As US-Iran Tensions Rise, Cyberattacks Target America's Water Infrastructure
Federal agencies are investigating coordinated cyberattacks on water utilities across at least seven states as investigators examine possible Iranian links
As military tensions between the United States and Iran continue to escalate, U.S. officials are racing to contain what cybersecurity experts describe as one of the most significant coordinated cyber campaigns against American water infrastructure in years. While Washington has stopped short of publicly attributing the attacks, multiple media reports citing U.S. officials say investigators increasingly suspect Iranian-linked hackers are behind the intrusions.
The cyber campaign highlights a growing reality of modern conflict: alongside missiles, drones and air strikes, critical civilian infrastructure has become an increasingly attractive battlefield.
The FBI and the U.S. Environmental Protection Agency (EPA) this week issued an unusual joint public warning after water and wastewater utilities in at least seven states reported cyber incidents since July 27. According to the agencies, some of the attacks disrupted water operations by targeting internet-connected industrial control devices used to monitor and operate treatment facilities.
The advisory follows a coordinated wave of attacks against more than 30 municipal water systems in Minnesota. Although officials say there is no evidence that drinking water was contaminated, some facilities temporarily lost remote monitoring and control capabilities, forcing operators to switch to manual operations while systems were restored.
According to Reuters, U.S. officials reviewing the incidents believe Iranian-linked hackers are the most likely culprits, although no formal public attribution has been made. The report noted that the attacks occurred as military hostilities between Washington and Tehran intensified, with both countries exchanging missile strikes and threats of further escalation. Reuters also reported that Iranian government representatives did not immediately respond to requests for comment.
CNN similarly reported that Iran remains one of the leading suspects but emphasized that investigators are proceeding cautiously and remain mindful of the possibility of false-flag operations designed to obscure the attackers' identity.
Rather than relying on sophisticated malware, the attackers exploited a far more basic weakness: internet-exposed programmable logic controllers (PLCs), industrial computers that regulate essential physical processes such as water pressure, pumping systems and chemical dosing.
According to the FBI, the attackers remotely accessed vulnerable PLCs manufactured by Rockwell Automation, specifically the MicroLogix 1100 and 1400 series. After gaining access, they changed device passwords and IP addresses, preventing operators from monitoring or controlling the equipment remotely. In some cases, investigators also identified unauthorized modifications to PLC programming files.
The operational impact varied depending on each facility's configuration. The FBI said reported consequences included flooding and pressure loss, which can potentially allow untreated groundwater to enter drinking water systems. Facilities that could quickly switch to manual operations generally limited the damage, while more automated sites faced greater disruption.
According to CNN, the campaign demonstrates that attackers are systematically scanning the internet for exposed industrial devices rather than targeting specific utilities. John Israel, Minnesota's chief information security officer, warned that threat actors would continue "rattling doorknobs" across the country's infrastructure, looking for systems with weak security configurations.
Cybersecurity specialists say the incidents also fit a broader pattern of Iranian cyber activity targeting operational technology. Reuters cited former senior FBI cybersecurity official Cynthia Kaiser, who said the campaign is highly consistent with previous Iranian-affiliated efforts against industrial control systems documented by CISA, the FBI and the National Security Agency. Another expert, Chris Day of Tenable, described the apparent ability to temporarily take systems offline as a notable escalation compared with earlier campaigns.
CNN quoted industrial cybersecurity expert Gus Serino as calling the scale and coordination of the attacks "unprecedented" for the U.S. water sector, while Joshua Corman, co-founder of the cybersecurity initiative I Am The Cavalry, warned that the growing reliance on internet-connected industrial systems has dramatically expanded the attack surface for critical infrastructure.
Not everyone in Washington agrees with the emerging assessment. Speaking at Camp David, President Donald Trump dismissed suggestions that Iran was responsible, arguing instead that the democratic Minnesota officials were to blame for poor cybersecurity. "I don't think so," Trump said when asked about Iranian involvement, according to Reuters. "I blame Minnesota because they're grossly incompetent."
For federal agencies, however, the immediate priority is mitigation rather than attribution. The FBI and EPA urged operators to remove PLCs from direct internet exposure, secure remote-access connections through gateways and firewalls, implement strong authentication, review system logs for suspicious activity, restrict communications to authorized devices, and prepare to operate facilities manually if automated systems are compromised. The agencies also recommended accelerating replacement of unsupported end-of-life equipment, which is frequently targeted because it no longer receives security updates.
Whether or not Iran is ultimately identified as the actor behind the campaign, the incidents underscore how cyber operations have become an increasingly important component of geopolitical confrontation. As tensions between Washington and Tehran continue to unfold, the battle is no longer confined to military installations or government networks. America's water infrastructure has become the latest reminder that in modern conflict, essential civilian services are now firmly on the front line.