Key facts
- Water utilities in at least seven U.S. states have been targeted by cyberattacks.
- U.S. intelligence agencies are confident that Iran, specifically the Islamic Revolutionary Guard Corps (IRGC), is behind the attacks.
- The attacks have led to operational disruptions, including loss of pressure and potential water contamination.
- Some affected communities, like Braham, Minnesota, had to take water plants offline, while others issued boil water advisories.
- President Donald Trump has publicly stated he does not believe the attacks were carried out by Iran.
A series of cyberattacks targeting water utilities across the United States has raised alarms, with U.S. intelligence agencies increasingly confident that Iran is behind the coordinated assaults. The incidents, which began surfacing in late July, have affected water systems in at least seven states, including Minnesota, Arkansas, Georgia, New Jersey, and Michigan.
The FBI confirmed that some attacks degraded water operations, leading to issues such as loss of pressure and potential contamination. The town of Braham, Minnesota, had to temporarily shut down its water treatment plant, urging residents to conserve water, while Maple Plain, Minnesota, briefly declared a state of emergency. In Georgia, a precautionary boil water advisory was issued.
While U.S. government agencies have not officially named the perpetrator, The Washington Post reported that intelligence agencies are confident the Islamic Revolutionary Guard Corps (IRGC) is responsible. This attribution is reportedly delayed due to uncertainty about the specific unit involved and potential reluctance to contradict President Donald Trump's public statements suggesting he did not believe it was an Iranian cyberattack.
Cybersecurity experts note that this campaign represents a potential escalation, as Iranian hackers have historically focused on less sophisticated, opportunistic attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had previously warned about Iranian targeting of internet-connected devices in water and energy sectors, a warning that aligns with the recent incidents, according to the Water Information Sharing and Analysis Center (WaterISAC).
The widespread nature of the attacks, hitting facilities in numerous states, is particularly concerning given the vast number of water systems in the U.S. While this decentralization theoretically makes mass targeting difficult, many smaller utilities may lack adequate resources for robust cybersecurity. Beyond operational impacts, the attacks have also generated significant public anxiety regarding the safety of essential water supplies, a psychological effect that may be a deliberate goal of the hackers.
