What we know about the alleged Iranian hacks on US water utilities
Since the end of last month, several water utilities in the United States have been hit by cyberattacks, causing alarm in the country.
For years, water utilities and other critical infrastructure facilities in the power sector , for example, have been targeted by hackers, whether government-backed or individuals. What makes this recent series of attacks—allegedly carried out by Iran—particularly concerning was how widespread they have been, hitting targets in around a dozen states.
The U.S. has more than 150,000 water systems , some of them run by local companies. In theory, that should make it harder for hackers to target several facilities at the same time. But on the flip side, the companies running these systems may not have the resources or cybersecurity expertise needed to protect themselves.
Cybersecurity experts have long believed that Iranian hackers target low-hanging fruit in opportunistic isolated attacks, so this hacking campaign could be a significant escalation.
A lot has happened since news of the initial attacks broke two weeks ago. So we decided it was a good time to recap what we know so far, and what we don’t.
On July 28, Minnesota authorities announced that water treatment plants in more than 30 communities were hit by coordinated cyberattacks.
Two days later, the FBI said water and wastewater utility companies in “at least seven states” reported incidents, and in some cases the attacks “degraded water operations.” Since then, apart from Minnesota, there have been reported hacks against water facilities in Arkansas , Georgia , New Jersey , and Michigan .
The short answer is: we don’t know yet, but the number one suspect is the Iranian government.
As of today, officially, the U.S. government has yet to name the culprit behind the coordinated wave of hacks.
However, the first incidents in Minnesota came days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without saying where those attacks were occurring. (CISA had originally published this warning in April, and updated it before the Minnesota attacks.)
After the initial wave was uncovered in Minnesota, President Donald Trump said he did not think “there was an Iranian cyberattack.” Instead, he blamed the state , perhaps because it is run by democratic governor Tim Walz, who was chosen as Kamala Harris’s vice president in the 2024 elections.
Trump’s claim came a day after Wired reported that the Water Information Sharing and Analysis Center, or WaterISAC, a nonprofit group that distributes cybersecurity information among the water sector, told its members that the recent attacks “aligned” with the hacking campaign CISA warned of—effectively accusing the Iranian government.
Earlier this week, The Washington Post reported that U.S. intelligence agencies “are confident” that Iran, and in particular the Islamic Revolutionary Guard Corps (IRGC), is responsible.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcrunch.com — the content belongs to TechCrunch.