LAS VEGAS, 9 AUG 2026 — According to the retired general who ran the National Security Agency, the reason water systems in at least twelve US states have been broken into is simple: programmable logic controllers should not be exposed to the internet.

Paul Nakasone told reporters at DEF CON that the intrusions were most likely Iranian. No official attribution has been made — not by the FBI, not by the administration — and Iran has claimed nothing.

What is known

The FBI said in late July that it was investigating attacks by malicious cyber actors against operational technology devices, programmable logic controllers among them. On 30 July it issued an alert covering water utilities in at least seven states. That count has since risen to twelve.

The intrusion pattern is unusually clear for an incident still under investigation. Having reached the controllers, the attackers changed their passwords and then altered their IP addresses — disconnecting the devices and locking out the operators who were supposed to be managing them.

That second step is the interesting one. Changing an IP address is not a destructive act against water treatment; it is a denial of control. The operator loses visibility and remote management of a device that is still running.

Why small utilities are the target

A programmable logic controller is a small industrial computer that opens a valve, runs a pump or holds a pressure setpoint. It was designed in an era when physical access was the security model, and many models still in service authenticate with a shared password or a default one.

These controllers are on the internet for a good reason: it solved an operational problem. A small water district may serve a few thousand people with a handful of staff covering multiple sites, and remote access is the difference between adjusting a setpoint from a laptop and driving forty minutes at two in the morning. Nobody exposed these devices out of carelessness; they did it because the alternative was an operational cost they could not carry.

This is why "do not put them on the internet," while correct, is incomplete advice. The utilities most likely to have exposed controllers are precisely those least able to fund the alternative, and telling them to stop does not supply the remote access they were buying.

Attribution deserves care here

The most senior voice in the story is a retired official speaking to reporters at a conference, not a government making a finding.

With critical infrastructure, that distinction is crucial: attributing an attack to a state actor changes its political meaning and the range of available responses. Nakasone's assessment is informed and it is not an official determination; the FBI has described malicious cyber actors without naming a country, and Iran has said nothing.

[Sentence deleted] That water systems in twelve states were compromised is documented by the FBI. That Iran did it is, at this stage, a suspicion held by credible people. The first is a fact you should act on. The second is a fact-shaped thing you should not repeat as settled.

The defensive question is not the attacker

For anyone running operational technology, the identity of the intruder is close to irrelevant to the remediation.

Default and shared credentials on internet-reachable controllers is the finding here, and it is a finding that has appeared after almost every incident of this type for a decade. The 2023 attacks on water systems using Unitronics equipment produced the same lesson and the same coverage.

What changed is scale and coordination. Seven states becoming twelve inside a fortnight describes a campaign scanning for a known exposure and working through what it finds, which is a different threat model from an opportunistic intrusion at one utility. Against a scanner, being small is not protection — it is selection criteria, because small operators are where the unpatched, default-credentialed devices live.

What a controller can and cannot do

It helps to be precise about consequences, because coverage of water-system intrusions tends to oscillate between shrugging and poisoning-the-supply.

A programmable logic controller in a small water system typically runs pumps, opens and closes valves, and holds setpoints — pressure, tank level, chemical dosing rate. Someone with control of one can cause real harm: over-dosing a treatment chemical, running a pump dry, or manipulating pressure enough to damage pipework. These are not theoretical.

They are also not unbounded. Most systems have physical and procedural limits above the controller — mechanical relief, dosing equipment with a maximum rate, laboratory sampling, staff who notice — and those limits are why previous intrusions of this kind produced disruption rather than casualties. The honest statement is that a controller compromise is a serious safety-adjacent event whose worst case depends entirely on what an individual utility has above the automation, and that varies enormously between a city and a rural district.

In this campaign, the reported actions were password changes and IP changes. On the evidence so far this was about seizing control, not exercising it.

What operators should actually do

Take the controllers off the public internet, and accept that this is a project rather than a setting. The realistic path is a VPN or a managed remote-access service in front of the device, so the remote management that justified the exposure survives.

Change default credentials on every controller, and check that "changed" means changed per device rather than one shared password across a fleet — the latter is the configuration that turns one compromise into all of them.

Then make loss of control an alarm. In this campaign the operators found out because devices stopped answering. A monitoring rule that fires when a controller becomes unreachable or its network configuration changes converts the attacker's own persistence step into your detection, and it costs nothing but attention.

Sector support is arriving in the form of a new Water Watch Center aimed at helping small utilities, which is an acknowledgement that the ones most exposed are the ones with no security staff at all.

What to watch

Whether the state count keeps climbing, since twelve inside a fortnight suggests scanning that has not finished. Whether any official attribution follows, and whether it matches the informal one. And whether the Water Watch Center reaches the utilities that need it, because every previous round of this has ended with guidance published and the smallest operators unable to act on it.