Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services.
Recent incidents show that poorly protected equipment can give attackers direct access to physical operations, with consequences ranging from lost monitoring to flooding and reduced water pressure.
The threat involves several campaigns rather than one newly discovered malware family. Attackers exploit exposed devices, weak passwords, insecure remote access, and legitimate engineering functions.
These weaknesses can let intruders change how equipment operates without deploying sophisticated industrial malware. Analysts from PolySwarm noted this growing risk in an assessment published October 5, 2026.
PolySwarm said in a report shared with Cyber Security News (CSN) that civilian infrastructure compromises can also affect military operations when bases depend on external utilities and suppliers.
The report separates confirmed controller attacks from reconnaissance and preparations for possible future disruption.
That distinction matters: some intrusions have already affected physical processes, while others establish access that could become dangerous during a crisis or conflict.
Beginning July 27, 2026, water and wastewater utilities in at least seven states reported attacks against internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers.
Previous reporting on exposed Rockwell industrial controllers illustrates why equipment reachable from public networks presents such a persistent concern.
Attackers changed passwords and network addresses, interfering with operators’ ability to monitor or control equipment.
At least one affected organization discovered modified controller project files and discrepancies in the programming logic used to manage physical processes.
Reported consequences included flooding and lost water pressure. The FBI warned that sufficiently reduced pressure could potentially allow untreated groundwater into distribution pipes.
This was a warning about possible contamination, not confirmation that contamination occurred during the reported incidents. Authorities have not publicly attributed the July campaign to Iran, Russia, or another named group.
PolySwarm cautioned against merging it with separate Iranian-affiliated activity simply because both involved exposed industrial controllers and disruptive changes.
Earlier attacks against Unitronics controllers demonstrate how basic security failures can produce serious consequences. Between November 2023 and January 2024, CyberAv3ngers compromised at least 75 devices, including at least 34 in the US water and wastewater sector, using default passwords or devices without password protection.
The attackers erased original control logic, installed replacement programming, renamed devices, and altered configurations and ports.
A separate Iranian-affiliated campaign reported in April 2026 disrupted controller operations and manipulated information shown to operators, but officials have not explicitly attributed that campaign to CyberAv3ngers.
The broader concern extends beyond individual utilities. US agencies assess that Volt Typhoon infrastructure intrusions are intended to establish access that could enable disruption during a future crisis.
The group often relies on legitimate administrative tools and stolen credentials rather than distinctive malware. Military installations depend on civilian electricity, water, communications, transportation, fuel, and industrial suppliers.
Disrupting those services could hinder missions without breaching military networks. The report does not establish that the July water attacks specifically targeted military operations.
Meanwhile, pro-Russian groups have been hijacking exposed VNC connections to reach industrial interfaces. Authorities warn that these actors sometimes exaggerate their achievements, yet have also caused actual harm. Limited technical skill does not eliminate the risks of manipulating unfamiliar equipment.
PolySwarm recommends removing unnecessary internet exposure, eliminating default credentials, restricting remote access to authorized users, and monitoring remote sessions.
Operators should also separate business networks from industrial environments and watch for intrusion paths that could bridge the two.
Recovery planning should preserve trusted controller configurations, project files, programming logic, firmware details, and network settings. Teams need tested manual operating procedures when remote control becomes unavailable or unreliable.
Utilities and military planners should map shared dependencies and rehearse cascading outages, coordinating cybersecurity, engineering, operations, and emergency management before disruption occurs.
The report also lists malware sample hashes associated with four featured threat actors. These indicators are reproduced below exactly as supplied; their inclusion does not establish that the samples were deployed in the July water attacks or every campaign discussed here.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
The Wikimedia Foundation has uncovered unauthorized wiki edits, failed hacking attempts, and millions of automated…
Dell has released security updates for five vulnerabilities in Dell System Update (DSU), including a…
Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…
Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…