
Across at least 12 American states, hackers have quietly broken into local water systems’ control gear, turning the taps of cyber war while the water coming out of your faucet still runs clear.
Story Snapshot
- Water and wastewater utilities in at least 12 states report cyberattacks on critical control systems.
- Federal agencies warn of an “urgent and ongoing” Iranian-affiliated threat, but have not issued formal attribution.
- Operations were disrupted in some towns, yet officials say drinking water remains safe so far.
- President Trump publicly doubts Iran is behind the attacks, putting politics directly into a cybersecurity crisis.
Coordinated cyber strikes on small-town water systems
Hackers have targeted water and wastewater utilities in at least 12 states, hitting the technology that controls pumps, valves, water pressure, and alarms across the country.
The Federal Bureau of Investigation said last week that at least seven states had already reported attacks on these systems, and the number has since grown as more utilities discover intrusions. These are not giant city plants. Many are small or mid-size community systems that rely heavily on remote access tools and cheap internet-connected gear.
Sources told national outlets that possible cyber intrusions are now being investigated in at least a dozen states, as utilities work with federal agents to clean up and restore systems.
In Minnesota, more than 30 municipal water systems were struck in a short window of time, which pushed some facilities into manual mode and even temporarily shut down at least one treatment plant, according to detailed reporting on the campaign’s spread. This combination of scale, timing, and focus on control hardware suggests a coordinated effort, not random mischief.
What the hackers did and what they did not do
Attackers broke into operational technology devices, including the small industrial computers that run pumps, towers, and wastewater lift stations. According to the Federal Bureau of Investigation, they changed passwords and internet addresses tied to these systems, locking operators out and blinding them to what was happening in their plants.
In some cases, this led to degraded operations, including loss of pressure and localized flooding events, the bureau warned. That is why some utilities fell back to manual control and issued precautionary boil-water notices after pressure loss.
More than a dozen states have been targeted by cyberattacks on water systems as new evidence increasingly points to Iran. pic.twitter.com/qmw0SSOJUS
— Breaking911 (@Breaking911) August 6, 2026
Federal and state officials have been clear about one key point: they have seen no evidence that drinking water itself has been contaminated at any confirmed affected utility. Michigan authorities said all systems continued to operate safely and there were no known impacts that threatened public health, based on information from their environmental department.
A broad outcomes review of the 12-state campaign found no confirmed contamination at any utility as of early August, even where disruptions forced short-term shutdowns or manual workarounds. That distinction matters. The attacks poked at the steering wheel, not yet at the chemistry.
Iranian-linked threat warnings and a disputed culprit
Weeks before the Minnesota attacks, federal agencies issued an unusual joint advisory warning of an “urgent and ongoing” Iranian-affiliated cybersecurity threat against American drinking water and wastewater systems.
The Environmental Protection Agency, Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, and National Security Agency said Iranian-linked actors were exploiting internet-facing operational technology and sometimes causing disruption.
The Cybersecurity and Infrastructure Security Agency later warned that attacks on programmable logic controllers had already led to boil-water notices and sustained manual operations.
Multiple news outlets now report that intelligence officials and sources familiar with the probe see Iran or Iran-backed hackers as the prime suspect in the new wave of water system attacks. They point to familiar tradecraft and a history of Iranian Revolutionary Guard Corps-linked groups targeting the same kind of industrial control hardware in American utilities since at least 2023.
Cyber experts interviewed by major networks say the technical tactics and lack of ransom demands line up with past Iranian operations, even though the hacks themselves are relatively basic.
President Trump’s skepticism and the politics of attribution
President Trump has publicly said he does not think Iran is behind the Minnesota cyberattacks, despite what anonymous officials are telling reporters. In one exchange, he went further and alleged, without evidence, that Minnesota’s governor was “behind” the attacks, turning a serious infrastructure incident into a political fight.
This kind of public doubt without clear proof can be risky when federal security agencies are trying to rally utilities to take a foreign threat seriously.
At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say. pic.twitter.com/JF992IDAC6
— Dyonne (@kgpnet) August 6, 2026
On the other hand, the president’s caution highlights a real gap: federal agencies have not yet issued formal, public attribution to Iran for this specific 12-state campaign. Cyber attribution is complex and often slow.
The danger is that, while Washington debates labels, local operators are left exposed with outdated systems, thin staffing, and foreign actors already inside their control rooms.
Why this matters for everyday Americans
These attacks hit the most basic promise of modern life: clean, reliable water when you turn the tap. They also reveal how many small utilities rely on cheap remote access and unsecured internet connections to run critical gear.
Federal advisors have warned that Iran-linked hackers are targeting those weak spots nationwide, and this campaign is the broadest known strike on American municipal water infrastructure so far. For now, the water is safe. The next round, if utilities do not harden their systems, might not be.
Sources:
cbsnews.com, epa.gov, time.com, bloomberg.com, waterisac.org, insidecybersecurity.com, cisa.gov, reuters.com














