Iran-linked cyberattacks on US water systems
Analysis based on 210 articles · First reported Jul 28, 2026 · Last updated Aug 11, 2026
The cyberattacks heightened concerns about the vulnerability of U.S. critical infrastructure, potentially increasing demand for cybersecurity solutions and services for water utilities. Publicly traded companies in the cybersecurity and industrial control sectors may see positive sentiment, while water utilities and related infrastructure operators face increased scrutiny and potential regulatory pressure.
A coordinated series of cyberattacks targeted municipal water and wastewater systems across at least seven U.S. states, including more than 30 community water systems in United States — Minnesota, over a 48-hour period in late July 2026. The attacks exploited internet-exposed programmable logic controllers (PLCs) and other operational technology, often using default or weak credentials, to disrupt monitoring and control functions. Some utilities were forced to switch to manual operations, and at least one city issued a temporary boil-water advisory. No water supplies were reported contaminated or unsafe, and no public health impacts were confirmed. U.S. officials, including the FBI and CISA, investigated the incidents and privately assessed that Iranian hackers were the likely perpetrators, though formal attribution was pending. The attacks occurred amid heightened U.S.-Iran tensions and ongoing military conflict. President Donald Trump publicly disputed the Iran link, blaming United States — Minnesota's state government and Governor Tim Walz for incompetence, while Walz criticized Trump's response. Federal agencies issued urgent advisories urging utilities to disconnect exposed operational technology from the internet and strengthen security.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard