Iran Cyberattack
US federal authorities are investigating a series of cyberattacks targeting water and wastewater facilities across multiple states, with intelligence officials and cybersecurity experts increasingly pointing toward Iranian-linked hackers as possible suspects. However, officials stress that the investigation remains ongoing and no formal public attribution has been made against Iran.
The attacks affected more than 30 community water systems in Minnesota, while similar incidents were reported in at least seven US states. Some utilities experienced disruptions after hackers altered passwords, modified control settings, or compromised industrial control systems used to manage water treatment and distribution.
Authorities said drinking water quality was not compromised, although several facilities temporarily switched to manual operations while restoring affected systems. The FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA) are jointly investigating the incidents.
US intelligence officials believe the attacks share technical similarities with previous campaigns attributed to Iranian-affiliated cyber groups. Federal cybersecurity advisories issued in recent months warned that Iranian actors were actively targeting internet-connected programmable logic controllers (PLCs) used in water and wastewater infrastructure.
Cybersecurity researchers say the latest attacks appear consistent with those earlier warnings. Nevertheless, officials caution that attribution in cyberspace is complex and investigators have not yet officially declared Iran responsible.
The cyber campaign has also sparked political controversy. President Donald Trump publicly questioned whether Iran was responsible, suggesting the attacks reflected failures by local authorities instead. His remarks contrasted with assessments from intelligence officials and cybersecurity experts, who continue to investigate possible Iranian involvement.
Experts warn that water infrastructure has become an increasingly attractive target because many facilities rely on aging operational technology with limited cybersecurity protections. They argue that utilities should disconnect critical control systems from the public internet, strengthen authentication mechanisms, and improve continuous monitoring.
The incidents highlight how cyber warfare has become a central feature of modern geopolitical competition. Even without physical attacks, digital intrusions targeting essential services such as water, electricity and transportation can create significant disruption and public anxiety. As investigations continue, US agencies are urging operators nationwide to review their cyber defenses and prepare for similar threats.