Washington: At least seven US states have reported cyber intrusions targeting water and wastewater systems, putting critical infrastructure security under renewed scrutiny and raising questions over whether Iran-linked hackers are behind the campaign. The attacks, which began coming to light in late July, affected municipal systems and exposed vulnerabilities in internet-connected equipment used to control water operations.

At least 30 municipal water systems in Minnesota were targeted in what state officials described as a coordinated cyberattack. The Federal Bureau of Investigation (FBI) subsequently warned that malicious cyber actors had breached water and wastewater systems in at least seven states, causing operational disruptions. Similar incidents have also been reported in states including Georgia, New Jersey and South Dakota, although it remains unclear whether all of those incidents are part of the FBI’s seven-state assessment.

Iran has emerged as a major focus of the investigation because US officials have been examining possible links to Iranian hackers. However, Washington has not formally attributed the latest attacks to Iran, and investigators are still examining technical evidence. There is also a possibility that another actor could have copied Iranian tactics to mislead investigators.

The incidents have not so far resulted in reports of drinking water being deliberately contaminated or rendered unsafe. However, some systems experienced operational disruptions, requiring manual intervention and precautionary boil-water advisories.

What happened to US water systems?

The attacks came to light in late July when Minnesota reported that at least 30 municipal water systems had been targeted.

The incidents raised concern because water utilities rely increasingly on digital systems to monitor and control operations. Equipment connected to these networks can regulate functions such as water pressure, pumping and chemical dosing.

The FBI later warned that malicious cyber actors had penetrated water and wastewater systems in at least seven US states.

The scale of the incidents has made the campaign particularly significant. The US has approximately 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities, according to federal government data cited by NDTV.

The systems range from large metropolitan utilities to small municipal facilities, creating a huge and varied cybersecurity landscape.

Why are water systems vulnerable to hackers?

Modern water infrastructure relies on a combination of physical machinery and computer-controlled systems.

Water is generally drawn from sources such as rivers, reservoirs, lakes and underground aquifers. Electric pumps move the water through pipelines to treatment facilities, where it is filtered and disinfected before being stored and distributed to consumers.

A network of sensors and controllers helps operators monitor these processes.

Many facilities use programmable logic controllers (PLCs) to control industrial equipment. These devices can monitor and adjust water pressure, pumping systems and chemical dosing.

The problem arises when such operational technology is exposed directly or indirectly to the internet.

Cybersecurity experts have warned that internet-facing controllers and dashboards can provide attackers with a route into systems that were traditionally separated from the wider internet.

What are PLCs and why do they matter?

PLCs are specialised computers used to control machinery and industrial processes.

In a water treatment facility, a PLC can receive information from sensors and issue commands to equipment. Depending on the system, it can influence functions such as pumps, valves, pressure controls and chemical dosing.

Operators can monitor these processes through dashboards.

According to an explanation cited by NDTV, attackers can scan internet addresses for exposed controllers, dashboards and remote-access services. They may then attempt to gain entry using default or stolen passwords, unpatched vulnerabilities or incorrectly configured remote-access systems.

Once access is obtained, attackers could potentially change passwords, issue commands or attempt to alter controller software.

That makes the security of these devices particularly important because a cyberattack does not necessarily need to target a utility’s main computer network to affect physical operations.

How the attacks can disrupt water operations

A successful intrusion into operational technology can interfere with the way a water facility is monitored or controlled.

An attacker could potentially disrupt communication between operators and equipment, change system settings or interfere with the information shown on an operator’s dashboard.

Even when the water itself remains safe, losing remote control can create operational problems.

Operators may have to switch to manual controls until affected systems are secured.

That can require additional staff, slow down operations and increase the risk of mistakes, particularly at smaller facilities that may have limited technical resources.

Recent attacks have reportedly caused disruptions requiring manual overrides. Some authorities also issued boil-water advisories as a precaution, although there has been no report that these attacks contaminated drinking water.

Why Iran is being investigated

Iran has come under scrutiny because US authorities have previously warned about cyber activity associated with Iranian actors targeting critical infrastructure.

In April 2026, the US Environmental Protection Agency, FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency issued a joint advisory warning of an ongoing Iranian-affiliated cyber threat affecting organisations including water and wastewater systems.

The advisory said Iranian-affiliated actors had been exploiting operational technology used by critical infrastructure.

The EPA later highlighted threats involving internet-exposed PLCs and described the continuing risk to water and wastewater systems.

A July update to the US government’s warnings also expanded the types of industrial control systems being targeted, according to reporting on the federal advisory.

This history explains why investigators are examining a possible Iranian connection to the latest attacks.

However, a suspected link is not the same as formal attribution.

US has not formally blamed Iran

Despite the focus on Iran, US authorities have not publicly confirmed that Tehran ordered or carried out the latest water-system attacks.

NDTV reported that US officials are investigating whether Iranian hackers are involved while cautioning that the assessment could change as investigators collect additional technical evidence.

Investigators are also considering whether another actor may have deliberately copied techniques associated with Iranian hackers.

Such a possibility is important because cyberattacks can be designed to create misleading digital fingerprints.

Attributing a cyberattack requires more than identifying similarities in tools or techniques. Investigators typically examine technical indicators, infrastructure, malware, account activity and other intelligence before reaching a conclusion.

Donald Trump questions Iran connection

US President Donald Trump has also questioned the suggestion that Iran was responsible for the Minnesota attacks.

According to NDTV, Trump blamed Minnesota authorities and expressed scepticism about claims pointing to Iran. He said Iran had bigger problems to deal with than worrying about Minnesota.

The comments have added a political dimension to an already sensitive cybersecurity investigation.

The broader issue, however, extends beyond the question of which country was responsible.

The attacks have highlighted vulnerabilities in critical infrastructure that could potentially be exploited by a range of criminal or state-linked actors.

No evidence of contaminated drinking water

One of the most important points is that there is currently no reported evidence that the attacks made US drinking water unsafe.

The incidents have caused operational disruptions, but authorities have not reported contamination resulting from the cyber intrusions.

Some communities issued precautionary boil-water advisories after disruptions, but those measures were taken as a safety precaution rather than because authorities had confirmed deliberate contamination.

This distinction is important because reports of hacked water systems can create public anxiety about the safety of drinking water.

For now, the primary demonstrated risk has been disruption of operations rather than confirmed contamination.

Why small water utilities are particularly exposed

The US water sector includes thousands of small municipal utilities.

Unlike large metropolitan utilities, smaller systems may have limited cybersecurity budgets, fewer specialised employees and greater reliance on outside contractors.

That can make it difficult to maintain complex industrial control systems securely.

The technology used by a water utility may have been installed years earlier, while remote-access requirements and internet connectivity have grown over time.

If old equipment is connected to modern networks without adequate security controls, attackers may have more opportunities to gain access.

The Minnesota incidents have therefore prompted renewed discussion about the cybersecurity resilience of smaller municipalities.

The wider critical infrastructure threat

The concern is not limited to water.

Industrial control systems are used across numerous sectors, including energy, manufacturing, transport and other critical services.

US authorities have previously warned about Iranian-affiliated actors targeting operational technology in critical infrastructure.

The July 2026 federal warning said Iranian-linked hackers had targeted industrial control systems used by American water and energy providers, according to TechCrunch’s report on the advisory.

This means the latest water-system incidents are part of a broader debate over the security of operational technology.

A cyberattack against an office network may cause data loss or temporary disruption. An attack against operational technology can potentially affect physical equipment.

That distinction makes industrial cybersecurity a national-security issue.

What can water utilities do?

Cybersecurity experts have recommended several measures to reduce the risk.

One of the most important is ensuring that PLCs and operator dashboards are not directly exposed to the public internet.

Where remote access is necessary, utilities can use secure gateways and VPNs, require multi-factor authentication and limit user permissions.

Default passwords should be changed, unnecessary remote-access services disabled and vendor-approved security updates installed.

Operational networks should also be separated from ordinary business networks wherever possible.

This can make it more difficult for an attacker who compromises an employee’s computer or email account to move into the systems controlling physical infrastructure.

Manual operation remains an important safeguard

The recent incidents have also highlighted the importance of being able to operate water systems manually.

If operators lose access to digital controls, a facility should have procedures that allow essential functions to continue.

Experts have recommended backing up controller programmes, monitoring remote-access activity and regularly practising system restoration and manual operation.

These measures can reduce the impact of a cyberattack even if an attacker manages to gain access.

Cybersecurity therefore cannot depend entirely on preventing every intrusion.

Resilience and recovery are equally important.

The danger to public confidence

Experts say the consequences of such attacks can extend beyond physical disruption.

Water is an essential public service, and people expect it to be safe and reliably available.

Even a relatively limited cyber incident can undermine public confidence if residents believe authorities cannot protect essential infrastructure.

Former White House Deputy National Cyber Director Jake Braun told the BBC that attacks on basic services could affect trust in government, particularly during a period of heightened political tension.

This makes public communication an important part of cybersecurity response.

Authorities must explain what happened, whether water remains safe and what steps are being taken to restore secure operations.

Why the seven-state figure matters

The FBI’s identification of intrusions across at least seven states is significant because it indicates that the problem is not confined to a single municipality.

A single compromised utility could potentially be treated as an isolated cybersecurity incident.

Multiple incidents across different states suggest a broader campaign or a common vulnerability.

At the same time, investigators have not established that every reported incident is connected.

Georgia, New Jersey and South Dakota have reported similar attacks, but NDTV noted that it remains unclear whether these are included in the FBI’s original seven-state count.

That uncertainty means the final scope of the campaign could change as investigations continue.

Earlier warnings make the latest attacks more serious

The US government had already warned about Iranian-affiliated cyber threats to water infrastructure before the latest incidents.

The April joint advisory from the EPA, FBI, CISA and NSA described an ongoing threat and urged water-sector organisations to strengthen their cybersecurity.

The EPA’s subsequent guidance specifically addressed Iranian-affiliated actors targeting internet-exposed PLCs.

The latest attacks therefore demonstrate why authorities have been warning utilities to secure operational technology rather than treating it as isolated equipment.

Cybersecurity is becoming part of water security

Water security has traditionally been associated with physical issues such as drought, pollution, infrastructure damage and supply shortages.

Cybersecurity is now an increasingly important part of the same equation.

Water treatment and distribution systems depend on computers, sensors and communications networks.

If those digital systems are compromised, physical services can also be affected.

The recent incidents show that protecting water infrastructure requires both physical security and digital security.

What happens next?

The immediate priority for US authorities is to determine the full scope and origin of the attacks.

Investigators will examine affected systems, technical evidence and similarities between incidents in different states.

They will also need to determine whether the attacks were conducted by a single group or by multiple actors using similar methods.

If Iranian involvement is eventually confirmed, the incidents could add another dimension to the already tense relationship between Washington and Tehran.

If Iran is ruled out, investigators will still need to determine who was responsible and why the attackers targeted municipal water infrastructure.

Either way, the vulnerabilities exposed by the attacks are likely to remain a major concern.

Conclusion

The cyberattacks on water and wastewater systems across at least seven US states have placed America’s critical infrastructure under renewed scrutiny. At least 30 municipal water systems in Minnesota were targeted in late July, while the FBI subsequently warned of intrusions affecting water systems in multiple states.

Iran has emerged as a focus of the investigation because US authorities have previously documented Iranian-affiliated cyber activity against critical infrastructure, including water and wastewater systems. However, the US government has not formally attributed the latest attacks to Iran, and investigators are still examining technical evidence. There is also a possibility that another actor deliberately copied Iranian tactics.

The attacks targeted internet-connected operational technology, particularly PLCs and dashboards used to monitor and control functions such as water pressure and chemical dosing. Vulnerable remote-access services, weak passwords and exposed systems can provide attackers with an entry point.

So far, there has been no reported evidence that the attacks contaminated drinking water or made public water supplies unsafe. However, some systems experienced operational disruptions that required manual intervention, while precautionary boil-water advisories were issued in certain cases.

The incidents highlight a wider problem facing the US: thousands of water utilities depend on increasingly connected technology, while smaller municipalities may lack the resources required to defend complex industrial systems.

For now, the biggest question is not only whether Iran was behind the attacks, but whether the US can close the vulnerabilities that made the incidents possible. Strengthening network separation, securing remote access, using multi-factor authentication, updating equipment and maintaining effective manual backup procedures will be essential to protecting water infrastructure from future cyber threats.