On August 8, 2026, US security agencies CISA and FBI announced that hacker groups linked to Iran's Islamic Revolutionary Guard Corps (IRGC) carried out an unprecedented attack on water and wastewater management systems in several US states. The attack was not aimed at data theft or financial extortion, but at directly disrupting the operation of vital industrial control systems that supply the population with drinking water.
According to available information, the targets of the attack were PLC (Programmable Logic Controllers) and SCADA systems used for remote monitoring and control of pumps, pressure, and chemical dosing in water treatment plants. The hackers exploited security vulnerabilities in industrial equipment that was directly connected to the internet without adequate protection, two-factor authentication, or with factory-default passwords.
Taking Control and Political Messages
After gaining control of equipment screens in certain municipal utilities, the attackers left political messages and temporarily disabled automated systems. Engineers were forced to switch to manual operation of the plants to prevent more serious consequences.
Thanks to a swift response and security protocols that allowed switching to manual mode, this wave of attacks did not result in chemical contamination of drinking water or prolonged supply disruptions. CISA officials emphasized that the very fact that a foreign entity managed to access control systems is a serious warning for all government bodies.
Why the Water Sector Is the Most Vulnerable Link
The water supply sector is considered the weakest link within the critical infrastructure of many countries. It consists of thousands of small, local utilities with modest cybersecurity budgets. Unlike the financial sector or telecommunications, which invest billions in network protection, local water utilities often use outdated computer systems that have not been updated for years.
Experts warn that automation technology in such facilities was introduced to reduce costs and facilitate management, but without prior planning for defense against malicious network intrusions. The scenario where hackers could alter chlorine levels in water or cause pipeline ruptures by suddenly closing valves is no longer science fiction but a real danger.
Hybrid Warfare and Global Warning
Cyberattacks on infrastructure have become a key weapon in modern warfare because they allow states and sponsored groups to inflict serious damage at minimal cost. Besides Iran, security reports regularly mention Russia, China, and North Korea as leading actors in this field.
The strategy of these state-sponsored hacker collectives is to infect critical networks of rival countries during peacetime and leave hidden backdoors, so that in the event of geopolitical escalation, they can remotely paralyze the energy or transportation system. This case has served as a stark wake-up call for all European and regional states to urgently review the security of their own municipal networks.
EU Tightens Regulations
The European Union has already tightened regulations through the NIS2 directive, which obliges all operators of essential services to apply the strictest encryption and access control standards. Although wars are still fought with traditional weapons on the front lines, the key battles for the stability of modern society are increasingly taking place invisibly, in lines of code and on network routers.
Protecting drinking water, the electricity grid, and healthcare facilities from cyber intrusions in the coming decade will no longer be just a technical matter for IT departments, but one of the primary pillars of national security for every sovereign state.