Thursday, August 13, 2026

Water-Supply Hacks Widen Across U.S. as Iran Evidence Grows

Valyrian News Network 6 min read

Water-Supply Hacks Widen Across U.S. as Iran Evidence Grows

The scope of cyberattacks on U.S. water systems has grown to include at least seven states and may be far wider, according to The New York Times, which reported Saturday that investigators increasingly believe the assault is the work of Iran. The disclosure landed as federal authorities raced to safeguard the nation’s water supply and urged utilities to remove vulnerable industrial controls from the internet.

Context

Water systems have long been a target of Iranian cyber operations, but the current campaign is notable for its breadth. More than 30 community water systems in Minnesota were hit in a coordinated attack between July 26 and July 27, according to Minnesota IT Services, with four cities—Plymouth, South St. Paul, Maple Plain, and Braham—publicly disclosing breaches. By August 1, Michigan had joined Minnesota in reporting intrusions, with officials saying nine Michigan water systems were affected. The FBI and Environmental Protection Agency warned in a joint public service announcement that, since July 27, utilities in at least seven states had reported incidents, some of which degraded water operations.

Attackers targeted Operational Technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) in the MicroLogix 1100 and 1400 series, according to the FBI-EPA advisory. After remotely accessing internet-facing devices, the actors changed IP addresses and passwords, causing a loss of monitoring and control functionality. In Plymouth, a city of about 80,000, compromised PLCs were found at two water towers and 14 sewer lift stations; officials disconnected the devices from the cellular network and restored communications by Tuesday afternoon. In Braham, a town of roughly 1,700, attackers shut down operating controls for the well and water treatment plant, causing an outage even though water quality was not affected. South St. Paul moved to manual operations early Monday with no interruption to service. John Israel, Minnesota IT Services assistant commissioner and chief information security officer, said the response “worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services.”

Water tower in Plymouth, Minnesota, on July 30, 2026, after cyberattacks targeted more than 30 water systems in the state.

Attribution and Politics

Officials have not officially attributed the attacks. The FBI, EPA and Cybersecurity and Infrastructure Security Agency (CISA) have stopped short of blaming Iran, and Minnesota and federal authorities have not publicly confirmed the culprit. U.S. officials told The New York Times that Iran is the chief suspect, while investigators also examine whether the attacker may have tried to appear Iran-based in a possible false-flag operation.

The question of responsibility has become politically charged. At a Cabinet meeting at Camp David on July 31, President Donald Trump said he believed Minnesota, not Iran, was behind the attacks. “I think that Minnesota is behind it… Because they’re grossly incompetent. I think the governor’s behind it,” Trump said, according to CBS News. He added, “Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

Minnesota Gov. Tim Walz responded on social media, saying the president “knows exactly who is responsible for this attack, and knows that other states were hit too.” Walz argued the administration had left the country exposed, accusing Trump of taking “an axe” to CISA, and said the episode illustrates that the White House has “no plan to win a war with Iran.”

On August 1, the FBI said it was “fully engaged to protect critical infrastructure” and remained “well-equipped to protect against cyber threats of all varieties.”

President Donald Trump speaks during a Cabinet meeting at Camp David, Maryland, July 31, 2026.

Analysis

The widening scope highlights a persistent vulnerability in America’s water sector. Municipal utilities often lack the funding and technical staff to patch or secure operational technology, and many industrial control devices were designed for reliability rather than security. CISA said it is “currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities” and urged operators to remove publicly exposed PLCs and other OT from the internet. Nick Anderson, CISA’s acting director, said: “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.” The agency also warned that even mature organizations should validate external connections, including undocumented cellular modems.

The pattern also fits Iran’s broader approach during the current conflict. With limited conventional military options, Tehran has repeatedly turned to digital operations to pressure Washington, according to reporting by The Verge and The Times of Israel. Iranian-linked actors have previously targeted U.S. banks, a New York dam, and—most notably—water utilities. In 2023, a group affiliated with Iran’s Islamic Revolutionary Guard Corps, known as CyberAv3ngers, exploited internet-connected PLCs that used default or no passwords, at one point shutting down a pump in Aliquippa, Pennsylvania.

What’s Next

At this point, the number of affected communities could still grow. The FBI and EPA have said incidents were reported in at least seven states, and The New York Times reported the true scope may be far wider. No drinking water quality compromise has been reported, and state health officials have not asked residents to change how they use water, but the disruption to critical services has already forced utilities across the country to review their defenses.

The immediate question is attribution. A formal determination by the FBI could take weeks, and the possibility of a false-flag operation complicates the picture. Michigan officials, meanwhile, sought to reassure the public. “All systems continued to operate safely,” said Dale George, communications director for the Michigan Department of Environment, Great Lakes, and Energy. “Issues were addressed by local operators, and there are no known impacts that posed a public health concern.”

Utilities, regulators and elected officials will be watching for three things in the coming weeks: whether more states disclose intrusions, whether Iran is formally blamed, and whether the episode leads to binding cybersecurity rules for the water sector, a subject that remains politically contested. For now, the episode is a reminder that critical infrastructure depends on equipment that many municipalities cannot easily defend—and that the consequences of a failure can ripple far beyond a single water tower.