Cybersecurity4 mins read

Alleged Iranian hacks on U.S. water utilities: What’s known so far

Hackers have targeted and broken into systems at several U.S. water plants, raising alarms about critical infrastructure security and the still-unconfirmed attribution to Iran.

Why the water utility attacks are raising alarms

Since the end of last month, several water utilities in the United States have been hit by cyberattacks. TechCrunch reports the wave is especially concerning because it appears widespread, with targets in around a dozen states.

The U.S. has more than 150,000 water systems, and some are run by local companies that may lack the cybersecurity resources or expertise needed to defend themselves. That makes basic operational technology exposure a major risk area for critical infrastructure operators.

Where incidents have been reported

Minnesota authorities said water treatment plants in more than 30 communities were hit by coordinated cyberattacks on July 28. Two days later, the FBI said water and wastewater utility companies in “at least seven states” had reported incidents.

Reported hacks have included facilities in Minnesota, Arkansas, Georgia, New Jersey, and Michigan. In some cases, the FBI said the attacks “degraded water operations.”

Attribution remains officially unresolved

The U.S. government has not publicly named a culprit behind the coordinated wave of hacks, according to the TechCrunch report. The leading suspicion described in the article is the Iranian government, but that attribution has not been officially announced.

CISA had warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector. WaterISAC reportedly told members that the recent attacks “aligned” with that campaign, while The Washington Post reported that U.S. intelligence agencies are confident Iran, specifically the IRGC, is responsible.

Operational impacts and the bigger takeaway

The FBI said some attacks caused loss of pressure, which could potentially allow untreated groundwater into pipes, as well as flooding. Braham, Minnesota, took its water plant offline for a few hours and urged around 1,700 residents to conserve water; Maple Plain briefly declared a state of emergency; and officials outside Atlanta briefly told residents to boil water as a precaution.

The most durable impact may be public concern over the safety of a fundamental service. For water utilities, the practical takeaway is clear: internet-facing controllers and other exposed systems are an urgent security priority.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile