A series of coordinated cyberattacks targeting water infrastructure across the United States (US) has triggered a major federal investigation, with authorities examining whether Iranian-linked hacking groups may be involved.
Although investigators have not officially blamed Iran, they say the attacks share similarities with previous cyber campaigns attributed to Iran-affiliated hackers. The incidents affected dozens of water and wastewater facilities across several states, forcing many utilities to temporarily switch to manual operations.
Officials have stressed that there is no evidence that drinking water was contaminated or that public water supplies were interrupted.
Cyber Campaign Targets Water Infrastructure Across Multiple States
The attacks first came to light in Minnesota, where more than 30 community water systems were targeted on July 26 and July 27.
According to Minnesota IT Services, investigators detected "unauthorized access with malicious intent" aimed at critical water infrastructure. Officials quickly classified the incidents as coordinated cyberattacks and launched a full investigation.
Emily Zimmer, spokesperson for Minnesota IT Services, said authorities are still examining the attacks.
“The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.”
However, she added that investigators are not yet ready to officially identify those responsible or release additional technical information.
The cyber campaign soon expanded beyond Minnesota.
US officials and sources familiar with the investigation said water and wastewater facilities in at least seven states have now reported suspicious cyber activity. Around six states experienced similar incidents within just one week.
Federal Agencies Join Investigation
Several federal agencies are working together to investigate the attacks and secure affected systems. The Federal Bureau of Investigation (FBI) confirmed it is working directly with impacted organisations "to resolve the matter."
Meanwhile, the US Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), state governments and other federal investigators are helping strengthen security at vulnerable facilities. Minnesota officials also reassured residents that there is currently no reason to change their water usage.
Authorities said they are "not aware of any active requests from Minnesota cities to have residents modify their drinking water usage," indicating there is no known threat to public drinking water.
How Hackers Targeted Water Facilities
Investigators believe the attackers focused on internet-connected programmable logic controllers (PLCs), which control many of the automated systems used in water treatment plants, pumping stations and wastewater facilities. These industrial devices regulate critical operations such as water pressure, chemical treatment, pumps and other essential processes.
If hackers successfully manipulate these systems, they could disrupt water operations or potentially create conditions that increase contamination risks.
According to an internal memo from the Minnesota Bureau of Criminal Apprehension, the attackers' "likely desired impact" was "to cause loss of system pressure and subsequent potential contamination of water supply."
Officials said the attacks were not especially sophisticated. Instead, hackers exploited PLCs that were directly connected to the internet without adequate security protections.
Experts Warn Hackers Are Searching Nationwide
Minnesota Chief Information Security Officer John Israel believes the attackers are scanning critical infrastructure across the country for vulnerable systems. “I suspect that those attackers are going to … continue to look nationally across the infrastructure,” Israel told CNN.
The hackers will "continue to rattle those doorknobs and try to break into systems that have weak configurations," he added.
Utilities Quickly Switched to Manual Operations
Several communities successfully limited the impact of the attacks by immediately switching from automated controls to manual operations. In South St. Paul, public works employees shifted to manual controls almost immediately, allowing water and sewer services to continue without interruption. Officials also confirmed that no customer data had been compromised.
In Braham, workers noticed a malfunctioning well pump early Monday and restored a backup system within 90 minutes, preventing any disruption to water services.
Plymouth also detected compromised controllers affecting two water towers and 14 sewer lift stations before restoring automated systems after temporary manual operation.
Is Iran Behind the Attacks?
Investigators are examining whether Iranian-linked hackers may be responsible, but no US agency has officially blamed Iran. Authorities say Iran remains one of several possible suspects because the methods used closely resemble previous cyber operations linked to Iranian hacking groups.
However, investigators caution that cybercriminals often copy another country's techniques to mislead investigators and create political confusion, especially during periods of international tension.
Zimmer said authorities cannot yet discuss formal attribution.
Similarities With Previous Iran-Linked Cyber Campaigns
Cybersecurity researchers say the latest attacks share several characteristics with earlier campaigns targeting American critical infrastructure.
Earlier this year, CISA warned that Iranian-affiliated hackers were targeting internet-connected programmable logic controllers manufactured by Rockwell Automation.
The agency later expanded its advisory to include equipment produced by Schneider Electric, Siemens and possibly other manufacturers.
Joe Slowik, director of threat research and cyber engineering at cybersecurity firm Dataminr, said the updated intelligence suggests a broader campaign.
“CISA’s updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States,” he told Reuters.
He added, “Extending this activity to encompass additional equipment lines and pairing this with process manipulation and safety degradation makes matters more concerning as it enables various physical impact scenarios.”
Federal agencies also pointed to previous incidents.
In 2023, CISA said hackers linked to Iran’s Islamic Revolutionary Guard Corps compromised multiple US water and wastewater facilities by exploiting industrial controllers that still used factory-default passwords.
Separately, the US Department of Justice previously charged an Iranian hacker over the 2013 cyber intrusion involving the control systems of a dam in Rye, New York.
Earlier this year, Iran-linked hackers were also reported to have disrupted operations at several US oil, gas and water facilities.
Trump and Minnesota Governor Clash
The cyberattacks also sparked a political dispute.
During a Cabinet meeting, President Donald Trump dismissed suggestions that Iran was responsible and instead blamed Minnesota officials.
“I just want to mention that we heard in Minnesota there was a cyberattack, and they blame it on Iran,” Trump said.
“I don’t think so. I think I blame it on Minnesota because they’re grossly incompetent.”
He added, “There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
Minnesota Governor Tim Walz responded on X by criticising Trump's comments.
“Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
Experts Call the Attacks Unprecedented
Cybersecurity specialists say the scale and coordination of the attacks make them among the most serious cyber incidents ever directed at US water infrastructure.
CISA has warned that attackers "are targeting water entities of all sizes" and urged utilities to disconnect exposed operational technology and cellular modems from the public internet wherever possible.
Acting CISA Director Nick Anderson also warned that attempts to compromise industrial control systems at water utilities have increased sharply across the country.
The Water Information Sharing and Analysis Center (WaterISAC) has also advised water utilities to strengthen cyber defences while investigations continue.
Gus Serino, a veteran cybersecurity expert specialising in water infrastructure, described the attacks as unprecedented.
“The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented.”
He added, “While the inherent resilience of the water sector helped limit operational impacts, these incidents once again demonstrate that many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls capable of preventing or significantly impeding this type of attack.”
Industrial cybersecurity expert Joshua Corman also warned about the growing threat.
“The rising number of water compromises is deeply concerning. So much depends upon water… No water, no hospital, no kidding… in 2-4 hours.”
He told CNN, “Water systems have enjoyed the benefits of remote access, but now those who wish us harm have it, too.”
“With great connectivity comes great responsibility. We should be asking ourselves: if we can’t protect it, should we disconnect it?”
Investigation Continues
Federal and state authorities continue to investigate the attacks while strengthening cybersecurity protections at water utilities nationwide.
Although investigators are examining similarities with previous Iran-linked cyber operations, officials emphasise that there is currently no confirmed evidence directly linking Iran to the latest attacks.
