Iran-Linked Hackers Target US Water Systems

Iran-linked hackers breached a Pennsylvania water utility, prompting urgent US cybersecurity warnings.

Iran-Linked Hackers Target US Water Systems

Image: the-express.com

US cybersecurity officials have issued an urgent warning after Iranian-linked hackers breached a water utility in Pennsylvania, according to a joint advisory released on July 30, 2026. The attack targeted a Unitronics PLC, a device used in water and wastewater systems, and was traced to an IP address linked to Iran's Islamic Revolutionary Guard Corps (IRGC).

The advisory, from CISA, the FBI, and the EPA, said the hackers exploited poor security practices, including weak passwords and exposure to the internet. In one case, the attackers changed a water treatment system's settings, though officials said the public was not endangered.

While the Pennsylvania incident is confirmed, reports of attacks on water systems in seven states remain unverified. The advisory urges all water utilities to review their security, change default passwords, and disconnect control systems from the internet.

This incident highlights the growing threat to critical infrastructure from state-sponsored hackers. The IRGC has been increasingly active in cyber operations against US targets, and water systems are particularly vulnerable due to aging infrastructure and limited cybersecurity resources.

❓ Frequently Asked Questions

What happened in the Pennsylvania water utility attack?

Iran-linked hackers breached a water utility in Pennsylvania, exploiting weak passwords and internet exposure to access a Unitronics PLC. They changed system settings, but no public danger was reported.

Who issued the advisory about the cyberattack?

The advisory was issued jointly by CISA, the FBI, and the EPA on July 30, 2026.

How can water utilities protect themselves?

Utilities should change default passwords, disconnect control systems from the internet, and follow CISA's recommended security measures.

📰 Source:
the-express.com →
Share: