Interestana
Home/News/Iranian Hackers Target US Water Systems With Default Passwords
Fortune3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Iranian Hackers Target US Water Systems With Default Passwords

Iranian Hackers Target US Water Systems With Default Passwords

Hackers, suspected to be aligned with Iran, attempted to breach at least 30 municipal water systems in Minnesota between July 26-27, 2026. Since these initial attempts, similar cyberattacks have been reported in Michigan, New Jersey, and several other U.S. states. The attackers did not target the primary computers used by utility offices. Instead, their focus was on gaining control of smaller, embedded computers within equipment such as pumps and valves, which are essential for delivering drinking water to millions of people. In response to these threats, the affected utilities took measures to counter the attacks by shutting down the compromised control computers. Personnel were dispatched to operate the equipment manually in the field, ensuring the continuity of water supply. Utility officials have stated that the water remained safe to drink throughout these incidents. As a scholar specializing in cyber conflict, the methods employed in these attacks are consistent with those typically seen in international cyber operations. While initial suspicions point towards hackers allegedly associated with Iran, the U.S. government has not yet officially attributed the attacks to any specific entity. The ease with which remote actors can potentially seize control of water systems and disrupt supply or compromise water quality raises significant security concerns. The United States is served by approximately 152,000 public drinking water systems, according to federal government data. These systems typically draw water from sources like lakes, reservoirs, rivers, or underground aquifers. A series of pumps then transport the raw water to treatment plants for filtration and disinfection. Following treatment, additional pumps move the purified water into storage tanks before it is distributed through a network of pipes to homes and businesses, often spanning many square miles. The critical components within these vast systems are small computers known as programmable logic controllers (PLCs). These PLCs are responsible for operating a wide array of industrial equipment, including pumps and valves. They continuously read data from sensors that monitor vital parameters such as water pressure, water chemistry, tank levels, and equipment status. Based on this data, PLCs automatically adjust the operation of pumps, valves, and alarms to maintain the desired water flow and quality. The hackers exploited vulnerabilities in these PLCs, reportedly by using default or easily guessable passwords, which allowed them to attempt to gain unauthorized access and control over these essential industrial control systems.

Original source — read the full reporting at the publisher:

Read on Fortune

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next