Skip to content
Live newsroom 140 readers online
Sunday, August 23, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingVin Diesel Says He Would Die for Paul Walker's Daughter Meadow Walker
Share Suggestions AVOID AMZN Stage 4 (Conv: 3/5 | Size: 10%)

Weak Passwords Just Exposed Our Water Supply to Iranian Hackers

Tech > Services & Software > Cybersecurity Our critical utility infrastructure can make the same classic mistakes as we do with our everyday connected devices. I’ve spent years writing about the need to update default passwords on internet-connected devices, but the recent cyberattacks on our water systems show that the same preventable flaws continue to […]

By deepak · August 7, 2026 · 3 min read

Tech > Services & Software > Cybersecurity

Our critical utility infrastructure can make the same classic mistakes as we do with our everyday connected devices.

I’ve spent years writing about the need to update default passwords on internet-connected devices, but the recent cyberattacks on our water systems show that the same preventable flaws continue to leave our most critical infrastructure vulnerable. 

Starting on July 26, more than 30 water systems in Minnesota started experiencing symptoms of a coordinated cyberattack. A week and a half later, those attacks had spread to at least a dozen states, leading to widespread disruptions in service, boil-water notices, drops in pressure and flooding. 

In a joint statement on July 30, the Federal Bureau of Investigation and Environmental Protection Agency described a situation that will sound familiar to anyone who’s followed cyberattack stories in recent years: Malicious actors gained access to internet-connected devices, changed the IP addresses and passwords and took control of their operations. Iranian hackers are likely behind the attacks, according to multiple news reports.

In most cases, facilities were able to restore services within hours by switching to manual operations. But experts say the attacks highlight alarming vulnerabilities in the security of our critical infrastructure.

“We’re in a lot worse shape than you would think,” says Maurice E. Dawson, a professor at the Illinois Institute of Technology who studies critical infrastructure cybersecurity. 

The attacks shouldn’t have come as a surprise to anyone. As far back as 2023, the Cybersecurity and Infrastructure Security Agency issued an alert about threats targeting water systems by exploiting internet-connected devices with default passwords or no password at all. 

In April this year, CISA put out another warning to water facilities about Iranian-affiliated actors potentially targeting US water and energy systems. The agency updated the advisory with additional guidance four days before the first attack in Minnesota was reported, listing the specific devices it had observed being targeted. Again, it urged operators to “ensure device passwords are changed from their default.”

I’ve been writing about attacks on Wi-Fi routers for years, and it’s shocking how much CISA’s guidance to water systems mirrors what I tell internet users all the time: Change default credentials, use a VPN, keep devices updated with the latest security patches.

In the recent attacks on water systems, the open doors were industrial computers called programmable logic controllers, or PLCs. Like Wi-Fi routers, PLCs “serve as the central nervous system for complex industrial control systems,” according to Process Solutions, a company that manufactures the devices.

You’ll find them in virtually every industrial setting across the country, including food processing plants, water treatment facilities and electrical substations. Many of them have been in service for decades without security updates, making them inviting targets for attack.

Once found, the passwords were either too weak or too obvious. “It was very much a low-hanging fruit for an actor to go and attack these systems,” said Michael Garcia, policy director of the industry group Operational Technology Cybersecurity Coalition and former CISA associate chief. 

On July 30, the research firm Censys identified 4,148 internet-exposed hosts made by Rockwell Automation, with 71% of them living in the US. Ron Fabela, an industrial control systems researcher, demonstrated how a typical attack might work in an interview with CSO Online. A malicious actor could scan Shodan, a search engine for internet-connected devices, looking for public IP addresses in a specific area. From there, they could identify which PLC model a water facility uses, pull up the manufacturer’s user manual and input the factory login credentials.

“These are PLCs that were connected to the internet that shouldn’t have been connected to the internet,” said Garcia. “And once they were found, they had either no passwords on them or weak passwords like ‘1234’ or ‘password.’”

Source: Read the original article on www.cnet.com