Thursday, August 27, 2026
Tech Beat
Aug 14, 2026, 7:04 PMCybersecurity

Iran Suspected in US Water Utility Cyberattacks Across at Least Seven States

Alleged Iranian hackers hit US water utilities across at least seven states, disrupting pressure as investigators examine possible IRGC responsibility.

A water glass shaped like the United States fractures into pixels under a red shadow, symbolizing suspected cyberattacks.
Listen to this briefingAudio briefing

Summary

Late July cyberattacks hit water utilities across around a dozen states. Minnesota said on July 28, 2026, that plants serving more than 30 communities were hit; on July 30, the FBI said utilities in at least seven states reported incidents, sometimes degrading operations. Cases were reported in Minnesota, Arkansas, Georgia, New Jersey, and Michigan. The US has more than 150,000 water systems, some locally run with limited cybersecurity resources, making coordinated compromises notable and potentially escalating Iran’s previous opportunistic attacks on easy targets.

As of August 14, the US government had not publicly attributed the campaign. CISA’s April warning about Iranian targeting of internet connected water and energy devices was updated days before Minnesota’s incidents; WaterISAC later said the attacks aligned with that campaign. The Washington Post said US intelligence agencies were confident Iran’s Islamic Revolutionary Guard Corps was responsible, but attribution remained private because the unit was unknown and officials might avoid contradicting President Donald Trump, who denied an Iranian attack and blamed Minnesota, led by Democratic Governor Tim Walz, Kamala Harris’ 2024 running mate. Iran could be retaliating for the six-month war. Iranian operations previously had limited success: in March, Handala disrupted Stryker and claimed it hacked FBI Director Kash Patel’s personal Gmail; the US government later said Iran’s Ministry of Intelligence and Security operated Handala.

Forescout found more than 2,800 internet exposed controllers in US water systems in August, though exposure does not ensure control. The FBI reported pressure loss that could admit untreated groundwater into pipes, plus flooding. Braham, Minnesota, took its plant offline for several hours and asked about 1,700 residents to conserve; Maple Plain briefly declared an emergency; and officials outside Atlanta, Georgia, briefly advised boiling water. Broad coverage amplified fear over water safety, potentially serving the attackers’ goal of spreading panic.

Positives

  • CISA updated its April warning about Iranian targeting of water and energy devices before the Minnesota incidents.
  • Braham’s water plant remained offline for only several hours while about 1,700 residents were asked to conserve water.
  • Maple Plain’s state of emergency and the Atlanta area boil water advice were both brief.
  • Forescout stressed that an internet exposed controller does not automatically give attackers operational control.
  • WaterISAC distributed its assessment linking the incidents with the campaign identified by CISA.

Risks & concerns

  • More than 30 Minnesota communities reported coordinated attacks, while the FBI received incident reports from utilities in at least seven states.
  • More than 2,800 controllers in US water systems were exposed online, according to Forescout.
  • Some attacks caused pressure loss, possible untreated groundwater intrusion, flooding, plant shutdowns, and precautionary boil water advice.
  • The US government had not publicly identified the culprit despite reported intelligence confidence that Iran’s IRGC was responsible.
  • More than 150,000 US water systems create a fragmented target base, with some local operators lacking adequate cybersecurity resources.
  • National and local coverage heightened public fear about water safety, potentially advancing the attackers’ goal of spreading panic.
Primary sourceTechCrunchhttps://techcrunch.com/2026/08/14/what-we-know-about-the-alleged-iranian-hacks-on-u-s-water-utilities/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate