In the past few weeks, cyberattacks that officials suspect may be linked to Iran-backed hackers have hit water systems in at least a dozen U.S. states, including Michigan, Minnesota, Georgia, New Jersey, and South Dakota. In Georgia, the Clayton County Water Authority, which serves 300,000 customers near Atlanta, had to issue a boil water advisory in July after cyber activity caused a pressure drop. Service was restored within hours, and drinking water has stayed safe throughout these incidents. The pattern is still worth every utility's attention, including utilities that are not direct targets yet.
The short version
- Cyberattacks suspected to be linked to Iran-backed actors have hit water systems in at least 12 states, with more than 30 community water systems affected in Minnesota alone.
- The attacks are targeting operational technology, meaning the systems that directly control pumps, valves, and treatment processes. They are not targeting billing or customer-facing software.
- The FBI, EPA, and CISA issued a joint warning on July 30 after threat actors remotely accessed water and wastewater operating systems in at least seven states, causing utilities to lose monitoring and control functionality.
- The tactics resemble a 2023 campaign by CyberAv3ngers, a group linked to Iran's Revolutionary Guard, which exploited default passwords on water-system controllers.
- Your billing and customer information system is not the target of these specific attacks. The underlying lesson still applies to every system your utility runs: weak passwords and exposed remote access are what attackers actually use.
What's actually happening
These attacks are hitting operational technology: the industrial control systems, programmable logic controllers, and SCADA setups that physically operate pumps, valves, and treatment equipment. In several cases, hackers gained remote access to these controls directly. Some utilities lost the ability to monitor or operate their systems remotely and had to switch to manual operation.
That is a different attack surface than the software utilities use to bill customers, track accounts, or manage customer service. It is worth being precise about the distinction, because the fix for OT security and the fix for billing security are not the same thing. But the entry point in most of these campaigns has been strikingly low-tech. Default or weak passwords, and internet-exposed systems that should not have been reachable from outside at all. That is not an OT-specific weakness. It is a weakness anywhere access controls are loose.
Why this should raise the bar everywhere, not just in the plant
Attackers go after the easiest door, not the most important one.The 2023 CyberAv3ngers campaign and this year's activity both relied on default passwords, not sophisticated exploits. That is a sobering fact for any utility system. Attackers are not picking locks, they are walking through doors that were never locked. Any system that still uses default or weak credentials is exposed the same way, customer portals and admin tools included.
Federal guidance is now explicit and public.The July 30 joint advisory from the FBI, EPA, and CISA specifically told water utilities to disconnect operating programs from the internet and strengthen password protections and firewalls. When three federal agencies issue a joint warning naming a sector, that is a signal to review every system's exposure, not just the one named in the headline.
Utility staff are stretched thin, and security work competes with everything else.Most small utilities do not have a dedicated security team. Password policy, remote access review, and vendor security questions often fall to whoever is already managing billing, customer service, and operations. That is exactly why it is worth periodically asking pointed questions about every vendor and every system, instead of assuming the software you are not thinking about is fine.
A visible incident anywhere in the sector affects trust everywhere in the sector.Customers and boards do not necessarily distinguish between plant controls and office software when they hear that a utility got hacked. A boil water advisory at one utility, even from an unrelated cause, raises questions at every utility nearby. Being able to say what you checked matters even when your systems were not the ones affected.
Questions worth asking about every system you run
Does anything still use a default or shared password?This is the single most common entry point across these campaigns. Check controllers, admin panels, and any system with a factory-set login, not just the obvious ones.
What is actually reachable from the open internet?Systems that do not need to be internet-facing should not be. If you are not sure what is exposed, that is worth finding out directly rather than assuming.
Who has remote access, and is it still needed?Vendor access, contractor access, and old employee accounts are common gaps. A periodic review catches access that should have been revoked.
What does your vendor do on their end?Ask your software vendors what they do for authentication, monitoring, and incident response. That goes for billing, OT, and everything else. If you do not know the answer for a system you use every day, that is a gap worth closing.
Where Current fits, and where it doesn't
Current is a billing and customer information system, not an OT or SCADA platform, so it is not part of the specific attack surface these advisories describe. We are not going to overstate our relevance to a story about pump controllers and treatment plants.
What we can say is that the same discipline applies to any system handling utility data and customer information. Strong authentication, no shared default credentials, and a vendor who treats security as a baseline rather than an afterthought. If you have questions about how Current approaches account security and access controls, we are glad to walk through it directly rather than in the abstract.
The bigger takeaway
These attacks are a reminder that utility infrastructure is a target across the board, and that the vulnerabilities attackers exploit are usually mundane. Default passwords, unnecessary internet exposure, and unreviewed access. That applies whether the system in question controls a pump or holds a customer's account balance. Treat this as a prompt to review access and credentials across everything your utility runs, not just the systems named in this week's headlines.
Common questions
- Are Iranian hackers targeting water treatment systems specifically?
- Federal officials suspect a possible link between Iran-backed actors and recent cyberattacks on water systems in at least a dozen states, though no formal attribution has been made as of early August 2026. The targeted systems are operational technology, meaning the industrial controls that operate pumps, valves, and treatment processes.
- Has drinking water been affected by these attacks?
- According to officials, drinking water has remained safe throughout these incidents. Some utilities experienced pressure drops or lost remote monitoring and control capability, requiring a temporary switch to manual operation, but water quality itself has not been compromised.
- What did the July 30 federal advisory say?
- The FBI, EPA, and CISA jointly warned that threat actors had remotely accessed water and wastewater operating systems in at least seven states, causing utilities to lose monitoring and control functionality. The agencies advised disconnecting operating programs from the internet and strengthening passwords and firewalls.
- Is a utility's billing system at risk from this specific campaign?
- These attacks have targeted operational technology, not billing or customer information systems. That said, the underlying weaknesses these campaigns exploit, default passwords and unnecessary internet exposure, can exist in any system. It is a reasonable prompt to review security across your full software stack, not just OT.
- What should a utility do right now in response to this news?
- Review every system for default or weak passwords, confirm what is actually exposed to the internet, audit who has remote access and whether they still need it, and ask every vendor what they do to secure their platform.