Twelve states targeted, one boil-water advisory: the gap the water-hack coverage keeps skipping
CSIS counts Iranian-linked targeting of US water systems in at least 12 states, nine publicly confirmed. The most severe outcome on record is a pump station shutdown in Georgia. The campaign is real and wide; its effects, so far, are not.
The Center for Strategic and International Studies, publishing in mid-August, mapped Iranian-linked targeting of US water systems in at least 12 states “according to ABC and other news outlets,” of which nine states have publicly confirmed being targeted. CSIS is explicit that CISA and the FBI have not publicly identified all 12 — the number is media-sourced, not government-sourced, and should be labelled that way wherever it appears. CSIS also reports no discernible pattern in which states were hit: not swing states, not red or blue states, consistent with a broad sweep for exposed devices rather than a targeted campaign. Against that breadth, CSIS records no reports of water quality degraded to a level endangering consumers. The most severe consequence was in Georgia, where attackers shut down a pump station, water pressure dropped, contamination risk rose and a boil-water advisory was issued; no related illnesses were reported. Dark Reading reported Minnesota incidents in which operators were locked out of PLCs, losing visibility and control and forcing manual workarounds.
The technical detail that deserves more attention than the state count sits in the joint CISA/FBI/NSA/EPA advisory AA26-097A. The FBI observed Iranian-affiliated actors targeting internet-exposed programmable logic controllers “with the intent to cause disruptions — including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays.” At one US victim, the FBI observed actors download a malicious project file to a PLC using configuration software; analysis indicated the file retained ladder logic for downstream function but added logic overriding specific instruction sets responsible for maintaining safe operating parameters. That is manipulation of a safety system, not a defacement — a different order of intent from the 2023 CyberAv3ngers operation against Unitronics devices, which turned on unchanged default credentials and left a banner reading “You have been hacked, down with Israel.” The July 22 update named Schneider Electric Modicon M340 and Siemens S7-1200 devices alongside Rockwell Automation/Allen-Bradley, and noted Dropbear SSH used for remote access in one attack.
Attribution to a named actor remains weaker than the coverage suggests. Cybersecurity Dive reported that the Iran-linked persona Handala claimed credit in June 2026 for an attack on California Water Service; The National, on September 2, repeated it and added a claim that Handala hacked FBI director Kash Patel’s personal email and cloud services. Neither has been confirmed by California Water Service, the FBI or an independent forensic assessment. Handala has a documented record of overclaiming: Symantec noted that its December 2025 claim to have compromised the phones of former prime minister Naftali Bennett and Netanyahu chief of staff Tzachi Braverman was disputed by researchers, who found the intrusions “appeared to be limited to Telegram accounts, and did not achieve complete phone access” — even as a Haaretz investigation on January 7 found the leaked contact lists reached Israeli security officials and world leaders.
Assessment: Two numbers are doing opposite work and only one of them travels. “Twelve states” is a scanning statistic — the count of places where exposed controllers were found and touched. “One boil-water advisory” is the outcome statistic. A campaign that is broad, opportunistic and technically unsophisticated, exploiting outdated systems and needlessly internet-facing devices, produces exactly that shape: wide reach, thin consequence. That does not make it harmless — the ladder-logic manipulation described in AA26-097A shows intent to defeat safety parameters, and intent tends to precede capability. But readers should be suspicious of any account that cites the breadth figure without the severity ceiling, and of any persona claim, from Handala or anyone else, that arrives without a victim’s confirmation.