Digital attacks targeting water and wastewater treatment systems across the United States, believed to be linked to Iranian state actors, have now been confirmed in at least 12 states. The intrusions, which exploit operational technology networks, have forced facility operators to disconnect systems from the internet or revert to manual controls, according to state and federal officials. No impact on safe drinking water has been reported, but the sweep of the campaign underscores persistent gaps in American critical infrastructure defense.

Operational Impact and Foreign Origin

The attackers, using compromised programmable logic controllers manufactured by the Israeli-owned Unitronics, gained access to supervisory control and data acquisition (SCADA) systems that manage water pressure, chemical dosing, and filtration processes. In several instances, operators discovered default credentials had never been changed, providing a trivial entry point. Federal investigators have traced the command-and-control infrastructure to servers previously associated with the Islamic Revolutionary Guard Corps (IRGC) cyber command.

The Cybersecurity and Infrastructure Security Agency (CISA) has not publicly attributed the attacks, but a joint advisory with the FBI confirmed the targeting of the water sector by “an advanced persistent threat group linked to Tehran.” The advisory notes the specific exploitation of public-facing operational technology devices, a pattern consistent with Iran’s 2020 attempt to raise chlorine levels in Israeli water systems—an attack thwarted before harm occurred.

National Security and Fiscal Exposure

The vulnerabilities highlight a lack of investment in domestic infrastructure security, with many municipal utilities operating on constrained budgets that leave them reliant on outdated hardware. Congress has allocated over $1 billion for cyber resilience in water systems since 2018, but distribution has been slow and fragmented across 50,000 distinct utility operators. The American Society of Civil Engineers’ 2021 report card estimates a $434 billion investment gap for the nation's drinking water infrastructure over the next two decades.

The Iranian cyber threat is not new. The Department of Justice indicted multiple IRGC hackers in 2016 for a previous campaign against a Rye Brook, New York dam. Current attacks come as the administration negotiates a readmittance to a nuclear accord with Tehran, a deal critics argue would unfreeze billions in assets and eliminate leverage against IRGC cyber proxies. “The regime funds its cyber war machine with the same accounts we are poised to unfreeze,” a senior intelligence official told Nerve, speaking on condition to discuss active operations. “This is the cost of prioritizing diplomatic engagement over hard deterrence.”

No domestic casualties or contamination have occurred, but the intrusions are a provocation that tests U.S. policy. As long as American critical infrastructure remains digitally porous, foreign adversaries will continue to map it for future use—and geopolitical concessions will not alter that calculation.