Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Not a drop to drink: Unknown attackers are targeting US water systems, and it could happen here

Whether or not it is Iran behind the attacks, the US attacks have grave implications for critical infrastructure operators in Australia – here’s what they need to know.

Tue, 11 Aug 2026
Not a drop to drink: Unknown attackers are targeting US water systems, and it could happen here

In recent weeks, 12 US states have reported varying degrees of cyber attacks targeting water and wastewater systems.

Minnesota reported cyber attacks on more than 30 water systems between 26 and 27 July, leaving at least one treatment plant offline. Within a week, Michigan reported similar attacks on nine of its water systems, and more states followed suit.

Investigations by state and federal authorities are underway, and while Iran is a prime culprit – CISA, the FBI, and the EPA recently released a joint warning regarding Iranian actors targeting critical infrastructure (CI) – the risk of serious disruption remains.

 
 

“Crews maintained or quickly restored operations using manual or contingency procedures. That is a credit to the utility teams, but it does not make the risk small,” Manish Sharma, chief information security officer at Aurigo Software, told Cyber Daily.

“Water infrastructure presents a particular challenge because utilities often operate across a patchwork of aging assets, legacy control systems, newer connected technologies, and equipment installed and maintained by multiple contractors over decades.

“Cyber security has to account for that complexity. It must be treated as an infrastructure requirement throughout the asset life cycle, from planning and design through construction, commissioning, operation, modernisation, and replacement.”

While the attacks in the US and the conflict between that country and Iran may seem far away, the malicious activity could have “very real implications for Australia’s critical systems”, according to Mickey Bresman, co-founder and CEO of cyber security firm Semperis.

“According to national intelligence agencies, the threat of espionage and foreign interference are at extreme levels and preparation for sabotage is growing in scale and sophistication. In 2024–25, the Australian Cyber Security Centre responded to over 1,200 incidents against critical infrastructure entities,” Bresman said.

“Additionally, Iran continues to view Australia as a legitimate target for covert operations.”

Bresman said that water utilities and other CI operators should assume that adversaries are already inside their systems and act accordingly, paying attention to the following assessment areas:

  • Determine whether default passwords are being used on programmable logic controllers that indirectly control water flow, tank levels, pressure and pump speeds.
  • Identify the components that are most essential in the wake of a cyber attack and prioritise incident response and recovery for those systems.
  • Follow the Australian Signals Directorate’s guidance for critical infrastructure operators – CI Fortify – to strengthen cyber resilience and prepare for threats.
  • Include network disconnect as part of your response plans. This requires an understanding of how to disconnect access and how to operate during the disconnect.
  • Focus not just on fast recovery, but on secure recovery to ensure that threat actors are not maintaining persistence in critical environments.

“Cyber resilience isn’t just about technology,” Bresman said.

“It’s about people, processes, and the ability to act decisively when everything is on the line.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: