
Recent coordinated cyberattacks on water facilities across roughly a dozen US states have raised critical security concerns and sparked fears of infrastructure vulnerability.
Several US water utilities across about a dozen states have been hit by coordinated cyberattacks, raising alarm and prompting suspicions of Iranian state-backed involvement amid widespread infrastructure vulnerabilities.
AI-generated summary
US water utilities have faced historical targeting by hackers, but recent coordinated attacks across multiple states indicate a potential escalation.
Since the end of last month, several water utilities in the United States have been hit by cyberattacks, causing alarm in the country.
For years, water utilities and other critical infrastructure facilities in the power sector, for example, have been targeted by hackers, whether government-backed or individuals. What makes these recent attacks — allegedly carried out by Iran — particularly concerning is how widespread they were, hitting targets in around a dozen states.
The U.S. has more than 150,000 water systems, some of them run by local companies. In theory, that should make it harder for hackers to target several facilities at the same time. But on the flip side, the companies running these systems may not have the resources or cybersecurity expertise needed to protect themselves.
Cybersecurity experts have long believed that Iranian hackers target low-hanging fruit in opportunistic isolated attacks, so this hacking campaign could be a significant escalation.
A lot has happened since news of the initial attacks broke two weeks ago. So we decided it was a good time to recap what we know so far, and what we don’t.
Where have there been attacks?
On July 28, Minnesota authorities announced that water treatment plants in more than 30 communities were hit by coordinated cyberattacks.
Two days later, the FBI said water and wastewater utility companies in “at least seven states” reported incidents, and in some cases the attacks “degraded water operations.” Since then, apart from Minnesota, there have been reported hacks against water facilities in Arkansas, Georgia, New Jersey, and Michigan.
Who is behind the attacks?
The short answer is: we don’t know yet, but the No. 1 suspect is the Iranian government.
As of today, officially, the U.S. government has yet to name the culprit behind the coordinated wave of hacks.
However, the first incidents in Minnesota came days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without saying where those attacks were occurring. (CISA had originally published this warning in April, and updated it before the Minnesota attacks.)
After the initial wave was uncovered in Minnesota, President Donald Trump said he did not think “there was an Iranian cyberattack.” Instead, he blamed the state, perhaps because it is run by democratic governor Tim Walz, who was chosen as Kamala Harris’ vice president candidate in the 2024 elections.
Trump’s claim came a day after Wired reported that the Water Information Sharing and Analysis Center, or WaterISAC, a nonprofit group that distributes cybersecurity information among the water sector, told its members that the recent attacks “aligned” with the hacking campaign CISA warned of — effectively accusing the Iranian government.
Earlier this week, The Washington Post reported that U.S. intelligence agencies “are confident” that Iran, and in particular the Islamic Revolutionary Guard Corps (IRGC), is responsible. The attribution isn’t public yet, according to the paper’s sources, because the agencies are not sure which specific unit within the IRGC was responsible, and also because officials may be reluctant to contradict Trump’s claim.
Iranian government hackers have a history of targeting critical infrastructure in the U.S., and it’s possible that these attacks are part of its strategy to retaliate against the country because of the six-month war.
Until now, Iranian hackers had only limited success in their cyberattacks against U.S. targets. In March, a hacktivist group called Handala disrupted the operations of medical tech giant Stryker. The U.S. government later accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). Then, the group claimed responsibility for hacking the personal Gmail account of FBI director Kash Patel.
What effects have the attacks had?
The reality is that some systems inside critical infrastructure facilities are exposed to the internet and relatively easy to find. Earlier this month, cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems exposed online. If a system is exposed, it doesn’t automatically mean hackers can take over control and cause real-world effects. But that has happened in some isolated cases in recent attacks.
The FBI said some of the cyberattacks around the country caused loss of pressure, which “could potentially allow untreated groundwater to seep into pipes,” and flooding.
The town of Braham in Minnesota, one of the first to report an incident, had to take its water plant offline for a few hours, urging its around 1,700 residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local officials briefly told residents to boil water before using it as a precautionary measure.
The worst effect, however, may be psychological. These attacks have been widely covered in national and local press, causing people to worry about the safety of a fundamental and basic need like water. That may very well be part of the hackers’ goals: to spread panic and fear.
AI outlook — possibilities, not facts
US intelligence agencies will formally attribute the attacks to the Iranian government.
Likely · Within weeks

Romania intercepted and destroyed an explosive-laden drone boat near the Neptun Deep gas platform in the Black Sea. Officials blamed Russia for the incident, marking the second such threat to the critical energy infrastructure this month.

President Donald Trump signed a national space transportation policy aiming for over 1,000 annual launches by 2030. The directive mandates infrastructure upgrades at federal spaceports, improved scheduling transparency, and the identification of new launch sites for geographic resiliency.

A new Pentagon report shows that more U.S. service members are reporting unwanted sexual contact, with reporting rates rising to 33% in fiscal year 2025. Meanwhile, the overall prevalence of sexual assault and harassment incidents decreased among active duty personnel.

The USS Abraham Lincoln is returning after a nine-month deployment. Reports of deteriorating mental health and potential suicide attempts among the 5,000-person crew have surfaced, with experts citing extended isolation and inconsistent leadership messaging as key stressors.

The US and South Korea concluded their military drills six days early in a gesture to North Korea, but Pyongyang dismissed the move and test-fired about 10 short-range ballistic missiles.

The U.S. Army has directed a specialized drone warfare battalion within the 173rd Airborne Brigade to end its unmanned technology efforts and return to traditional infantry duties under acting chief of staff Gen. Christopher LaNeve.