Federal authorities are investigating cyberattacks on water treatment facilities across at least 12 states, with evidence pointing to Iranian state-sponsored hackers who gained control of critical infrastructure systems including pumps, valves, and water pressure controls.
Widespread Infrastructure Breach
The attacks have impacted water systems in Michigan, Minnesota, Georgia, New Jersey, and South Dakota, among other states. Minnesota alone saw more than 30 community water systems targeted in the coordinated campaign. In Clayton County, Georgia, hackers caused a pressure drop affecting 300,000 customers near Atlanta, forcing officials to issue a boil water advisory last month before service was restored within hours.
Multiple utilities lost remote-control capabilities, forcing operators to abandon automated systems and switch to manual operations. Despite the security breaches, federal officials confirmed that drinking water quality remained safe throughout all incidents, with no contamination or public health threats detected. The attacks focused on control systems rather than water treatment processes themselves.
Federal Warning Issued
On July 30, the FBI, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency issued a joint warning about cyber threat actors who remotely accessed online infrastructure for water and wastewater systems in at least seven states. The agencies reported a loss of monitoring and control functionality at affected facilities. Water agencies nationwide received advisories to disconnect operating programs from internet access and strengthen password protections and firewall defenses immediately.
Link to Iranian Revolutionary Guard
The cyberattack tactics mirror a 2023 campaign conducted by the CyberAv3ngers, a hacking group linked to Iran’s Revolutionary Guard. That operation exploited water system controllers using default passwords that facility operators had failed to change. Security experts note the current attacks demonstrate increased sophistication, with hackers penetrating systems protected by standard security measures. The targeting of American water infrastructure represents a direct threat to civilian safety and national security.
What This Means
The attacks expose dangerous vulnerabilities in critical infrastructure that millions of Americans depend on daily. While no contamination occurred, the hackers proved they could manipulate water pressure and disable remote monitoring systems. Federal agencies are working with state and local utilities to implement stronger cybersecurity protocols. The incidents highlight how foreign adversaries continue probing weaknesses in essential services, raising urgent questions about infrastructure protection and the need for mandatory security standards across all public utility systems nationwide.
