Skip to content
Gigantum.net
Artificial intelligence

Iran’s attacks on US water systems are just the beginning

Iran isn’t waiting for this war to end before it looks for the next vulnerability, and neither should we.

· 592 words· updated August 25, 2026 at 09:14 AM
Flag of Iran on a computer binary codes falling from the top and fading away.
Flag of Iran on a computer binary codes falling from the top and fading away.

As a teenager, I was capable of hacking into critical municipal infrastructure. I wasn’t an elite operator, but I knew where the vulnerabilities were and how to get around systems that weren’t even protected in the first place. From default passwords to open ports, attackers don’t need to be brilliant when defenders leave doors open.

This approach is exactly how Iranian-linked hackers locked municipalities out of their own water systems across multiple states this summer, changing passwords, cutting off access and forcing utilities back to manual pumps and valves. I wasn’t surprised that it happened — I was surprised it took this long. And the scariest part is how little sophistication it took to disrupt something as fundamental as water.

These vulnerabilities have been around for years; the war with Iran is just escalating the attacks. Critical infrastructure defense still runs on human timelines, while attackers, increasingly augmented by artificial intelligence, operate continuously. As long as the Iran conflict remains unresolved, this attack surface stays open, and water is just the beginning.

The clear goal of these attackers is to shake confidence in the systems people rely on without thinking about them. Clean water from the tap, lights that turn on, and trains that run on time. It’s asymmetric warfare, a way to inflict outsized damage without ever matching the other side militarily. They don’t need to breach a bank or cross a border to cause panic. They just have to make people doubt their water is safe to drink.

Water in particular is exposed in a way electric utilities aren’t, because most are run by local governments that have limited budgets competing across schools, transit and other local priorities. Attackers have now written a playbook for what works, and we should expect it to grow from water to the rest of municipal infrastructure, including power, transit and wastewater.

Simultaneously, AI is outpacing current cybersecurity measures. Attackers search horizontally, scanning thousands of systems for the same exposed technology at once. Defenders fix vertically, one device at a time. Attackers are using AI to scan for exposed vulnerabilities at a scale no human security team can match. Fixes are still applied by hand — one utility, one password reset at a time. The Cybersecurity and Infrastructure Security Agency and the FBI can identify tactics, publish indicators and warn operators quickly, but a finding does not reduce risk. A fix does.

Addressing this problem doesn’t require a major breakthrough. The answer is actually quite simple. We have to treat cyber hygiene as infrastructure, not an afterthought.

Utilities need continuous, automated discovery over every device with a footprint on the internet. They need password and configuration enforcement that runs constantly in the background, and they need to stop treating a lack of available patches as an excuse to leave a known exposure open. Durable fixes exist even when a vendor patch doesn’t.

The next breakthrough in critical infrastructure security isn’t another way to tell defenders what is wrong. It’s dramatically reducing the time identifying an exposure and eliminating it. Attackers don’t exploit reports. They exploit what we haven’t fixed.

The systems that took down more than 30 water utilities were driven by the same boring loopholes I used to look for as a teenager. The uncomfortable truth is that the fix isn’t more sophisticated than the attack. It’s cyber hygiene applied continuously, everywhere, starting now.

Iran isn’t waiting for this war to end before it looks for the next vulnerability, and neither should we.

Tal Kollender, a former hacker, is CEO of cybersecurity startup Remedio.

Gathered from external sources. Rights to this text belong to whoever originally published it.