Iran-linked hackers reportedly targeted 100 U.S. water utilities amid heightened U.S.-Iran military tensions. Broader activity has also sought access to internet-exposed water, energy, and telecommunications systems, with attackers appearing to focus on reachable operational environments and other remotely accessible infrastructure.
There is no public evidence that the activity caused major disruption or achieved a strategic cyberattack, but the attempted access and reconnaissance could enable future operations and signal coercive intent. The EPA is providing $11 million to strengthen water-sector cybersecurity; infrastructure operators should restrict remote access, rotate credentials, segment operational technology, improve logging, and test incident-response plans.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. State Department offered a $10 million reward for information on Amir Yaryab, alleging he leads the IRGC Cyber-Electronic Command and oversees or directs CyberAv3ngers, Dadeh Afzar Arman, Mehrsam Andisheh Saz Nik, Shahid Hemmat, and Shahid Shushtari. Officials said these groups have targeted civilian and critical-infrastructure sectors across the United States, Europe, and the Middle East.
The U.S. Environmental Protection Agency is providing $11 million to improve cybersecurity for water systems.
Bloomberg reported that Iran-linked hackers hit 100 American water utilities; the available material does not identify the actor, affected utilities, methods, timing, or operational impact. Separate reporting characterized Iranian-linked activity during heightened U.S.-Iran confrontation as attempted access to accessible internet-connected water, energy, and telecommunications systems, with no public evidence of major disruption.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecybercenter.space
Open sourcebloomberg.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.