Iranian-Linked Cyberattacks Disrupt Water Utilities Across Seven U.S. States
Federal agencies tie a broad campaign targeting industrial controllers to Iranian hackers, sparking a public dispute over attribution.
A series of cyberattacks targeting U.S. water and wastewater utilities across at least seven states has caused operational failures and highlighted critical vulnerabilities in national infrastructure. The campaign, which began around July 27, 2026, specifically targeted the digital controllers used to manage water flow and pressure.
According to the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers targeted internet-facing Programmable Logic Controllers (PLCs). By remotely accessing these devices to change IP addresses and passwords, the hackers disabled essential monitoring and control systems. The impact was felt most acutely in Minnesota, where over 30 community water systems were affected, as well as in Michigan. The FBI reported that these disruptions led to tangible physical consequences, including loss of water pressure and flooding at affected facilities.
A Pattern of Infrastructure Targeting
This campaign follows a documented history of Iranian-affiliated actors targeting U.S. industrial control systems (ICS). CISA had previously issued a warning in April 2026 regarding similar threats, echoing a 2023 campaign where actors linked to the Islamic Revolutionary Guard Corps exploited default passwords on internet-connected controllers. These attacks occur against the backdrop of ongoing geopolitical conflict between the U.S. and Iran, where critical infrastructure is increasingly viewed as a primary theater for asymmetric warfare.
Systemic Vulnerabilities
The scale of this operation marks one of the broadest attacks on U.S. industrial control systems to date. By manipulating the physical layer of infrastructure—the PLCs—the attackers demonstrated that they could move beyond data theft to cause real-world operational failures. The breach underscores a systemic weakness in how small-to-medium utilities manage operational technology (OT) that is exposed to the public internet, often leaving critical valves and pumps accessible to remote actors.
Political Friction and Future Risks
Despite the intelligence findings, the attribution of the attacks has become a point of political contention. President Donald Trump has publicly disputed the link to Iran, suggesting instead that the disruptions in Minnesota were the result of local incompetence. In contrast, Governor Tim Walz criticized the administration's response, stating that the attacks illustrate a lack of a viable plan to counter Iranian aggression and describing the events as a reflection of modern warfare.
While officials in Minnesota and Michigan have emphasized that water quality remained safe and no widespread boil-water notices were required, the ability of foreign actors to trigger flooding and pressure loss remains a significant security concern. Federal agencies continue to urge utilities to secure their PLCs and remove industrial controllers from the public internet to prevent further incursions.