
WATER ATTACK: Suspected Iranian Cyber Offensive Targets Water Systems Across Multiple U.S. States
Federal authorities are investigating a coordinated cyber campaign aimed at water utilities in at least seven states, with Iran emerging as the leading suspect behind the attacks, according to a report by The New York Times.
While officials say there has been no interruption to public drinking water supplies, the incidents have prompted heightened concern within the U.S. government over attempts to penetrate systems that regulate water quality and chemical treatment.
The investigation began after officials in Minnesota detected a cyber intrusion affecting local water infrastructure. Similar incidents were later reported in other states, including Michigan, expanding the scope of the federal probe. According to The New York Times, the FBI and the Environmental Protection Agency have confirmed that suspicious activity has been identified in at least seven states, although no contamination or disruption of drinking water has been reported.
According to U.S. officials, investigators currently view Iran as the primary suspect. However, they cautioned that the investigation remains in its early stages and that no definitive evidence has yet been uncovered to formally attribute the attacks to Tehran.
The reported cyber campaign has drawn comparisons to Iran’s attempted cyberattack against Israel’s water infrastructure in 2020. In that incident, hackers allegedly sought to manipulate chlorine levels in drinking water by infiltrating the computerized control systems of water pumps. Israeli authorities successfully thwarted the attack before any major damage occurred.
Investigators believe the attackers in the latest incidents attempted to gain control over systems responsible for monitoring water quality and regulating chemical dosing. Officials also suspect they may have tried to activate emergency procedures at multiple facilities. In response, the Cybersecurity and Infrastructure Security Agency has urged water utilities nationwide to disconnect sensitive operational control systems from the internet whenever possible to reduce the risk of future attacks.
President Donald Trump, however, questioned whether Iran was actually responsible and downplayed the cyber incidents. Despite his comments, federal officials involved in the investigation continue to regard Iran as the leading suspect, while acknowledging that determining responsibility could take months.
Cybersecurity experts warned that the attacks represent a troubling shift in strategy. Unlike many previous cyber operations that focused primarily on espionage or disrupting computer networks, this campaign appears to have directly targeted critical infrastructure that millions of Americans rely on every day.