Cybersecurity

Iranian hackers hit U.S. water utilities in 12 states

Published Aug 14, 2026, 7:24 PM2 min readNewUJ Editorial Desk

Iranian hackers hit U.S. water utilities in 12 states
Photo: Shahadat Rahman · Unsplash
0 0
XWhatsAppTelegramLinkedIn

A wave of cyberattacks has struck water utilities across the United States since late July, with incidents reported in at least seven states and affecting more than 30 communities in Minnesota alone. The FBI confirmed that some attacks degraded water operations, and officials suspect Iranian government hackers are behind the campaign.

The attacks have disrupted essential services in several states. In Braham, Minnesota, the water plant was taken offline for a few hours, prompting officials to ask its roughly 1,700 residents to conserve water. Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, residents were told to boil water as a precaution. Other reported incidents occurred in Arkansas, New Jersey, and Michigan.

The campaign is significant because it targets a critical sector with limited cybersecurity resources. The U.S. has more than 150,000 water systems, many run by local companies that may lack the expertise to defend against sophisticated attacks. Cybersecurity experts have long believed Iranian hackers focus on opportunistic, isolated attacks, making this coordinated effort a potential escalation.

On July 28, Minnesota authorities announced that water treatment plants in over 30 communities were hit by coordinated cyberattacks. Two days later, the FBI said water and wastewater utility companies in at least seven states reported incidents, some involving degraded operations. The FBI also noted that some attacks caused loss of pressure, which could allow untreated groundwater to seep into pipes, and flooding.

The U.S. government has not officially named a culprit, but evidence points to Iran. Days before the Minnesota attacks, the Cybersecurity and Infrastructure Security Agency (CISA) updated an April warning that Iranian hackers were targeting internet-connected devices in water and energy systems. The nonprofit Water Information Sharing and Analysis Center told members the attacks aligned with that campaign. The Washington Post reported that U.S. intelligence agencies are confident the Islamic Revolutionary Guard Corps is responsible, though attribution is not public because officials are unsure which unit was involved and may be reluctant to contradict President Donald Trump, who denied an Iranian cyberattack and blamed Minnesota.

Iranian hackers have a history of targeting U.S. critical infrastructure, possibly as retaliation for the ongoing war. In March, the hacktivist group Handala, later linked to Iran's Ministry of Intelligence and Security, disrupted medical tech firm Stryker and claimed to hack FBI Director Kash Patel's personal Gmail. Earlier this month, cybersecurity firm Forescout found more than 2,800 controllers in U.S. water systems exposed online, though exposure does not guarantee hackers can cause real-world effects. The attacks have also raised public fear about water safety, which may be part of the hackers' goal to spread panic.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.