Critical Infrastructure Security
Water Hacks Raise Questions About Attackers’ True Intent

Three weeks have passed since a series of cyberattacks targeted numerous rural and small-town water and wastewater utilities across at least twelve states, leaving cybersecurity experts pondering the attackers’ motivations. This unprecedented wave of attacks raised alarms about the ramifications on critical infrastructure, particularly concerning water safety.
The cyberattacks, believed to have been carried out by a group linked to Iran’s Islamic Revolutionary Guard Corps, raised fundamental questions about the attackers’ tactics and objectives. According to Josh Corman, an executive in residence at the Institute for Security and Technology and the founder of “I Am The Cavalry,” which promotes the cybersecurity of essential services, the hackers seemingly had unfettered access to the targeted utilities. He emphasized that compromising the operational technology could result in catastrophic consequences for communities reliant on these services. Yet, surprisingly, the damage inflicted during these attacks was minimal, with no indications of unsafe drinking water and only a few communities issuing precautionary boil-water notices.
The attackers managed to infiltrate programmable logic controllers (PLCs)—the computerized devices responsible for managing the pumps and valves that distribute water and administer treatment chemicals. However, instead of launching damaging operations, the hackers changed passwords and IP addresses, thus severing operators’ remote access to these critical systems. This action effectively alerted operators to the security breach, thereby undermining any potential for sustained covert manipulation.
A retired federal law enforcement official, reflecting on the incident, remarked, “They blew up their own operation,” expressing confusion over the attackers’ lack of strategic planning. Corman also noted the lack of any destructive or disruptive actions that could cause physical harm or public panic, leading many analysts to speculate about the underlying intentions behind such abnormal behavior. Iran’s attacks on U.S. soil typically evoke impactful psychological warfare, which was notably absent in this instance.
The U.S. cybersecurity establishment, including the Cybersecurity and Infrastructure Security Agency (CISA), issued warnings regarding Iranian efforts to target internet-exposed PLCs months prior to the attacks. Corman pointed out that the intruders were not looking to initiate a ransom scenario or wreak havoc. Instead, they seemed to be engaged in altering software within the PLCs, disabling alarms and alerts typically sent to operators.
Those familiar with Iranian cyber operations observed that such tactics do not align with their usual preference for aggressive, destructive actions during conflicts. Pascal Geenens, vice president of threat intelligence at Radware, echoed this sentiment, stating, “Iran is known for using wipers. They are known for destructive attacks, but this is just an annoyance.” Restoring PLC functionality would require only physical access, rendering their cyber intrusions less threatening than initially perceived.
Amid ongoing tensions marked by a lengthy U.S.-Israeli conflict with Iran, analysts theorized that the July attacks were an Iranian show of strength—a demonstration of their capability to infiltrate vital systems within the U.S. without triggering severe consequences that might provoke significant retaliation. Observers commented that the relative restraint displayed by Iranian operatives might reflect an understanding of the potential for overwhelming U.S. responses.
In a broader context, the attacks might signal Iran’s intention to establish itself as a formidable adversary capable of striking back at its enemies without overstepping boundaries that could lead to war. A former senior Department of Defense official speculated that the Iranians have calculated their strategic responses in a manner that allows them to convey their capabilities while minimizing risks.
The cyber campaign unfolded against a backdrop of increasing hostilities between Iran and the U.S., particularly following threats directed from the U.S. to strike Iranian desalination plants and reports of hostile actions near the Straits of Hormuz. In this economic light, the Iranian government’s message appears to convey, “You’re vulnerable here, and we can actually hit you in your homeland.” By showcasing such capacity without inflicting chaos, they underline their potential leverage in future escalations.
Corman, expressing skepticism about the notion that these hacks served as mere signaling, questioned the rationale behind such a complicated operation if the intent was solely to convey a message. He argued that compromising critical water systems with no resulting physical or psychological impact seems counterproductive to Iranian operational strategies, which historically emphasize high-visibility targets and effective psychological operations.
Moreover, analysts observed an absence of the typical information campaigns that would accompany a major cyber offensive. The lack of attempts to amplify the psychological impact of the cyberattacks, particularly in a critical sector like water, raises further questions about the true thrust of these operations. Water infrastructure often proves to be fertile ground for instilling public fear, and yet Iran did not capitalize on this vulnerability.
As experts continue to analyze these puzzling cyberattacks, the striking inconsistency between operational execution and usual tactical objectives in Iran’s cyber strategy leaves many discerning the possibility of internal strategic constraints or miscalculations. For now, the water hacks serve as a reminder of the complexities surrounding modern cyber warfare and the unpredictable nature of state-sponsored cyber activities.

