Federal authorities and cyber security investigators are examining potential links to Iranian state-sponsored hackers following a series of coordinated cyberattacks on water and wastewater utilities across the United States.
The disruptions began in late July in Minnesota, where at least 30 municipal water systems were hit. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) subsequently confirmed that water facilities in at least seven states—with reports expanding to as many as 12 states—have experienced operational disruptions.
Extent of the Attack & How Hackers Targeted Infrastructure
The US operates over 152,000 public drinking water systems and 16,000 wastewater treatment facilities, servicing millions of residents across vast geographic networks.
According to cybersecurity advisories issued by CISA and the FBI, the malicious actors targeted internet-connected Programmable Logic Controllers (PLCs)—the industrial devices responsible for controlling critical operations like:
-
Monitoring and adjusting water pressure
-
Controlling automated chemical dosing and filtration
-
Transmitting operational metrics to municipal dashboards
Exploitation Tactics: Attackers scanned public IP addresses to locate exposed controllers, exploiting unpatched software vulnerabilities, misconfigured remote-access tools, or default/stolen credentials. Once inside, hackers altered passwords and IP addresses to lock out local operators and disrupt remote monitoring capabilities.
Is Iran Behind the Intrusions?
While federal law enforcement and intelligence agencies have refrained from issuing a formal public attribution, investigators suspect Iranian-linked threat actors.
-
Historical Pattern: Iranian state-sponsored groups have previously deployed identical tactics against industrial control systems in the US and Israel.
-
Alternative Theories: Investigators are also looking into whether another threat actor mimicked Iranian cyber techniques to misdirect attribution.
-
Political Reactions: Former President Donald Trump publicly cast doubt on Iran’s involvement during a cabinet meeting, attributing the issues instead to local administrative incompetence in Minnesota.
Impact on Public Safety & Trust
To date, no reports indicate that drinking water supplies have been contaminated or rendered unsafe for consumption. However, the attacks caused operational degradation, forcing several utilities to trigger precautionary boil-water advisories and transition to manual operations.
Cybersecurity experts emphasize that beyond immediate operational disruptions, the broader objective of such nation-state attacks is to erode public confidence in the government’s ability to maintain essential civilian infrastructure.
Recommended Security Mitigations
CISA and cyber risk analysts recommend that public utilities immediately implement the following defenses:
-
Disconnect OT from the Internet: Remove PLCs and human-machine interface (HMI) dashboards from direct public internet access.
-
Secure Remote Access: Enforce multi-factor authentication (MFA) and route connection through configured firewalls or secure VPNs.
-
Network Segmentation: Isolate operational technology (OT) networks from standard corporate and email systems.
-
Credential Hygiene: Replace all default factory passwords with unique, complex credentials.
-
Manual Protocols: Regularly backup controller configurations and train staff to operate treatment systems manually during automated outages.

