Urgent.News

the world's headlines, one feed

Editions

Tech

Iranian hackers and America’s Achilles heel on water: default passwords

The FBI and EPA say attackers accessed internet-connected Rockwell Automation controllers and changed their IP addresses and passwords.

Iranian hackers and America’s Achilles heel on water: default passwords

In July 2026, hackers attempted to infiltrate at least 30 municipal water systems across Minnesota. Subsequent reports revealed similar cyberattacks in Michigan, New Jersey, and several other states. The attackers did not target the utility offices but rather focused on small computer systems controlling pumps and valves that deliver drinking water to millions of people.

Utility authorities shut down control computers and performed manual operations, assuring that the water remained safe to drink. Initial suspicions pointed towards hackers potentially affiliated with Iran, although the U.S. government has not officially attributed the attacks.

Water systems in the United States consist of about 152,000 public drinking water systems, which obtain water from various sources and treat it before distributing it to homes and businesses. Small computers, known as programmable logic controllers (PLCs), manage pumps, valves, and other equipment involved in the water delivery process.

These PLCs read sensors monitoring water pressure, chemistry, tank levels, and equipment status, and automatically control pumps, valves, and alarms. They also transmit operational data to a utility's central computer system, which personnel monitor through dashboards.

The hackers targeted PLCs, which can be controlled through internet connections, radio, cellular links, or protective firewalls, secure gateways, or virtual private networks. Many utilities have small staffs, relying on remote connections for monitoring and diagnostics. PLCs can be compromised through direct internet access, weak or stolen passwords, unpatched vulnerabilities, or misconfigured remote-access services.

In some cases, sophisticated malware was not necessary; attackers could exploit default passwords, known security flaws, or compromised remote-access services.

Once hackers gain access, they could change passwords, issue commands, or manipulate the PLC's software. Industrial equipment in service for decades may lack modern security features, and utilities might delay updates to avoid operational disruptions. The Minnesota attacks were reportedly carried out through PLCs communicating directly with the internet, with the attackers changing IP addresses and passwords.

The Cybersecurity and Infrastructure Security Agency recommended that utilities remove controllers and human dashboards from direct internet connections, instead placing them behind properly configured firewalls and other safeguards. When remote access is necessary, utilities should route communications through secure gateways, virtual private networks, and employ strong, unique passwords.

Written by urgent.news from Fortune's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Also reported by 1 other outlet

Read the original at fortune.com →

More in Tech