Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Iran-Linked Hackers Expand US Water System Attacks to Seven States — What Canadian Water Operators Must Know

What Happened

FBI and EPA officials confirmed on August 4 that the wave of cyberattacks targeting US municipal water systems — which began with more than 30 Minnesota utilities on July 26-27 — has extended to water facilities in at least six additional states. Confirmed affected states beyond Minnesota now include Michigan, South Dakota, Georgia, and at least three others that have not been publicly named pending ongoing investigation.

Attackers gained remote access to internet-connected industrial control systems and operational technology at water treatment facilities. The intrusions involved altering network addresses and administrative credentials on ICS equipment, in some cases leaving facility operators temporarily unable to monitor real-time operations through their normal interfaces. No states have reported confirmed disruption to water supply, water treatment, or public health as a result of the attacks.

Iran-backed hackers are the leading attribution assessed by FBI and EPA investigators. The attack pattern is consistent with prior IRGC-affiliated activity against water and wastewater operators documented in the 2023 CISA advisory AA23-335A, in which Iran-affiliated actors exploited Unitronics PLCs with default credentials. The current campaign targets a broader range of internet-exposed ICS than the Unitronics campaign, and FBI has characterized the intrusion tradecraft as consistent with Iranian cyber operators seeking to demonstrate capability against US critical infrastructure rather than to cause immediate physical disruption.

The advisory follows the July 31 CISA/FBI/EPA joint alert on PLC security for water sector operators, which was itself triggered by the initial Minnesota attacks. The escalation to confirmed multi-state activity changes the scope classification of the campaign from a regional incident to a national critical infrastructure event.

Why This Matters for Canadian Organizations

Canadian water and wastewater operators use much of the same ICS and SCADA technology as their US counterparts, including the same brands of PLCs, HMI software, and remote monitoring equipment. The attack methodology — exploiting internet-exposed ICS with default or weak credentials — applies to any operator that has not implemented network segmentation, replaced default credentials, and removed direct internet exposure from OT systems.

Canada has approximately 3,000 drinking water systems and 3,500 wastewater systems across federal, provincial, and municipal jurisdiction. The majority of small and rural systems operate with limited IT security staffing and rely on internet-accessible remote monitoring for practical operational reasons. These systems are not meaningfully less exposed than the Minnesota utilities that were compromised in late July.

The expansion to seven states should be read as a signal that an Iranian-linked threat actor has made water sector ICS a sustained campaign target, not a one-time incident. The Canadian Centre for Cyber Security issued an advisory in April 2026 warning that state-sponsored actors are actively conducting reconnaissance against Canadian critical infrastructure operators, including water utilities. Bill C-26 critical infrastructure reporting obligations, when in force, will require designated operators to notify the government of incidents of this type within 72 hours.

Water utilities operating under provincial Safe Drinking Water Acts and municipal procurement frameworks should treat this campaign as a realistic threat scenario and not a remote US concern. The operational profile — limited IT security resources, aging OT equipment, internet-facing remote access — is common across Canadian systems.

What to Do

Audit internet-facing OT and ICS assets. Any PLC, HMI, SCADA gateway, or remote monitoring system directly accessible from the internet without a VPN or jump host should be treated as actively at risk. Remove direct internet exposure where operationally possible. Where internet access cannot be eliminated immediately, restrict inbound connections to known IP ranges, enforce strong unique credentials, and disable default accounts on all OT equipment.

Review credentials on all ICS and SCADA equipment. The current campaign and the 2023 Unitronics campaign both exploited default or weak credentials. Change default passwords, remove default accounts, and document credential assignment for all OT systems.

Implement network segmentation between IT and OT environments. Operators that have not deployed a demilitarized zone between corporate IT networks and process control networks should treat this as a priority action rather than a future project. The CCCS Industrial Control Systems Security guidance and the CISA Water Sector Cybersecurity Assessment Tool provide frameworks for implementing segmentation in resource-constrained environments.

Report unusual ICS access or credential change events to the CCCS National Cybersecurity Coordination Centre and to provincial water regulatory authorities. Early notification enables coordinated response and sharing of indicators of compromise across the sector.

Source: SecurityWeek | CISA Water Sector

Enjoy this article? Don’t forget to share.