Cybersecurity

Iran suspected in cyberattacks on US water facilities across 7 states

2 min read

Iran suspected in cyberattacks on US water facilities across 7 states
Photo: Luca Bravo · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Malicious cyber actors targeted water and wastewater facilities across at least seven US states, with Minnesota suffering the most disruptions, according to a warning issued by the US Cybersecurity and Infrastructure Security Agency (CISA) on July 30, 2026. The attacks led to low-pressure water flow and boil-water notices in some areas, though no drinking water contamination was reported.

Minnesota saw 30 of its water systems hit, prompting Governor Tim Walz to describe the incident as modern warfare. Other affected states were not named in the advisory, but the attacks affected entities of all sizes, CISA stated.

The intrusions exploited internet-connected systems, allowing hackers to change passwords and lock out operators. CISA advised utilities to take systems offline and switch to manual mode to mitigate further disturbances.

Officials speaking anonymously to outlets including The New York Times and Washington Post suspect Iran is behind the attacks, citing a pattern of Iranian-backed cyber activity since the war began nearly six months ago. The FBI opened an investigation but has not publicly assigned blame. CISA had previously warned in April 2026 about Iranian targeting of programmable logic controllers in water systems, updating its advisory on July 22, 2026 with additional guidance and manufacturer vulnerabilities.

At a cabinet meeting on July 31, 2026 at Camp David, President Donald Trump blamed Minnesota, calling the state “grossly incompetent” and targeting Governor Walz without evidence. Walz countered on X that Trump knows Iran is responsible and that other states were also hit.

Cybersecurity experts and industry groups urged federal action, with Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition, calling for reinstatement of the state and local cybersecurity grant program set to expire in September 2026. The $1 billion program, established in 2021, is seen as critical for defending small towns against nation-state actors. The incidents follow Russian-linked attacks on Texas water systems in 2024 and Iranian-linked targeting of Pennsylvania water systems in 2023 and 2024.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.