Alleged Iranian Cyberattacks Disrupt US Water Utilities Across Multiple States
Coordinated hacks have impacted water treatment plants in at least seven states, causing operational failures and boil-water advisories, while the White House disputes the foreign state actor narrative.

A coordinated wave of cyberattacks has targeted water treatment plants across approximately a dozen US states, including Minnesota, Arkansas, Georgia, New Jersey, and Michigan. The incidents have caused significant operational disruptions, including loss of water pressure and temporary plant shutdowns, leading to boil-water advisories and heightened public concern regarding critical infrastructure security.
While the US government has not officially attributed the attacks, intelligence agencies are reportedly confident that the Iranian government, specifically the Islamic Revolutionary Guard Corps (IRGC), is responsible. This assessment aligns with warnings issued earlier this year by the Cybersecurity and Infrastructure Security Agency (CISA), which highlighted Iranian hackers targeting internet-connected devices in water systems and the energy sector.
The first major incidents were reported in Minnesota on July 28, where authorities confirmed that water treatment plants in more than 30 communities were hit. Two days later, the FBI reported similar incidents in at least seven states, noting that some attacks had degraded water operations. Subsequent reports identified hacks in Arkansas, Georgia, New Jersey, and Michigan, suggesting a widespread campaign rather than isolated incidents.
The political response has been sharp. President Donald Trump stated he did not believe there was an Iranian cyberattack, instead blaming the state of Minnesota. This comment came despite reports from The Washington Post that US intelligence agencies are confident in the attribution to Iran but have not made it public, partly due to uncertainty regarding the specific IRGC unit involved and reluctance to contradict the President’s denial.
The Water Information Sharing and Analysis Center (WaterISAC) told members that the attacks aligned with the campaign previously warned about by CISA, effectively accusing the Iranian government. Meanwhile, cybersecurity firm Forescout reported finding more than 2,800 controllers in US water systems exposed online earlier this month, highlighting vulnerabilities that may have facilitated the breaches.
Specific impacts included the town of Braham, Minnesota, taking its water plant offline for a few hours, and Maple Plain, Minnesota, briefly declaring a state of emergency. In a county outside Atlanta, Georgia, officials issued a precautionary boil-water advisory. The FBI noted that the loss of pressure could potentially allow untreated groundwater to seep into pipes, posing health risks.
The attacks have also caused significant psychological distress, with widespread media coverage leading to public anxiety over water safety. Experts suggest that spreading panic may be a strategic goal for the hackers, who have a history of targeting critical infrastructure, including previous incidents linked to Iran’s Ministry of Intelligence and Security.

