Since the end of last month, several water utilities in the United States have been hit by cyberattacks, causing alarm in the country. 

For years, water utilities and other critical infrastructure facilities in the power sector, for example, have been targeted by hackers, whether government-backed or individuals. What makes this recent series of attacks—allegedly carried out by Iran—particularly concerning was how widespread they have been, hitting targets in around a dozen states. 

The U.S. has more than 150,000 water systems, some of them run by local companies. In theory, that should make it harder for hackers to target several facilities at the same time. But on the flip side, the companies running these systems may not have the resources or cybersecurity expertise needed to protect themselves. 

Cybersecurity experts have long believed that Iranian hackers target low-hanging fruit in opportunistic isolated attacks, so this hacking campaign could be a significant escalation. 

A lot has happened since news of the initial attacks broke two weeks ago. So we decided it was a good time to recap what we know so far, and what we don’t. 

On July 28, Minnesota authorities announced that water treatment plants in more than 30 communities were hit by coordinated cyberattacks. 

Two days later, the FBI said water and wastewater utility companies in “at least seven states” reported incidents, and in some cases the attacks “degraded water operations.” Since then, apart from Minnesota, there have been reported hacks against water facilities in Arkansas, Georgia, New Jersey, and Michigan

The short answer is: we don’t know yet, but the number one suspect is the Iranian government. 

As of today, officially, the U.S. government has yet to name the culprit behind the coordinated wave of hacks.

However, the first incidents in Minnesota came days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without saying where those attacks were occurring. (CISA had originally published this warning in April, and updated it before the Minnesota attacks.) 

After the initial wave was uncovered in Minnesota, President Donald Trump said he did not think “there was an Iranian cyberattack.” Instead, he blamed the state, perhaps because it is run by democratic governor Tim Walz, who was chosen as Kamala Harris’s vice president in the 2024 elections.

Trump’s claim came a day after Wired reported that the Water Information Sharing and Analysis Center, or WaterISAC, a nonprofit group that distributes cybersecurity information among the water sector, told its members that the recent attacks “aligned” with the hacking campaign CISA warned of—effectively accusing the Iranian government.  

Earlier this week, The Washington Post reported that U.S. intelligence agencies “are confident” that Iran, and in particular the Islamic Revolutionary Guard Corps (IRGC), is responsible. The attribution isn’t public yet, according to the paper’s sources, because the agencies are not sure which specific unit within the IRGC was responsible, and also because officials may be reluctant to contradict Trump’s claim.

Iranian government hackers have a history of targeting critical infrastructure in the U.S., and it’s possible that these attacks are part of its strategy to retaliate against the country because of the six-month-long war. 

Until now, Iranian hackers had had only limited success in their cyberattacks against U.S. targets. In March, a hacktivist group called Handala disrupted the operations of medical tech giant Stryker. The U.S. government later accused Handala of being operated by Iran’s Ministry of Intelligence and Security (MOIS). Then, the group claimed responsibility for hacking the personal Gmail account of FBI director Kash Patel.

The reality is that some systems inside critical infrastructure facilities are exposed to the internet and relatively easy to find. Earlier this month, cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems exposed online. If a system is exposed, it doesn’t automatically mean hackers can take over control and cause real-world effects. But that has happened in some isolated cases in recent attacks.

The FBI said some of the cyberattacks around the country caused loss of pressure, which “could potentially allow untreated groundwater to seep into pipes,” and flooding. 

The town of Braham in Minnesota, one of the first ones to report an incident, had to take its water plant offline for a few hours, urging its around 1,700 residents to conserve water. The city of Maple Plain, also in Minnesota, briefly declared a state of emergency. In a county outside Atlanta, Georgia, local officials briefly told residents to boil water before using it as a precautionary measure.  

The worst effect, however, may be psychological. These attacks have been widely covered in national and local press, causing people to worry about the safety of a fundamental and basic need like water. That may very well be part of the hackers’ goals: to spread panic and fear.

Leave a Reply

Your email address will not be published. Required fields are marked *