More than 30 U.S. water utilities across seven states were hit by coordinated cyberattacks linked to suspected Iranian hackers, prompting FBI, EPA and CISA investigations into critical infrastructure security.
WEBDESK – ABDULLAH FARHAD – SHARJAH NEWS
Coordinated Attacks Strike Critical Infrastructure
A coordinated wave of cyberattacks has targeted more than 30 water and wastewater utilities across at least seven U.S. states, making it one of the most significant cyber incidents to affect America’s critical infrastructure in recent years. The attacks disrupted operational technology used by municipal water systems and triggered investigations by the FBI, the Environmental Protection Agency (EPA), and the Cybersecurity and Infrastructure Security Agency (CISA).
Authorities confirmed that the attacks primarily affected industrial control systems responsible for monitoring and operating water treatment facilities. While officials emphasized that drinking water quality remained safe, some utilities experienced operational disruptions, forcing staff to switch to manual control systems and, in certain locations, issue precautionary water-use advisories.
Minnesota Becomes the Primary Target
Minnesota was the hardest-hit state, where officials reported coordinated attacks on more than 30 community water systems between July 26 and July 27. Cities including Braham, Plymouth and South St. Paul experienced temporary disruptions after hackers gained unauthorized access to digital control systems.
In Braham, the attack briefly disabled the operating controls for the city’s well and water treatment plant. Although backup systems continued supplying water from storage tanks, residents were temporarily asked to limit water usage until engineers restored normal operations. No evidence suggested that the water itself was contaminated.
Investigators Suspect Iranian-Affiliated Hackers
Federal investigators believe the attacks resemble previous cyber operations attributed to Iranian-affiliated hacking groups. According to a leaked WaterISAC memo obtained by WIRED, technical indicators and attack methods closely match earlier campaigns targeting programmable logic controllers (PLCs) used in industrial facilities.
However, officials have not yet made a formal public attribution assigning responsibility to Iran. The FBI says the investigation is continuing, while CISA has noted that the tactics are consistent with previous Iranian-linked cyber activity against critical infrastructure.
Political Disagreement Emerges
The incident also sparked political controversy.
President Donald Trump publicly stated that he did not believe Iran was responsible, instead criticizing Minnesota officials and suggesting the problems resulted from poor local cybersecurity practices.
Minnesota Governor Tim Walz rejected that claim, saying state and federal investigators were examining evidence pointing toward foreign-linked cyber activity. Cybersecurity experts also cautioned against drawing conclusions before the investigation is complete, although many noted that the attack methods resemble previous Iranian operations.
Why Water Utilities Are Increasingly Vulnerable
Cybersecurity experts say water utilities have become attractive targets because many rely on aging infrastructure, outdated software and internet-connected industrial equipment with limited security protections. Smaller municipal systems often lack dedicated cybersecurity teams, making them easier for attackers to compromise.
Federal agencies have repeatedly warned that hostile foreign actors including groups linked to Iran, China and Russia have increasingly targeted critical infrastructure such as water treatment plants, energy grids and transportation systems.
Federal Response and Security Measures
Following the attacks, the FBI, EPA and CISA urged water utilities nationwide to immediately strengthen cybersecurity defenses. Recommended measures include disconnecting critical control systems from the public internet where possible, implementing multi-factor authentication, updating software, changing compromised passwords and ensuring facilities can continue operating manually if digital systems are disrupted.
Officials stressed that no widespread contamination of drinking water has been reported, but warned that the attacks demonstrate the growing cybersecurity risks facing essential public infrastructure
