Breaking: Iran-Linked Cyberattacks Hit Emergency Services, Water Systems in 12+ States — Suisun City Declares Emergency
Iran-Affiliated Attackers Disrupt Emergency Services in Suisun City, Escalate Water Infrastructure Campaign to 12+ States
Suisun City, California (population 30,000) declared a state of emergency on August 9 after a cyberattack forced the municipality to shut down its entire IT network. The attack disrupted 911 dispatch routing for police and fire services, forcing emergency calls through Solano County's dispatch centre. Online city services and internal operations remain down while federal investigators examine the incident. This is the first cyberattack known to have triggered an emergency declaration in the city's history.
The Suisun City incident did not occur in isolation. It is the latest escalation in a widening campaign targeting US critical infrastructure, particularly water and wastewater systems. Since late July, the FBI, EPA, and CISA have confirmed that cyberattackers have remotely accessed internet-facing programmable logic controllers (PLCs) at water and wastewater utilities in at least 12 states. The scope has expanded from the initial seven states reported in the FBI's July 30 alert. Attackers have changed administrator passwords on PLCs, manipulated pumps and valves, and caused operational disruptions including pressure loss and flooding. In Minnesota, 30 water systems were affected, with dramatic water-level drops triggering backup systems. Rockwell Automation MicroLogix 1100 and 1400 series PLCs are the primary targets.
Federal agencies assess that Iranian-affiliated threat actors are behind the campaign. CISA Acting Director Nick Andersen stated the agency is observing a significant increase in threat actors targeting PLCs at water utilities. The attacks exploit a structural vulnerability: small community water systems rely on internet-connected automated controls but often lack the budget and staff for adequate cybersecurity. The July CISA advisory urged water operators to remove remote controllers from the internet entirely.
Meanwhile, two critical vulnerabilities with confirmed active exploitation were added to the CISA KEV catalog in the past week:
Progress LoadMaster CVE-2026-8037 (CVSS 9.6) is an unauthenticated command injection flaw in the load balancer's API. CISA added it on August 7 with a three-day patch deadline. 792 exploitation attempts have been recorded from 65 unique IPs across 18 countries. The affected products include LoadMaster and Progress ADC. Any internet-facing LoadMaster without the patch should be treated as compromised.
JetBrains TeamCity CVE-2026-63077 (CVSS 9.8) is an unauthenticated remote code execution via deserialization of untrusted data through the agent polling protocol. CISA KEV-added August 5, patch deadline August 8. Rapid7 published a proof-of-concept on August 7. Successful exploitation exposes build credentials, CI/CD pipelines, and potentially the entire software delivery chain.
So What / Action
For CISOs with any US infrastructure footprint, this is a three-front problem. First, water and wastewater: if you operate or are responsible for OT systems with internet-facing PLCs (especially Rockwell MicroLogix), isolate them from the internet now. This is not a recommendation to segment; it is a recommendation to disconnect. The threat actors are not probing, they are manipulating physical controls.
Second, LoadMaster and TeamCity: both are internet-facing initial-access vectors with confirmed exploitation. Audit your external attack surface for these products and apply patches immediately. For LoadMaster, check for the three known attacker IPs and any unusual API endpoint activity since June 29. For TeamCity, rotate all credentials stored in the server, audit build artifacts, and check agent polling logs for unauthorised connections.
Third, Suisun City shows that cyberattacks on municipal infrastructure are now causing real-world disruption to emergency services. If you provide cybersecurity services to local government or critical infrastructure clients, their incident response plans need to include 911 fallback procedures and offline dispatch contingencies.
Sources: LA Times, CBS News, Axios, FBI Cyber Alert, CISA KEV Catalog, The Hacker News, BleepingComputer, Rapid7, Tenable, Washington Post

