromised at least 75 devices in the US, including equipment at water utilities. The advisory notes this activity has escalated recently in connection with hostilities between Iran, the United States, and Israel.
One important point: this is opportunistic, not personal. These actors scan the entire internet looking for exposed equipment. Being a small rural system does not make you less of a target. It often makes you an easier one, because small systems rely on internet-connected equipment for remote monitoring and rarely have someone watching for intruders.
How This Impacts You
Water and Wastewater Systems is one of three sectors named directly in this advisory, alongside local government and energy. The equipment named includes PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens, and the agencies warn that potentially any internet-exposed PLC is at risk regardless of brand.
If your facility uses remote monitoring, cellular modems on lift stations or well sites, or any control equipment your integrator can reach from outside the plant, you need to find out this week whether that access path is exposed to the open internet.
What To Do Now
Do these first:
- Find out what is exposed. Ask your integrator or IT support one direct question: can any of our PLCs or modems be reached from the internet? Get a written answer.
- Get exposed equipment off the internet. This is the agencies' number one action. Remote access should only happen through a secure gateway or firewall, never through a device sitting directly on the open internet.
- Flip the physical switch. Many controllers have a physical mode switch. Placing it in Run position blocks remote reprogramming. Review and validate the running program first, because switching modes locks in whatever program is currently loaded.
- Change default passwords on every PLC, HMI, and modem. Attackers know the factory defaults better than most operators do.
Then follow up:
- Have your integrator compare the programs running on your PLCs against a known good backup and look for unauthorized changes.
- Create offline backups of your PLC logic and configurations so you can recover quickly.
- Require multifactor authentication for any remote access into the control network.
- Tell your service providers and integrators about this threat, especially anyone who monitors or maintains your equipment remotely.
- Report anything suspicious to the FBI's Internet Crime Complaint Center (ic3.gov) or CISA's 24/7 Operations Center (1-844-729-2472).
How SecureCyber Can Help
SecureCyber works with Ohio water and wastewater systems every day, and we maintain active relationships with the FBI and other law enforcement partners on threats exactly like this one. If you are not sure whether your equipment is exposed, or you want a second set of eyes on your remote access setup, our team can help you find out where you stand and work through the steps above.
You can also check out our Auqua Guardian program page, which is specifically designed for Water and Wastewater operators.
Call us at (937) 388-4405 or email sales@secdef.com.
Are you experiencing a Cybersecurity Emergency? Call our rapid emergency response center 24/7/365 at 937-388-4405.
Sources
- Joint Cybersecurity Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (FBI, CISA, NSA, EPA, DOE, US Cyber Command CNMF, Treasury). Published April 7, 2026. Updated July 22, 2026. Available at cisa.gov.