Iran-linked water cyberattacks spread to 12 US states: new report
State officials detected “hostile cyber activity” at multiple water facilities.

Aerial landscape of water tower in DeKalb County, Georgia. Image by Andrew Baum | Shutterstock
- Possible Iranian cyberattacks have now hit water and wastewater systems in at least 12 states.
- The FBI described the attacks as a coordinated seven-state campaign; three affected states remain unidentified.
- Minnesota saw the most serious disruptions, with attackers locking operators out and knocking at least one facility offline.
- Officials reported no public health risks, but experts warn attackers may be probing water systems for future access.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Michigan, Georgia, and New Jersey have now confirmed attacks on multiple public water systems -- as new reports surface Wednesday the Iranian-linked hacking campaign has spread to at least 12 states.
Last week, at least 30 municipal water and wastewater treatment systems were targeted in Minnesota, while South Dakota also reported attacks in Rapid City, the state’s second-largest city, located about a half hour’s drive from Mt. Rushmore.
The attacks caused multiple disruptions across the public water supply and forced staff in some facilities to use manual workarounds to continue operations until systems were restored.
Now, officials in Michigan, Georgia, and New Jersey have come forward, announcing that they, too, were targeted in what the FBI referred to last week as a coordinated 7-state hacking campaign.
The other states have yet to be identified by authorities.
Joseph Perry, cybersecurity researcher and advanced services lead at Arcova, warns the attackers may be seeking long-term access rather than immediate disruption.
"Threat actors are increasingly focusing on essential infrastructure providers as part of larger campaigns against groups of similar organizations rather than as isolated targets,”Perry says.
“Gaining access to operational environments can provide attackers with visibility into systems, reveal weaknesses, and create opportunities for future action,” he says.
Georgia, Michigan, New Jersey come forward
On Wednesday, New Jersey officials revealed that two municipal water systems were targeted in attacks similar to those currently under FBI investigation across the country.
According to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), the attacks caused automated systems to go down, temporarily limiting operators' ability to monitor or manage them remotely, one NJ resident reported on X.
“Both utilities shifted quickly to manual operations, and there was no disruption to service and customers had uninterrupted access to safe drinking water,” they said.
Officials said operators detected “hostile cyber activity” at multiple water facilities in both Georgia and Michigan over the weekend, also consistent with the July 26th-27th attacks in Minnesota, The Register reported on Monday.
Michigan authorities said there were no reports of operational disruptions or risks to public health, such as water contamination or threats to drinking water safety.
Nine Michigan water systems were involved in the alleged Iranian hacking spree, including Michigan’s Department of Environment, Great Lakes, and Energy (EGLE), The Register said.
"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," EGLE communications director Dale George told the outlet.
In Georgia, a local ABC News affiliate reported water systems operators were able to “identify the vulnerabilities rather quickly,” averting any major disruptions, although it's unclear how many facilities may have been targeted.
In the Minnesota water attacks, the attackers were able to infiltrate operational systems to change passwords and IP addresses – locking operators out of critical water equipment.
At least one municipal well and treatment plant were knocked offline.
FBI: report intrusions immediately
FBI Director Kash Patel on Tuesday urged state and local officials to be vigilant and report suspected cyber intrusions "the second they have even a small indication of a threat or intrusion” rather than attempting to handle them alone.
“We will bring in our entire cyber capabilities, deploy our cyber teams to the field, and make sure we patch up the intrusion,"Patel said.
Patel said the FBI is now operating in eight different states and described the situation as "managed really well,” reported Florida’s local CBS 12 News.
IRGC actors tied to attacks
Minnesota IT Services (MNIT), responding to the July breach, said “the timing, methods of access, and targeted infrastructure share characteristics with previous coordinated attacks against US critical infrastructure,” which also involve specific components of industrial control systems (ICS), called PLCs.
PLCs, or Programmable Logic Controllers, are internet-connected computers used to automate facility operations.
When tampered with, attackers can physically force system shutdowns, cause damage to equipment by altering pump speeds and shutting off valves, and corrupt the water treatment process.
Attackers can also spoof data, tricking operators with fake status readings.
Paul Bischoff, consumer privacy advocate at Comparitech, agrees that the campaign appears more consistent with state-backed activity than financially motivated cybercrime.
"I think the question a lot of people are asking now is whether these attacks are coming from a state-sponsored threat actor, e.g. Iran, or more typical profit-seeking cybercrimnals. Most experts seem to agree the attacks were linked to Iran at this stage.
Curious what others think about this story? Contribute your thoughts to the debate below.
"A cyberattack on a water treatment plant is nothing new. We see ransomware attacks on all levels of public infrastructure all of the time," Bischoff says. He also says these attacks often come from cybercriminal gangs looking for “low-hanging fruit – easily phished employees and known software vulnerabilities.”
“State-sponsored attacks tend to be more targeted and persistent. They can use more sophisticated techniques, stockpile vulnerabilities, and pay a lot of money for initial access,"Bischoff says.
CISA warns of critical infrastucture attacks
Barely a week before the attacks began, the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a joint advisory warning critical infrastructure operators to harden water and wastewater treatment systems against an imminent threat from Iranian-affiliated hackers.
Although the FBI has not named a specific threat actor, security insiders have linked the campaign to the CyberAvengers – a known hacktivist collective with ties to the Islamic Revolutionary Guard Corps (IRGC).
The group has successfully breached other US water and wastewater facilities in the past.
To reduce the risk of compromise, the FBI is urging operators to "disconnect PLCs from direct internet exposure, set up strong, unique passwords, and use an access control list (ACL) to allow only authorized communication between control system devices."
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Perry also says that for smaller and rural service providers, these attacks reinforce the need for greater cybersecurity collaboration.
He says organizations should explore focused partnerships and communities that allow them to share best practices, improve access to resources, and address common challenges together.
“Similar to the benefits provided by larger information-sharing groups, smaller and more specialized communities can help organizations strengthen their collective resilience against evolving threats,” Perry says.
Has your password leaked?