Iranian Hackers Allegedly Target US Water Utilities Across Dozen States
Original: What we know about the alleged Iranian hacks on US water utilities
Why This Matters
A coordinated foreign cyberattack on critical water infrastructure across 12+ states signals a significant escalation in threats to US public safety systems.
Since late July 2026, cyberattacks have hit water utilities across at least 12 US states. The FBI confirmed incidents in at least seven states, with some attacks degrading water operations. US intelligence agencies are reportedly confident Iran's IRGC is responsible, though no official attribution has been made.
Starting July 28, 2026, coordinated cyberattacks struck water treatment plants in more than 30 communities in Minnesota alone. Within days, the FBI confirmed that water and wastewater utility companies in 'at least seven states' had reported incidents, with some attacks having 'degraded water operations.' Affected states reported so far include Minnesota, Arkansas, Georgia, New Jersey, and Michigan.
The primary suspect is the Iranian government. CISA had warned as early as April 2026 — and updated the warning just before the Minnesota incidents — that Iranian hackers were targeting internet-connected devices in water systems and the energy sector. The Water Information Sharing and Analysis Center (WaterISAC) told its members the attacks 'aligned' with the CISA-warned Iranian campaign. The Washington Post subsequently reported that US intelligence agencies are 'confident' Iran's Islamic Revolutionary Guard Corps (IRGC) is responsible. No formal official attribution has been issued as of publication.
President Trump publicly disputed the Iranian attribution, instead blaming the state of Minnesota. The US has over 150,000 water systems, many operated by local entities with limited cybersecurity resources, making them vulnerable targets. Experts note this campaign represents a potential escalation beyond Iran's historically opportunistic, isolated attacks.