Technology

Iranian-Linked Cyberattacks Target U.S. Water Utilities: What We Know

Martin HollowayPublished 5h ago6 min readBased on 18 sources
Reading level
Iranian-Linked Cyberattacks Target U.S. Water Utilities: What We Know
Photo by Fernando Narvaez on Pexels

Since late July 2026, a wave of cyberattacks has hit water and wastewater utilities across roughly a dozen U.S. states. Federal agencies and multiple media outlets have attributed the activity to Iranian-affiliated threat actors. The U.S. government has not officially named a culprit as of mid-August 2026, though officials have told multiple outlets that Iran is the suspected source (TechCrunch).

The first major public signal came on July 28, 2026, when Minnesota authorities announced that water treatment plants in more than 30 communities had been hit by coordinated cyberattacks. Two days later, on July 30, the FBI disclosed that water and wastewater utilities in at least seven states had reported incidents, with some attacks degrading water operations. NBC News reported that the FBI's seven-state warning followed the Minnesota campaign, which bore hallmarks of Iranian involvement (NBC News). Reported incidents during the campaign also struck facilities in Arkansas, Georgia, New Jersey, and Michigan.

The New York Times reported on August 5 that federal and state officials believed the assault on the nation's water supply was the work of Iranian hackers and were racing to address it (New York Times). NPR reported on August 12 that the series of cyberattacks had exposed vulnerabilities across critical infrastructure amid the broader U.S.-Iran conflict (NPR).

The attack surface is well documented. The U.S. has more than 150,000 public water systems serving over 300 million people, the vast majority operated by small municipalities with limited cybersecurity staff and budget. CISA's advisory identified the specific vector: Iranian-affiliated APT actors targeting internet-exposed programmable logic controllers with the intent to cause disruptions. APT, or advanced persistent threat, refers to skilled, often state-sponsored hacking groups that maintain long-term access to targeted systems. PLCs are specialized computers used in industrial settings to control processes such as chemical dosing, filtration, and pump operations. When exposed to the public internet, often with default or weak passwords, they become easy targets for actors who do not need to develop sophisticated exploit chains to cause operational impact.

Federal warnings predated the summer campaign by months. On April 7, 2026, the EPA, FBI, CISA, and NSA issued a joint cybersecurity advisory regarding Iranian-affiliated cyber attacks on U.S. water systems (EPA). CISA published advisory AA26-097A, "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers," on July 22, reporting that the FBI had observed Iranian-affiliated APT actors targeting internet-exposed PLCs. CISA, the FBI, the EPA, and other government partners updated a joint warning the same day that Iranian-affiliated threat actors were targeting internet-connected operational technology systems. The advisory warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without specifying where the attacks were occurring (CISA). CISA's warning was originally published in April 2026 and updated before the Minnesota attacks.

The political context added friction. The Guardian reported that despite the Trump administration's efforts to blame Tim Walz and Minnesota for the attacks, officials suspected Iran was behind the campaign against U.S. infrastructure (The Guardian). The attribution question and the political response unfolded in parallel, complicating the public picture.

This is not the first time Iranian-linked actors have targeted PLCs in U.S. critical infrastructure. CISA published advisory AA23-335A in December 2024, "IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple," detailing tactics, techniques, and procedures obtained from an extensive FBI investigation. That advisory followed earlier warnings stretching back to at least 2022, when CISA published AA22-055A on Iranian government-sponsored cyber operations. The FBI, CISA, and DC3 also released a joint advisory noting that, as of August 2024, a group of Iran-based cyber actors had been conducting cyber activity against U.S. targets. The current campaign fits a pattern of escalating, iterative targeting of operational technology systems that federal agencies have tracked for years.

The operational impact in this campaign appears to have been degradation rather than catastrophic failure. No verified reporting indicates that water safety was compromised at the treatment level. The attacks disrupted operations, which for water utilities can mean anything from loss of remote monitoring visibility to manual override of automated treatment processes. The distinction matters: degrading a PLC's control function is different from manipulating chemical levels in finished water. The former creates operational disruption and cost; the latter would constitute a public health emergency.

The broader context here is that water and wastewater remains one of the least hardened critical infrastructure sectors in the U.S. The sector's fragmentation, with tens of thousands of small systems operating independently, means that systemic improvements require coordination across entities that often lack dedicated IT security staff, let alone specialists in operational technology. Federal advisories can flag the threat and provide indicators of compromise, but the remediation, whether segmenting OT networks, enforcing strong authentication on PLC interfaces, or removing those interfaces from the public internet entirely, happens at the facility level. The gap between federal warning and local capacity to act is where the vulnerability lives.

CISA's advisories have consistently recommended the same mitigations: conduct regular vulnerability assessments, identify and inventory PLCs and other OT devices, and restrict access to operational technology networks. The advice is sound and the measures are not technically complex. The barrier is organizational, not technical, and that has been true for years. In my view, the current campaign is less a revelation than a reminder that this barrier persists, and that the distance between a federal advisory and a small-town water plant with no cybersecurity budget is where the real risk takes root.