Cyberattacks Target Water Utilities Across Multiple U.S. States
Since the end of July, several water utilities in the United States have experienced a wave of cyberattacks, raising significant concerns about the security of essential infrastructure. These coordinated attacks are reportedly linked to Iranian hackers and have impacted facilities across approximately a dozen states.
Extent of the Attacks
On July 28, authorities in Minnesota reported that more than 30 communities were targeted in coordinated cyberattacks on water treatment plants. Just two days later, the FBI confirmed that water and wastewater utility companies in at least seven states had reported similar incidents, with some attacks degrading water operations. In addition to Minnesota, facilities in Arkansas, Georgia, New Jersey, and Michigan have also been affected.
Identifying the Culprits
As of now, the specific perpetrators of these cyberattacks remain unidentified, but the Iranian government has emerged as the primary suspect. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had issued warnings in April regarding Iranian actors targeting internet-connected devices within the water and energy sectors, updating these alerts shortly before the Minnesota incidents began.
President Trump initially downplayed the existence of an Iranian cyberattack, attributing issues instead to state-level management. This claim followed a statement from the Water Information Sharing and Analysis Center (WaterISAC), which suggested the attacks aligned with CISA’s earlier warnings about potential Iranian government involvement.
The Washington Post later reported that U.S. intelligence agencies express confidence that Iran, particularly the Islamic Revolutionary Guard Corps (IRGC), is behind the attacks. However, attribution remains sensitive as officials determine which specific units were involved, complicating public disclosures amidst political considerations.
Impacts of the Cyberattacks
Cybersecurity analysts have identified vulnerabilities within U.S. water systems, noting that many critical infrastructure systems are exposed online. A recent report from cybersecurity firm Forescout revealed over 2,800 controllers in U.S. water systems that risk exposure to hackers. While not all exposures lead to control takeovers, some recent attacks resulted in operational issues.
The FBI indicated that some attacks resulted in loss of water pressure, which could allow untreated groundwater to infiltrate the water supply. In Braham, Minnesota, one of the first affected towns, local officials temporarily shut down the water plant, advising residents to conserve water. In Maple Plain, Minnesota, a state of emergency was declared briefly. In a nearby county in Georgia, officials recommended boiling water as a preventive measure.
Beyond the immediate technical concerns, the public’s response to these attacks has been pronounced, sparking anxiety about water safety. This psychological impact may align with the attackers’ intentions to induce fear surrounding access to a basic necessity.


