Friday, 14 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 15 August 2026 at 01:07

Suspected Iranian cyberattacks on U.S. water utilities: what we know

A wave of coordinated cyberattacks on U.S. water utilities since late July has affected around a dozen states, with officials reportedly confident that Iran is responsible.

Foto: TechCrunch

Since late July, U.S. water utilities have faced a wave of coordinated cyberattacks affecting roughly a dozen states. The country has more than 150,000 water systems, many run by local operators, and security experts have long warned that these smaller entities often lack the resources to defend against sophisticated hackers. The scale of the campaign marks a possible escalation for Iranian threat actors, who have typically targeted low-hanging fruit in isolated attacks.

Timeline of incidents

The first publicly confirmed wave came on July 28, when Minnesota authorities said water treatment plants in more than 30 communities had been hit. Two days later, the FBI reported incidents at water and wastewater utilities in at least seven states, with some attacks disrupting operations. Later reports added Arkansas, Georgia, New Jersey and Michigan to the list.

Who is behind the attacks?

No one has officially been named as responsible. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had warned in April, and updated its advisory before the Minnesota attacks, that Iranian hackers were targeting internet-connected devices in water and energy systems. After the Minnesota news, President Donald Trump said he did not believe there was an Iranian cyberattack and instead blamed the state's Democratic governor. The Water Information Sharing and Analysis Center (WaterISAC), which shares cybersecurity data across the sector, told members the attacks aligned with CISA's warning. The Washington Post later reported that U.S. intelligence agencies were confident Iran's Islamic Revolutionary Guard Corps (IRGC) was behind the campaign. The attribution has not been made public, sources said, because the specific IRGC unit remains unclear and officials may be reluctant to contradict Trump. Iran has previously targeted U.S. critical infrastructure. In March, a group known as Handala, which the U.S. links to Iran's Ministry of Intelligence and Security, disrupted medical device maker Stryker and later claimed to have hacked the personal Gmail account of FBI Director Kash Patel.

Impact and concerns

The FBI said attacks caused pressure loss that could allow untreated groundwater to seep into pipes, as well as flooding. The Minnesota town of Braham had to shut its water plant for hours and asked residents to conserve water; Maple Plain briefly declared a state of emergency. In a county near Atlanta, Georgia, residents were told to boil water as a precaution. Forescout, a cybersecurity firm, found more than 2,800 controllers in U.S. water systems exposed online, though exposure alone does not mean takeover. Beyond physical disruptions, the attacks have caused widespread alarm. Media coverage has fueled public concern about water safety, a fear that experts say may be exactly what the hackers intended.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category