Skip to content
Breaking:

Suspected Iranian Cyberattacks Hit U.S. Water Systems Across Multiple States

Coordinated intrusions targeting exposed utility controllers highlight systemic security gaps across decentralized municipal infrastructure.

By The Company Wire4 min read
Share
Forescout — Suspected Iranian Cyberattacks Hit U.S. Water Systems Across Multiple States
Forescout — Suspected Iranian Cyberattacks Hit U.S. Water Systems Across Multiple States. Photo: TechCrunch.

A widespread wave of cyberattacks targeting municipal water facilities across approximately one dozen U.S. states has raised federal security concerns regarding vulnerabilities in critical domestic infrastructure. The intrusions, which began surfacing late last month, mark a significant escalation in offensive digital campaigns directed at public utility systems. While American power grids and water distribution networks have faced routine probing by foreign state-sponsored groups and independent actors for years, the geographic reach and speed of the recent campaign present unprecedented challenges for federal defenders.

The timeline of public disclosures commenced on July 28, when authorities in Minnesota revealed that water treatment plants servicing more than 30 distinct communities had been hit by coordinated cyber intrusions. Two days later, the Federal Bureau of Investigation announced that water and wastewater management operators in at least seven states had reported similar security incidents, with several facilities experiencing degraded operational capabilities. Beyond Minnesota, confirmed cyber breaches have affected water utility infrastructure in Arkansas, Georgia, New Jersey, and Michigan.

Federal security officials had issued preemptive warnings prior to the initial breaches in Minnesota. The U.S. Cybersecurity and Infrastructure Security Agency updated an advisory initially published in April, warning critical infrastructure operators that Iranian state-backed hackers were actively targeting internet-connected control devices across energy and water facilities. Following the Minnesota attacks, the Water Information Sharing and Analysis Center—a nonprofit organization that distributes threat intelligence to water utilities—notified its members that the recent intrusions directly aligned with the threat campaign described by CISA, according to reporting by Wired.

Despite the advisory, public attribution has drawn political friction. President Donald Trump publicly dismissed claims of an Iranian cyber campaign, placing responsibility for the breaches on Minnesota state leadership under Democratic Governor Tim Walz, who served as Vice President Kamala Harris’s running mate in the 2024 presidential election. However, reporting from The Washington Post indicates that U.S. intelligence agencies hold high confidence that the Iranian government and its Islamic Revolutionary Guard Corps are responsible for the attack vector. Intelligence officials have delayed formal public attribution while working to identify the specific IRGC unit involved and navigating sensitivities surrounding executive statements.

The core vulnerability enabling the multi-state campaign stems from the structural fragmentation of American water infrastructure, which comprises more than 150,000 separate water systems. Many local operators are managed by small municipal entities or private regional firms that lack the financial capital, dedicated cybersecurity staff, and technical expertise required to secure complex operational networks. Recent scanning analysis from cybersecurity firm Forescout identified more than 2,800 industrial controllers in U.S. water facilities connected directly to the open internet without adequate protective isolation.

The broad offensive represents a departure from prior Iranian cyber operations, which historically focused on isolated, low-hanging targets with variable rates of success. Earlier this year in March, a hacktivist collective operating under the moniker Handala disrupted operations at major medical technology manufacturer Stryker. Federal authorities subsequently attributed Handala’s operations to Iran’s Ministry of Intelligence and Security. That same collective later claimed responsibility for breaching the personal Gmail account of FBI Director Kash Patel.

Although internet exposure does not automatically allow remote threat actors to take full administrative control over industrial equipment, several recent breaches caused real-world operational impact. According to the FBI, multiple facility compromises resulted in sudden pressure drops within water lines—a condition that risks allowing untreated groundwater to infiltrate municipal distribution pipes—as well as localized operational flooding. In Braham, Minnesota, local officials were forced to take the town's water plant offline for several hours, urging its roughly 1,700 residents to conserve water. Elsewhere in Minnesota, the city of Maple Plain declared a temporary state of emergency, while officials in a county outside Atlanta, Georgia issued precautionary boil-water advisories to local residents.

In addition to physical operational disruptions, security analysts note that targeting essential municipal utilities generates significant public anxiety regarding basic necessities like drinking water. As detailed in comprehensive coverage first reported by TechCrunch, the psychological impact of multi-state infrastructure breaches underscores the acute ongoing risks posed by exposed industrial control systems across small and mid-sized public utility providers.

Sources

  1. TechCrunch

Company: Forescout

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.