6 min read

Beneath the Waterline: Iran's Deniable Campaign Against America's Weakest Infrastructure- 294

Beneath the Waterline: Iran's Deniable Campaign Against America's Weakest Infrastructure- 294

August 11, 2026

Over two days in late July, a handful of programmable logic controllers in small-town Minnesota water plants stopped answering to their operators. No pipes burst and no one was poisoned; in Braham, a city of seventeen hundred people, the water tower simply had to carry the town for a few hours while engineers worked out why the treatment plant had gone dark. Two weeks later, the same quiet pattern had surfaced in at least twelve states, and Washington still would not say, on the record, who was responsible. That reluctance is not a failure of forensics. It is close to the point. What has been unfolding across the American water sector since late July reads less like a hacking spree than a calibrated exercise in staying just beneath the threshold that would force a formal accusation, aimed at the one slice of American critical infrastructure too fragmented, too poor, and too thinly defended to make anyone pay a price for trying.

The campaign's shape has been consistent from the start. Minnesota disclosed the first wave on July 26 and 27, when malicious activity was confirmed across more than thirty community water systems. The technique was almost administrative in its crudeness: attackers changed passwords to lock operators out of their own controllers and altered IP addresses to sever remote monitoring links, forcing utilities back onto manual operation. In Braham, that meant losing the ability to run the well and treatment plant remotely; in Plymouth, a city of eighty thousand outside Minneapolis, communications were restored by the following Tuesday afternoon and water quality was never in question. The Cybersecurity and Infrastructure Security Agency had, by coincidence or foresight, updated its standing advisory on Iranian activity against industrial control systems just days earlier, on July 22, widening the list of targeted equipment beyond Rockwell Automation's Allen-Bradley line to include Schneider Electric and Siemens controllers. By July 30, the FBI was prepared to confirm at least seven affected states; CISA followed with a fresh public alert the same day, describing the same password-and-IP-address tactics documented in Minnesota and again declining to name a culprit.

The map kept widening after that. Michigan, South Dakota, and Georgia surfaced through August, with Georgia's Clayton County Water Authority producing the campaign's most physically consequential incident to date: a temporary drop in water pressure serious enough to prompt a boil-water advisory, resolved within hours. By August 5, ABC News was reporting that at least twelve states had been affected in total, though only a handful had been named publicly. New Jersey and Alabama joined the list on August 10, each tracing back to intrusions on July 27 that had gone undisclosed for two weeks — Cape May and Woodbine's water systems in New Jersey lost only their phone lines, while Alabama's Childersburg Water, Sewer and Gas system saw its industrial controls targeted without any interruption to service. New York, notably, has confirmed no attack at all, yet found it prudent to announce more than nine million dollars in grants to harden a hundred and fifty-three of its own water systems — a preemptive move that says as much about the mood in the sector as any confirmed intrusion does.

No US government agency has formally attributed the campaign to Iran. But the circumstantial case, as officials and researchers describe it, is not subtle. Cynthia Kaiser, formerly deputy assistant director of the FBI's cyber division and now senior vice president of Halcyon's Ransomware Research Center, told SecurityWeek in late July that "most credible researchers and responders would be right to treat it like it's Iran until proven otherwise. When it walks like a duck and talks like a duck, it's really important to call it out." A week later, speaking to The Register at DEF CON on August 7, she went further still: "I'd be shocked if it's not Iran. It's almost certain it's Iran." Retired General and former NSA director Paul Nakasone, on the same stage, described the government's posture as a "measured approach" to attribution while noting that Iran has "certainly shown a history of being able to do this" and that "there's an intent" given the two countries remain, in his word, in conflict. The pattern fits a well-documented history — Iranian hackers were charged in 2016 over an intrusion at a small dam outside New York City, and Iran-linked actors exploited vulnerable cellular routers to reach Israeli water facilities as far back as 2020. Groups fitting that profile, including CyberAv3ngers and Handala, have not been formally linked to the current wave, but investigators describe the tradecraft — and the target selection — as consistent with the Iranian Revolutionary Guard Corps' established playbook.

What the campaign notably lacks is just as telling as what it contains. One security expert consulted by Dark Reading assessed with moderate confidence that the operators were capable of considerably more damage than they had inflicted, and that the objective was less about physical destruction than about imposing cost and disruption on operators and responders across as wide a footprint as possible. The pattern, the same expert observed, resembles a hacktivist campaign in its scale and coordination — except for the one thing hacktivists never skip: nobody has claimed it, and nobody is marketing it. That absence points toward something closer to deniable state signaling than to opportunistic activism — a demonstration of reach calibrated to avoid the kind of unambiguous act that would obligate a response, rather than an attempt to cause harm for its own sake or to win publicity for a cause.

The campaign has also functioned, whether by design or coincidence, as a stress test the American water sector was never built to pass. There are roughly a hundred and seventy thousand drinking water and wastewater systems in the United States, the vast majority of them small, decentralized, and running operational technology installed years ago by third-party integrators who are, as one analyst put it, "not cyber people." Field technicians routinely leave cellular modems, satellite links, or direct port forwards active for remote troubleshooting without informing the utility's own IT staff, let alone federal regulators — a shadow attack surface that predates this campaign by years and will outlast it. The internet-scanning firm Censys has counted roughly ten thousand internet-exposed Rockwell, Siemens, and Schneider controllers across the country, a number that makes the twelve reported states look less like the edge of the problem than a sample of it.

It is against that backdrop that the sector's most consequential response so far did not come from a federal agency at all. On August 10, the volunteer collective DEF CON Franklin and the National Rural Water Association launched the Water Watch Center, a program funding five managed detection and response providers to protect utilities serving fewer than ten thousand people — a category that covers ninety-one percent of America's community water systems. Jake Braun, the project's co-founder and a former Biden administration cyber official, framed the effort in blunt terms: after two years of volunteers embedding directly with individual utilities, "we already know how to do security for small businesses — it's MSSPs. So why don't we just do that?" The structure he described is a pyramid, with the NRWA distributing threat intelligence at the top, five contracted security providers — expanding toward ten, aligned with CISA's regional map — hunting for intrusions across utility networks, and Franklin's volunteer base absorbing the alerts CISA and sector information-sharing groups generate but that utilities themselves have no capacity to act on. In parallel, the Water Watch Center is working with Vanderbilt University on a DARPA-funded research program that builds digital twins of real utility environments and pits automated red-team and blue-team agents against each other, with the explicit goal of eventually deploying AI-driven defense across all hundred and fifty thousand utilities — a scale, Braun noted, that the roughly five-hundred-thousand-person national shortfall in cybersecurity professionals makes otherwise unreachable by any conventional hiring plan.