**A wave of cyberattacks against water services in the United States has put authorities on alert, with incidents reported in at least a dozen states since late July. Intelligence agencies point to Iran as the main suspect, but President Trump downplays the threat. Meanwhile, the operational and psychological effects are spreading across the country.
A wave of cyberattacks against water services in the United States has put authorities on alert, with incidents reported in at least a dozen states since late July. TechCrunch has compiled details of this incident, which initially hit Minnesota and then spread to Arkansas, Georgia, New Jersey, and Michigan. The Trump administration has yet to officially attribute responsibility, but intelligence agencies point to Iran as the main suspect, specifically the Islamic Revolutionary Guard Corps (IRGC).
Water infrastructure in the U.S. is a frequent target for malicious actors, but the scale of this campaign is unusual. The country has over 150,000 water systems, many operated by local companies with limited cybersecurity resources. This fragmentation makes the sector an attractive target, as while some systems have robust protections, others expose controllers to the Internet without adequate safeguards. The firm Forescout found over 2,800 water controllers exposed online, highlighting a broad attack surface.
On July 28, Minnesota authorities announced that water treatment plants in over 30 communities were affected by coordinated cyberattacks. Two days later, the FBI reported that water and wastewater service companies in at least seven states reported incidents, and in some cases, the attacks degraded water operations. Since then, in addition to Minnesota, hacks have been reported against facilities in Arkansas, Georgia, New Jersey, and Michigan, although the list could be broader as the investigation evolves.
The geographical dispersion has complicated the coordinated response. The FBI stated that some of the cyberattacks nationwide caused loss of pressure, which could allow untreated groundwater to seep into pipes, and flooding. In Minnesota, the city of Braham had to take its water plant offline for several hours, urging its approximately 1,700 residents to conserve water. Another locality, Maple Plain, briefly declared a state of emergency, while in a county outside Atlanta, Georgia, local authorities advised residents to boil water before using it as a precaution.
The speed with which the incidents occurred suggests prior coordination, according to cybersecurity experts. Water services are critical infrastructure, and their compromise can have direct effects on public health, prompting immediate responses from local authorities for each case. However, the lack of a unified national protocol complicates the assessment of the total damage, which has not yet been officially quantified by the federal government.
The short answer is that we still don’t know, but the main suspect is the Iranian government. As of today, the U.S. government has not officially named a culprit for the coordinated wave of hacks. However, the first incidents in Minnesota occurred days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting Internet-connected devices in water systems and the energy sector, without specifying where those attacks were happening. CISA had originally issued this warning in April and updated it before the attacks in Minnesota.
After the first wave was discovered, President Donald Trump said he did not believe there was an Iranian cyberattack and blamed the state of Minnesota, perhaps because it is run by Democratic Governor Tim Walz, who was chosen as Kamala Harris's vice-presidential candidate in the 2024 elections. Trump’s assertion came a day after Wired reported that the Water Information Sharing and Analysis Center (WaterISAC), a nonprofit group that distributes cybersecurity information among the water sector, told its members that the recent attacks aligned with the hacking campaign that CISA warned about, effectively accusing the Iranian government.
Earlier this week, The Washington Post reported that U.S. intelligence agencies are confident that Iran, and specifically the IRGC, is responsible. The attribution is not yet public, according to sources from the newspaper, because agencies are unsure which specific unit within the IRGC was responsible, and also because officials may be reluctant to contradict Trump’s assertion. Iranian government hackers have a history of attacking critical infrastructure in the U.S., and these attacks may be part of their strategy to retaliate against the country due to the six-month war.
So far, Iranian hackers have had only limited success in their cyberattacks against U.S. targets. In March, a hacktivist group called Handala disrupted operations at the medical technology giant Stryker. The U.S. government then accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). The group later claimed responsibility for hacking the personal Gmail account of FBI Director Kash Patel.
The reality is that some systems within critical infrastructure facilities are exposed to the Internet and are relatively easy to find. The cybersecurity firm Forescout reported finding over 2,800 controllers in U.S. water systems exposed online. If a system is exposed, it does not automatically mean that hackers can take control and cause real-world effects, but this has occurred in some isolated cases in recent attacks, as evidenced by reported incidents.
The FBI said that some of the cyberattacks across the country caused loss of pressure, which could allow untreated groundwater to seep into pipes, leading to flooding. The city of Braham in Minnesota, one of the first to report an incident, had to take its water plant offline for several hours, urging its approximately 1,700 residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local authorities briefly told residents to boil water before using it as a precaution.
The worst effect, however, may be psychological. These attacks have been widely covered by national and local media, causing people to worry about the security of a fundamental and basic necessity like water. It is very possible that this is part of the hackers' objectives: to sow panic and fear. The feeling of vulnerability extends beyond the directly affected communities and could influence public confidence in critical infrastructure.
The federal response so far has been to monitor the situation, but there has been no formal emergency declaration. National security officials insist that there is no evidence that the attacks have compromised water quality in most cases, but uncertainty persists. Meanwhile, water service companies are reviewing their security protocols, although many lack the budget to implement advanced measures.
In the geopolitical arena, these cyberattacks occur at a time of tension between Iran and the U.S., exacerbated by the conflict in the Middle East. Attribution to state actors is often complex, but the intelligence community seems to have reached an internal consensus. The delay in making the attribution public reflects both the need for more information about the responsible unit and the political implications of accusing a country while Trump downplays the incident.
For the water sector, the episode underscores the urgency of improving cybersecurity in essential infrastructures. Although the federal government offers support programs, their adoption is voluntary, and many small businesses do not prioritize these risks. Experts warn that without mandatory regulation, attacks like this could become more frequent. The media attention these incidents have received could be a catalyst for authorities to take concrete action.
Meanwhile, residents of the affected cities must live with uncertainty, and local authorities are trying to restore normalcy. The investigation continues, and the FBI and CISA are expected to release more details in the coming days. What is clear is that water security can no longer be taken for granted, and malicious actors see these systems as a vulnerable and high-impact target.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.






















![[SCAN 2026 Final Interview] ④1nf1n1ty: Solid Experience Built Through Over 200 CTFs](/public-static/26_2e1840f602.png?format=avif)






