Hackers Are Targeting America's Water Systems — Here's What's Going On

Since late July 2026, a wave of cyberattacks has hit water and wastewater utilities across roughly a dozen U.S. states. Federal agencies and multiple media outlets have pointed to Iranian-affiliated hackers as the likely source. The U.S. government has not officially named a culprit as of mid-August 2026, though officials have told multiple outlets that Iran is the suspected source (TechCrunch).
The first major public signal came on July 28, 2026, when Minnesota authorities announced that water treatment plants in more than 30 communities had been hit by coordinated cyberattacks. Two days later, on July 30, the FBI disclosed that water and wastewater utilities in at least seven states had reported incidents, with some attacks degrading water operations. NBC News reported that the FBI's seven-state warning followed the Minnesota campaign, which bore hallmarks of Iranian involvement (NBC News). Reported incidents during the campaign also struck facilities in Arkansas, Georgia, New Jersey, and Michigan.
The New York Times reported on August 5 that federal and state officials believed the assault on the nation's water supply was the work of Iranian hackers and were racing to address it (New York Times). NPR reported on August 12 that the series of cyberattacks had exposed vulnerabilities across critical infrastructure amid the broader U.S.-Iran conflict (NPR).
The scale of the problem starts with the sheer number of systems involved. The U.S. has more than 150,000 public water systems serving over 300 million people, and the vast majority are run by small municipalities with limited cybersecurity staff and budget. CISA, the federal agency responsible for protecting critical infrastructure, identified the specific method: Iranian-linked hackers targeted devices called programmable logic controllers, or PLCs. These are specialized computers that control industrial processes like chemical dosing, filtration, and pump operations in water plants. When these devices are connected to the public internet, often protected only by default or weak passwords, they become easy targets. Hackers do not need advanced skills to break in and cause disruption.
Federal warnings predated the summer campaign by months. On April 7, 2026, the EPA, FBI, CISA, and NSA issued a joint cybersecurity advisory regarding Iranian-affiliated cyber attacks on U.S. water systems (EPA). CISA published advisory AA26-097A, "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers," on July 22, reporting that the FBI had observed Iranian-linked hackers targeting internet-exposed PLCs. CISA, the FBI, the EPA, and other government partners updated a joint warning the same day that Iranian-affiliated threat actors were targeting internet-connected devices in water systems and the energy sector, without specifying where the attacks were occurring (CISA). CISA's warning was originally published in April 2026 and updated before the Minnesota attacks.
The political context added friction. The Guardian reported that despite the Trump administration's efforts to blame Tim Walz and Minnesota for the attacks, officials suspected Iran was behind the campaign against U.S. infrastructure (The Guardian). The attribution question and the political response unfolded in parallel, complicating the public picture.
This is not the first time Iranian-linked actors have targeted these devices in U.S. critical infrastructure. CISA published a similar advisory in December 2024 detailing tactics and procedures obtained from an extensive FBI investigation. That advisory followed earlier warnings stretching back to at least 2022, when CISA published guidance on Iranian government-sponsored cyber operations. The FBI, CISA, and DC3 also released a joint advisory noting that, as of August 2024, a group of Iran-based cyber actors had been conducting cyber activity against U.S. targets. The current campaign fits a pattern of escalating targeting of industrial control systems that federal agencies have tracked for years.
The operational impact in this campaign appears to have been disruption rather than catastrophic failure. No verified reporting indicates that water safety was compromised at the treatment level. The attacks disrupted operations, which for water utilities can mean anything from loss of remote monitoring to manual override of automated treatment processes. The distinction matters: disrupting a device's control function is different from manipulating chemical levels in the water that reaches people's homes. The former creates operational disruption and cost; the latter would constitute a public health emergency.
The broader context here is that water and wastewater remains one of the least protected critical infrastructure sectors in the U.S. The sector's fragmentation, with tens of thousands of small systems operating independently, means that systemic improvements require coordination across entities that often lack dedicated IT security staff. Federal advisories can flag the threat and provide guidance, but the actual fixes, whether separating industrial networks from the internet, enforcing strong passwords on control devices, or removing those devices from the public internet entirely, happen at the facility level. The gap between federal warning and local capacity to act is where the vulnerability lives.
CISA's advisories have consistently recommended the same fixes: conduct regular vulnerability assessments, identify and inventory control devices, and restrict access to operational networks. The advice is sound and the measures are not technically complex. The barrier is organizational, not technical, and that has been true for years. In my view, the current campaign is less a revelation than a reminder that this barrier persists, and that the distance between a federal advisory and a small-town water plant with no cybersecurity budget is where the real risk takes root.


