Iran-linked cyberattacks on US water systems
Analysis based on 6 articles · First reported Aug 01, 2026 · Last updated Aug 02, 2026
The cyberattacks heighten concerns over critical infrastructure vulnerabilities, potentially increasing cybersecurity spending and insurance costs for water utilities. While no water contamination occurred, the incidents may affect investor sentiment in the water utility sector and raise geopolitical tensions.
Cyberattacks targeting US water systems have expanded to at least seven states, including United States — Minnesota and United States — Michigan, causing operational disruptions such as boil-water notices and manual operations. Federal investigators, led by the FBI and EPA, are examining whether Iranian state-backed hackers are responsible, viewing Iran as the leading suspect, though the investigation remains preliminary with no definitive forensic evidence. The attackers targeted programmable logic controllers (PLCs) and changed passwords, but officials confirm no drinking water contamination or unsafe supply. President Donald Trump publicly dismissed the Iran link, attributing the incidents to United States — Minnesota state government incompetence, drawing criticism from Governor Tim Walz. The United States — Cybersecurity and Infrastructure Security Agency has urged utilities to disconnect operational systems from the internet. The campaign draws comparisons to Iran's 2020 attempted cyberattack on Israel's water infrastructure.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard