Over the past few weeks, water utilities across roughly a dozen U.S. states have been hit by a coordinated wave of cyberattacks, one of the most widespread campaigns targeting American critical infrastructure in recent memory. While official attribution hasn’t been publicly confirmed, mounting evidence points squarely at the Iranian government, and intelligence agencies are reportedly confident in that assessment even without a formal public statement.
Where the Attacks Have Hit
The wave began on July 28, when Minnesota authorities announced that water treatment plants in more than 30 communities had been hit by coordinated cyberattacks. Two days later, the FBI confirmed that water and wastewater utility companies in at least seven states had reported incidents, with some attacks actually “degrading water operations,” not just breaching systems without real-world effect.
Since then, additional confirmed incidents have surfaced in Arkansas, Georgia, New Jersey, and Michigan, expanding what started as a Minnesota-specific story into a genuinely nationwide pattern.
Why This Wave Is Different
Water utilities and other critical infrastructure, including the power sector, have been targeted by hackers for years, whether state-backed operations or individual actors. What sets this campaign apart is its sheer scale. The U.S. has more than 150,000 separate water systems, many run by small local companies, a structure that in theory should make it hard for any single actor to hit multiple targets simultaneously.
But that same fragmentation cuts both ways: many of these smaller utility operators simply don’t have the cybersecurity resources or expertise that a major metropolitan water system might. Cybersecurity experts have historically believed Iranian hackers tend to target isolated, opportunistic “low-hanging fruit” rather than launch coordinated, multi-state campaigns, which is exactly why this incident is being treated as a significant potential escalation rather than business as usual.
Who’s Behind It: The Evidence So Far
As of now, the U.S. government has not officially named a culprit. But the circumstantial case pointing to Iran is substantial:
- Just before the Minnesota attacks became public, the Cybersecurity and Infrastructure Security Agency (CISA) had warned that Iranian hackers were actively targeting internet-connected devices in water systems and the energy sector.
- WaterISAC, a nonprofit that shares cybersecurity intelligence across the water sector, reportedly told its members in a leaked memo that the recent attacks “aligned” with the exact hacking campaign CISA had warned about.
- The Washington Post reported that U.S. intelligence agencies “are confident” Iran, specifically the Islamic Revolutionary Guard Corps (IRGC), is responsible, though formal public attribution hasn’t happened yet, reportedly because officials aren’t certain which specific IRGC unit is involved.
A Notable Political Wrinkle
President Trump has publicly pushed back on the Iran attribution, stating he did not believe “there was an Iranian cyberattack” and instead suggesting the issue originated with the state of Minnesota itself, a state led by Democratic Governor Tim Walz, Kamala Harris’s 2024 vice presidential running mate. That claim came just a day after the Wired report linking the attacks to Iran via the leaked WaterISAC memo, creating a notable gap between what U.S. intelligence agencies reportedly believe internally and what’s being said publicly at the highest levels of government.
Iran’s Track Record With US Infrastructure Attacks
This wouldn’t be an isolated incident for Iranian government-linked hackers, who have a documented history of targeting American critical infrastructure. Earlier this year, a hacktivist group called Handala disrupted operations at medical technology giant Stryker. The U.S. government later formally accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). That same group later claimed responsibility for breaching the personal Gmail account of FBI Director Kash Patel. Given the ongoing six-month war involving Iran, this water utility campaign fits a plausible pattern of retaliatory cyber operations against U.S. targets.
Real-World Impact So Far
The attacks haven’t been purely digital in their consequences. According to the FBI, some incidents caused a loss of water pressure, which “could potentially allow untreated groundwater to seep into pipes,” alongside instances of flooding at affected facilities.
Specific local impacts have included:
- The town of Braham, Minnesota had to take its water plant offline for several hours, urging its roughly 1,700 residents to conserve water.
- Maple Plain, Minnesota briefly declared a state of emergency.
- Officials in a county outside Atlanta, Georgia told residents to boil water as a precautionary measure.
Separately, cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems exposed directly to the internet, a stark illustration of how much of the country’s water infrastructure is more accessible to remote attackers than most people would assume.
The Real Damage May Be Psychological
Beyond the operational disruptions, security experts note that the most significant impact of this campaign may be psychological rather than physical. These attacks have received extensive national and local media coverage, causing widespread public anxiety about the safety of drinking water, one of the most basic and universally trusted public services. That kind of fear and uncertainty may well be part of the attackers’ underlying strategic goal, independent of whatever technical damage they actually manage to cause.
What This Means Going Forward
This incident is a stark reminder that America’s water infrastructure, often overlooked compared to more heavily scrutinized sectors like finance or energy, remains a genuinely vulnerable target for state-sponsored cyberattacks. With thousands of internet-exposed control systems and highly fragmented local operators lacking dedicated cybersecurity resources, water utilities represent exactly the kind of soft target that adversarial nations can exploit for both real disruption and psychological impact, without needing especially sophisticated hacking techniques.
For continuing coverage of critical infrastructure cybersecurity and the latest national security tech news, keep following Tech News Reports for ongoing updates.

