Alleged Iranian Hackers Target U.S. Water Systems Across Seven States


In early August, the state of Minnesota reported a coordinated cyber‑attack on more than 30 state‑run water systems, sparking a federal investigation that soon expanded to six additional U.S. states. The FBI warned that the intrusions have degraded water operations and raised concerns over national security.


Is Iran Behind the Attacks?


Morgan Wright, a former U.S. state‑department anti‑terror adviser, indicated that breaches of this nature are often attributed to North Korea or Iran. He suggested that Iran, currently at odds with the United States, could be targeting critical infrastructure to gain leverage.


Jake Braun, a former acting White House Deputy National Cyber Director, notes that the Trump administration may be reluctant to admit Iranian involvement. Nevertheless, the timing and scope of the attacks align with other known Iranian cyber operations.


Historical Pattern of Iranian Cyber Activity


Experts point to a documented history of Iranian hacking groups operating from abroad. The Justice Department has linked the group “Handala” to attacks on U.S. water and wastewater facilities in 2023 and 2024, and on medical technology firms in 2026. Other incidents include:



  • 2026: Handala reportedly breached a medical technologies firm, releasing sensitive data about Israeli officials.

  • 2024: Three Iranian cyber actors were indicted for a hack‑and‑leak operation targeting U.S. presidential campaigns.

  • 2023: U.S. water and wastewater systems were targeted by groups affiliated with the Islamic Revolutionary Guard Corps.

  • 2020: Two Iranian nationals were charged with a disinformation campaign aimed at influencing the U.S. election.

  • 2017: Ransomware attacks on local governments and health institutions linked to Iranian‑backed groups, though not officially sanctioned by the Iranian government.


Potential Threat to Water Supplies


While the immediate risk is to public trust in water services, experts stress that malicious actors could eventually execute attacks that compromise water safety—such as injecting chemicals, shutting off supplies, or damaging equipment.


The U.S. manages over 152,000 public drinking water systems and 16,000 wastewater facilities, making the sector a prime target for adversaries aiming to undermine infrastructure and erode confidence.


Preventing Future Attacks


Many water and wastewater devices remain vulnerable due to outdated technology. CISA recommends immediate isolation of systems from the internet, regular password resets, and upgrading security controls across all utilities. The agency has published a series of advisories urging U.S. governments to implement these measures to safeguard critical water infrastructure.


Shayan Sardarizadeh with BBC Verify contributed to this report.