Iran, Russia, and China Have Been Quietly Attacking Water Systems — and the Door Was Usually Left Unlocked
A new threat-intelligence report finds three governments targeting water and wastewater infrastructure, not primarily to poison anyone, but to cause fear, probe weaknesses, and pre-position for future conflict. The tools they're using are embarrassingly basic.

Key points
- DomainTools published research on 25 June 2025 linking Iran, Russia, and China to ongoing attacks on water and wastewater infrastructure dating to at least 2024.
- In January 2024, Russian-linked hackers caused a water tank in Muleshoe, Texas to overflow for up to 45 minutes by remotely accessing a control interface.
- Volt Typhoon, a Chinese government-linked hacking group, had broken into US water and wastewater systems by February 2024, according to US federal agencies.
- Polish intelligence confirmed in May 2025 that hackers breached five water treatment plants using weak and default passwords.
- Security researchers say the most common entry points, exposed control panels, default passwords, and unguarded remote-access tools, are fixable with basic security hygiene.
Water and hacking in the same headline sounds catastrophic. It conjures images of poisoned reservoirs and taps running dry. The reality, according to new research from threat-intelligence firm DomainTools, is more unsettling in a different way: three governments are indeed breaking into water infrastructure, but their primary goals are fear, intelligence-gathering, and quietly leaving a back door open for later. Not mass casualties.
First reported by Dark Reading, the DomainTools report focuses on Iran, Russia, and China, tracing methods and motives across incidents stretching back to 2024.
How did the hackers get in?
Mostly through doors that should've been locked years ago. Across all three countries, entry points were strikingly similar: default passwords nobody ever changed, control-system screens left open to the public internet, and remote-access tools with little or no protection. HMIs, or human-machine interfaces, are the software panels operators use to manage physical equipment. They were a recurring target.
Polish intelligence reported in May 2025 that hackers walked into five water treatment plants almost entirely through weak default passwords. No exotic malware required.
The three governments each had distinct goals once inside.
Iran. Groups like CyberAv3ngers, tied to the IRGC (Iran's Revolutionary Guard Corps), targeted smaller, internet-exposed utilities in the US and Israel. Researchers describe their approach as opportunistic. A 2020 attempt against Israeli water systems during a heat wave was stopped before any harm occurred. DomainTools calls the objective psychological: public fear, not infrastructure destruction.
Russia plays rougher. Russian-linked hackers caused a municipal water tank in Muleshoe, Texas to overflow for 30 to 45 minutes in January 2024 by remotely accessing a control interface. Norway's counter-intelligence chief blamed Russia in 2025 for opening a floodgate that released 400 litres per second for four hours. The group behind the Texas incident, Cyber Army of Russia Reborn, was later linked by Mandiant to Sandworm, a unit of Russian military intelligence. Russia wants disruption, public alarm, and a clearer map of how Western infrastructure actually works.
China's Volt Typhoon group is playing the longest game. We've tracked Volt Typhoon since our first report on 28 May 2026, and the pattern here is consistent: durable access, patience, no immediate effects. US agencies including CISA, the federal body responsible for protecting critical systems, warned in February 2024 that Volt Typhoon had burrowed into US water systems not to cause immediate damage but to sit quietly. The goal appears to be pre-positioning: access that could be activated if military conflict ever breaks out. DomainTools rates the long-term threat level as severe.
Should you worry about your tap water?
For most people, the immediate contamination risk remains low. Modern facilities carry physical safeguards that keep tainted water from reaching taps. The real concerns are supply disruption and the erosion of public trust.
DomainTools CISO Daniel Schwalbe, speaking to Dark Reading, noted that the weaknesses here, exposed control panels, shared accounts, outdated legacy equipment, poor separation between office IT and operational systems, appear across many industries. Any organisation running industrial control systems should read this as a mirror, not a water-sector story.
The short version: Iran, Russia, and China don't need sophisticated malware to get inside critical infrastructure. They need an unlocked door. There are too many of those still open.



