U.S. water-sector officials warned that attacks attributed by the government to Iran targeted water facilities over the summer, while Iran-linked and pro-Russian actors have also been alleged to target small East Coast utilities. Reported targets included internet-accessible operational technology, such as Eclipse 9800i-series monitoring and flushing stations and PLCs that manage chlorine residuals; however, the specific advisory describing those systems did not identify victims or provide indicators of compromise, forensic evidence, or independently verified attribution.
WaterISAC said aging, exposed OT and PLCs, insecure systems-integrator connections, phishing, and weak cyber hygiene—particularly at smaller utilities—remain key intrusion paths. CISA has also warned that Russian and Chinese actors may pose threats to the sector. WaterISAC is partnering with Cyware to expand threat-intelligence sharing and provide smaller utilities with stronger cross-sector defensive support.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
WaterISAC announced a partnership with Cyware to use its threat-intelligence platform and speed information sharing across the water sector. The arrangement is intended to enable cross-sector intelligence sharing through Cyware's relationships with other ISACs.
The U.S. government reportedly assessed that Iran was responsible for attacks on water facilities during the summer. CISA alerts also identified Iran as a threat associated with the incidents and warned the sector of potential Russian and Chinese threats.
A threat advisory alleged that Iran-linked hackers, with activity also associated with pro-Russian groups, targeted small U.S. East Coast water utilities. It alleged compromise of Eclipse 9800i monitoring and flushing stations and tampering with PLCs managing chlorine residual levels, but supplied no named victims, dates, indicators, or independently verifiable attribution evidence.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.