← The Desk 2026-08-03 The Wire
The Perimeter Site

Is Tehran Really Turning Off the Taps?

Ray Delgado
2026-08-03
# Is Tehran Really Turning Off the Taps? Listen, kid, I’ve seen this movie before. Every few years, a handful of municipal water plants get hit and suddenly the news cycle decides we're in the middle of a grand geopolitical chess match. This week is no different. You've got The Washington Post and CBC reporting on attacks in Minnesota and Quebec, and the consensus is already baked in: Iran is targeting US and Canadian infrastructure to signal strength amid rising tensions. The narrative is that this is a coordinated campaign by a nation-state APT to map out our critical vulnerabilities for some future "Day Zero" scenario where they flip a switch and half the Midwest stops having drinkable water. It’s a clean story. It makes for great headlines. It also makes me want to put my head through a wall. Whenever I see a report about "nation-state actors" targeting small-town infrastructure, I look for the word "sophisticated." If it's in there, I assume the person writing the report has never actually had to recover a domain controller from a bare-metal backup at 4am on a Sunday. In my experience, "sophisticated" is the word people use when they don't want to admit the attacker got in because the HMI was exposed to the public internet with the password still set to 'admin'. Let's look at the actual blast radius here. We aren't seeing systemic failures of the water grid; we're seeing isolated incidents where attackers found a door that wasn't just unlocked, but wide open. You don't need an APT when you have Shodan. If you can find a PLC (Programmable Logic Controller) sitting on a public IP with no MFA and default credentials, you aren't a spy, you're just someone who knows how to use a search engine. I remember Code Red back in 2001. People talked about it like it was some masterstroke of digital warfare. In reality, it was a piece of junk code hitting unpatched IIS servers because people were too lazy to run an update. NotPetya was worse; the blast radius was global not because the malware was magic, but because we’d built a world where one compromised update server in Ukraine could brick a shipping company in London. The common thread isn't the genius of the attacker; it's the fragility of the target. What would this cost you on a Tuesday? That's the only question that matters. If your water pumps stop working, I don't care if the packet came from Tehran, Pyongyang, or a bored teenager in a basement with too much caffeine. Your priority isn't attribution; it's containment. You check your backups, you isolate the OT network from the IT network (if they aren't already air-gapped, which they shouldn't be) and you get the water flowing again. The fact that we're spending more time discussing Iranian motives than why these plants are reachable via a standard browser is an embarrassment. Look at the noise surrounding us this week. There were 346 data breach stories alone. We saw SplitVPN leak personal records for just under 865,000 users and Ethiack remediating a vulnerability that exposed over 500,000 websites. That's not nation-state craft; that's basic hygiene failure on a massive scale. When you have half a million sites exposed by one flaw, the idea that we need "sophisticated" Iranian agents to find a water plant in Minnesota is laughable. They aren't picking locks; they're walking through doors that are literally missing the hinges. The second-order effect here is where it gets dangerous. When we label everything as an APT attack, we shift the conversation from "why is our security so bad?" to "how do we stop foreign governments?" This moves the problem out of the hands of the systems administrator and into the hands of the State Department. It creates a convenient shield for municipal managers who can tell their city council that they were victims of a superpower's cyber-warfare rather than admitting they forgot to change the default password on a Unitronics PLC. And then there are the vendors. They love this hype. Nothing sells an "AI-powered ICS threat detection suite" quite like the fear of an Iranian sleeper cell. They'll charge you six figures for a dashboard that tells you what I can tell you for free: your network is flat and your passwords suck. Who benefits if the crowd is wrong? The municipal governments do. They get to be victims of a geopolitical tragedy instead of targets of their own incompetence. Who benefits from the hype itself? The security firms selling the "silver bullet" software that promises to stop the next APT while ignoring the fact that the attacker probably just used a leaked credential from one of those 346 breaches we saw this week. If you want to prove me wrong, show me a single one of these water plant intrusions that utilized a zero-day exploit targeting the firmware of the PLC. Show me a campaign that bypassed multi-factor authentication using a custom-built tool designed specifically for industrial control systems. Until then, I'm betting my pension that this is just another case of "who left the back door open?" Stop staring at the attribution slides and go check your firewall rules. If your OT gear is talking to the public web, you aren't waiting for a nation-state; you're already compromised.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.