Iranian Cyberattacks Hit US Water Utilities in 12 States

A coordinated wave of Iranian cyberattacks has struck water utilities in at least 12 states, triggering boil-water advisories and emergency declarations.

By Central
Coordinated cyberattacks on US water utilities since July implicate Iranian state hackers, with no official attribution yet.
Highlights
  • The attacks have forced treatment plants offline and triggered boil-water advisories in at least a dozen states.
  • CISA warned about Iranian targeting of water systems months before the attacks began in late July.
  • U.S. intelligence agencies are confident Iran is responsible, but the government has not formally named the attacker.

For nearly three weeks, water utilities across the United States have been grappling with a coordinated wave of cyberattacks that has struck facilities in at least a dozen states, raising urgent questions about the security of the nation’s critical infrastructure. Since late July, these incidents have forced some treatment plants to go offline, prompted boil-water advisories, and triggered emergency declarations in small communities, while the federal government has yet to officially name the attacker.

A Widespread Assault on Critical Water Infrastructure

What distinguishes this campaign from previous attacks on water systems is its geographic breadth and apparent coordination. On July 28, Minnesota authorities announced that water treatment plants in more than 30 communities had been hit by coordinated cyberattacks. Two days later, the FBI disclosed that water and wastewater utility companies in at least seven states had reported incidents, with some attacks having degraded water operations.

Since those initial reports, additional breaches have come to light in Arkansas, Georgia, New Jersey, and Michigan, bringing the total number of affected states to at least twelve. The attacks have not been limited to any single region or type of water system, suggesting the perpetrators conducted reconnaissance across a wide area and selected targets based on vulnerability rather than geography.

The United States has more than 150,000 public water systems, many of them operated by small municipalities or local companies with limited cybersecurity expertise and budgets. While this fragmentation theoretically makes it harder for attackers to compromise many facilities at once, it also means that a significant portion of the country’s water infrastructure lacks the defenses needed to repel even moderately sophisticated hacking campaigns.

Who Is Behind the Attacks

The short answer is that the perpetrator has not been officially named, but the evidence pointing toward Iran’s government is substantial and growing. However, the U.S. government has yet to issue a formal attribution, and the absence of a public naming has created an unusual vacuum in which conflicting narratives have flourished.

The timeline of events provides important context. The first incidents in Minnesota occurred days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated a warning originally published in April, cautioning that Iranian hackers were targeting internet-connected devices in water systems and the energy sector. CISA had initially flagged this threat months earlier, and its updated alert proved prescient.

Shortly after the Minnesota attacks became public, the Water Information Sharing and Analysis Center, or WaterISAC, a nonprofit organization that distributes cybersecurity intelligence across the water sector, informed its members that the recent incidents aligned with the hacking campaign CISA had warned about, effectively pointing to Iran as the responsible party.

Earlier this week, the Washington Post reported that U.S. intelligence agencies are confident Iran, specifically the Islamic Revolutionary Guard Corps (IRGC), is responsible. According to the newspaper’s sources, the attribution has not been made public for two reasons: intelligence officials are still determining which specific unit within the IRGC executed the operation, and there may be reluctance to contradict President Donald Trump’s contrary claim.

The Political Dimension

President Trump responded to the initial reports by saying he did not think there was an Iranian cyberattack, instead blaming the state of Minnesota, which is governed by Democratic Governor Tim Walz. Walz had recently been chosen as Kamala Harris’s vice presidential candidate for the 2024 elections. This political framing of what cybersecurity experts describe as a national security incident has added a layer of complexity to the response.

Iranian government hackers have a well-documented history of targeting critical infrastructure in the United States, and these attacks may be part of a broader strategy to retaliate for ongoing geopolitical tensions. Until now, however, Iranian cyber operations against American targets had achieved only limited success.

The Handala Precedent

In March, a hacktivist group calling itself Handala disrupted the operations of medical technology giant Stryker. The U.S. government later accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). The same group subsequently claimed responsibility for hacking the personal Gmail account of FBI Director Kash Patel. These incidents demonstrated that Iranian cyber actors were becoming more aggressive and willing to target high-profile American entities, but the scale and coordination of the water utility attacks represent a significant escalation.

What Happened Inside the Targeted Water Systems

To understand how these attacks succeeded, it helps to know how water treatment plants are controlled. Many facilities rely on programmable logic controllers, or PLCs, which are industrial computers that automate functions such as opening valves, adjusting chemical dosing, and managing water pressure. These devices were designed for reliability and longevity, not security, and an alarming number of them remain directly accessible from the internet.

Cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems that were exposed online. Exposure does not automatically mean a hacker can take control, but in several of the recent incidents, attackers crossed that threshold. The FBI stated that some of the attacks caused loss of pressure, which could potentially allow untreated groundwater to seep into pipes, and flooding in at least one location.

Community-by-Community Impact

The town of Braham, Minnesota, population approximately 1,700, was among the first to report an incident and had to take its water plant offline for several hours, urging residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local officials told residents to boil water before using it as a precautionary measure. These disruptions, while temporary, created real hardship for communities that depend on their water systems functioning correctly every day.

The attacks did not result in widespread contamination or prolonged outages, but cybersecurity experts caution that this may reflect the attackers’ objectives rather than their capabilities. In some cases, the hackers appear to have deliberately caused nuisance-level disruptions, perhaps to demonstrate their access without triggering a more aggressive response.

Why Water Utilities Are Vulnerable

The water sector’s cybersecurity challenges are structural and will not be solved quickly. Many utilities were built decades ago, when connecting control systems to the internet was not even contemplated. Adding cybersecurity protections retroactively is expensive and can be technically difficult, particularly for small systems with limited staff.

Compounding this problem, the industry has traditionally prioritized reliability and uptime over security. Plant operators are trained to keep water flowing and pressure stable, and they may be reluctant to install security updates that could disrupt operations. This operational mindset creates openings that sophisticated attackers can exploit.

Cybersecurity experts have long characterized Iranian hackers as opportunistic actors who target low-hanging fruit, exploiting known vulnerabilities rather than developing novel attack techniques. The recent campaign, however, suggests a higher level of coordination and strategic intent. Targeting water utilities in multiple states simultaneously requires reconnaissance, planning, and the ability to execute attacks at scale, all of which represent a meaningful upgrade in capability.

The Psychological Dimension of the Attacks

The worst effect of these incidents may be psychological rather than operational. Water is a fundamental human need, and the idea that someone could deliberately disrupt its supply or compromise its safety strikes at a deep source of public anxiety. These attacks have been widely covered in both national and local press, and the resulting fear may be exactly what the hackers intended to create.

Spreading panic and undermining public confidence in essential services is a classic asymmetric warfare strategy. When people lose trust in the safety of their drinking water, the social and economic consequences can ripple far beyond the immediate disruption. The attackers may not need to achieve lasting physical damage if they can create a pervasive sense of vulnerability.

How the Response Has Unfolded

The federal response has been complicated by the absence of an official attribution. CISA issued warnings and technical guidance, and the FBI has been collecting evidence from affected utilities. But without a public statement naming Iran as the perpetrator, the response lacks the clarity and urgency that typically accompanies state-sponsored attacks on critical infrastructure.

WaterISAC has been acting as an information conduit, sharing intelligence with its member utilities about the tactics, techniques, and procedures observed in the attacks. This kind of sector-specific threat intelligence is valuable, but it depends on utilities having the capacity to act on the information, which many smaller systems do not.

The attacks have also reignited debates about regulatory requirements for water system cybersecurity. Unlike the electric power sector, which has mandatory cybersecurity standards enforced by the North American Electric Reliability Corporation, the water sector relies largely on voluntary guidance and best practices. Some lawmakers and cybersecurity advocates argue that mandatory standards are needed, while industry groups warn that regulations could impose burdensome costs on small utilities.

What This Means for the Future of Critical Infrastructure Security

The Iranian water utility attacks should be understood as a warning shot. The fact that multiple facilities across a dozen states could be compromised in a coordinated campaign demonstrates that the gap between attacker capabilities and defender readiness is wide and growing wider. The attackers did not need to develop zero-day exploits or deploy advanced malware; they simply found systems that were exposed and vulnerable.

For the water sector, the path forward involves several difficult steps. Utilities need to inventory their internet-connected devices and remove unnecessary exposures. They need to implement multi-factor authentication and strong password policies. They need to develop incident response plans that can be executed even by small staffs. And they need access to threat intelligence that is timely, actionable, and affordable.

None of these steps are easy, and many will require financial and technical support from state and federal governments. The water sector has been underfunded for decades, and cybersecurity has rarely been a priority when pipes are leaking and treatment plants are aging. But the cost of inaction is now clear: the next wave of attacks could be more destructive, and the consequences of a successful large-scale water contamination event would be catastrophic.

The Iranian campaign has also demonstrated that geopolitical tensions can manifest in unexpected ways in the digital domain. What begins as a conflict over nuclear programs or regional influence can translate into attacks on American water utilities in small towns far from any battlefield. Defending against this kind of threat requires not just technical measures but also a clear-eyed recognition that critical infrastructure has become a arena for state-on-state conflict.

The communities affected by these attacks have been resilient, restoring service quickly and alerting residents with appropriate precautions. But resilience should not be confused with security. The fact that the water kept flowing in most places does not mean the system is safe. It means that so far, the attackers have chosen to cause disruption rather than destruction. That restraint may not hold indefinitely, and the infrastructure that delivers water to more than 300 million Americans remains exposed to adversaries who have demonstrated both the intent and the capability to strike.

Share This Article