Ask Finn← Discover
TOP STORIES

Iran Suspected as Hackers Breach Drinking Water Systems Across 12 States

By Cameron Brooks · Wednesday, August 5, 2026
Finn's Take· TL;DR
  • Hackers breached water systems across 12 U.S. states by compromising control devices, causing boil-water notices but no confirmed water contamination.
  • Iran suspected but unconfirmed as the attacker; officials warn of ongoing Iranian-affiliated cyber activity targeting critical infrastructure nationwide.
  • Water utilities lack basic cybersecurity defenses; FBI urges systems offline where possible and manual control preparation against future breaches.
See this from any side — with sources:
Left takeNeutralRight take

A Coordinated Strike on America's Taps

Hackers have targeted water systems in several U.S. states in a coordinated cyberattack that has caused some utilities to issue boil-water notices and switch to manual mode — making it one of the most serious cyberattacks on water systems in the United States in years, according to analysts. The scope of the breach has grown rapidly. Hackers have now targeted water and wastewater utilities in at least 12 states, up from the seven states the FBI initially confirmed were experiencing cyberattacks on systems that control pumps, water pressure, and valves.

The initial signs of the attack emerged between July 26 and 27, 2026, when authorities in Minnesota reported that hackers targeted about 30 water systems in their state. After gaining access to programmable logic controllers (PLCs), the threat actors remotely modified passwords and disconnected them by changing their IP addresses to lock out operators. The goal wasn't to poison the water — it was to seize control of the machinery that manages it.

How the Attack Works — and Why It's Dangerous

The hackers targeted internet-facing programmable logic controllers, the devices that allow machinery to communicate at water facilities and other industrial plants. These PLCs monitor water pressure, chemical dosing, and other critical features. By compromising these systems, attackers can effectively blind operators to what's happening inside their own infrastructure.

Some of these incidents have resulted in degraded water operations, including "loss of pressure and flooding," per the FBI. In Minnesota, some residents experienced low water pressure or received boil-water notices as a result. Still, the drinking water in affected regions has so far remained safe. Michigan authorities confirmed that "all systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern."

Iran in the Crosshairs — But Questions Remain

The FBI, EPA, and CISA put out a joint statement warning of "ongoing Iranian-affiliated cyber activity" targeting critical U.S. infrastructure, including water and wastewater systems, energy, government services and facilities, and local municipalities. Iran is the prime suspect in the cyberattacks, which can blind utility operators by changing passwords or disabling alarms, though its involvement has not been officially confirmed.

Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said he doesn't "think there was an Iranian cyberattack." Investigators are not ruling out other possibilities. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected — and they are also probing whether the actor could have attempted to appear Iran-based as a way of stirring tensions amid the ongoing U.S. conflict with Iran.

A Vulnerability Years in the Making

The attacks drew immediate comparisons to a 2023 incident involving a cyberattack on a municipal water facility near Pittsburgh, Pennsylvania, which CISA attributed to a group called CyberAv3ngers, affiliated with the Islamic Revolutionary Guard Corps. The pattern suggests this is not opportunistic hacking — it's a sustained campaign against a sector that has long been warned about its cybersecurity gaps.

As one official noted, "the inherent resilience of the water sector helped limit operational impacts," but these incidents "once again demonstrate that many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls." The FBI is urging utilities to disconnect systems from the internet where possible, use systems with breakers, and become familiar with reverting to manual controls if automated systems are compromised. With over 152,000 public water systems operating across the country, the sheer scale of potential exposure means the question facing officials isn't just who attacked — it's how many more systems remain one password change away from a crisis.

Have a question about this story?
Ask Finn — answers grounded in this article, from any viewpoint.