Since late July, cyberattacks have struck water utilities across roughly a dozen U.S. states, alarming officials and residents with a coordinated wave of intrusions that mark a potential escalation in threats against critical infrastructure. A TechCrunch report published August 14 recaps the incidents, noting that while water systems and power facilities have faced hacking attempts for years, the breadth of these recent attacks stands out. The country operates more than 150,000 water systems, many managed by local companies that may lack the budget or technical know-how to defend themselves effectively.

Minnesota authorities disclosed on July 28 that treatment plants in over 30 communities had been targeted in synchronized cyberattacks. Two days afterward, the FBI revealed that water and wastewater companies in at least seven states had reported incidents, with some attacks degrading operations. Since then, hacks have been documented in Arkansas, Georgia, New Jersey, and Michigan, in addition to Minnesota. In Braham, Minnesota—a town of roughly 1,700 people—operators shut down the water plant for several hours and asked residents to limit usage. Maple Plain, also in Minnesota, briefly declared a state of emergency, while a county near Atlanta told people to boil water as a precaution.

The U.S. government hasn't officially named a culprit, but intelligence agencies are confident Iran—specifically the Islamic Revolutionary Guard Corps—is responsible, The Washington Post reported earlier this week. Attribution remains unpublicized partly because agencies haven't pinpointed which IRGC unit carried out the campaign, and also because officials may hesitate to contradict President Trump's claim that he didn't believe Iran was behind the breaches. The nonprofit Water Information Sharing and Analysis Center told members the attacks aligned with a hacking campaign the U.S. Cybersecurity and Infrastructure Security Agency had warned about in an advisory originally issued in April and updated before the Minnesota incidents. Iranian government hackers have previously gone after U.S. critical infrastructure, and these strikes could be retaliation for the six-month war.

Cybersecurity firm Forescout found more than 2,800 controllers in American water systems exposed online earlier this month, illustrating how vulnerable some facilities remain. Even when systems are accessible, hackers don't always seize control and trigger real-world damage—but they did in isolated cases during this campaign. The FBI said certain attacks caused pressure loss that could let untreated groundwater leak into pipes, as well as flooding. The report notes that the worst impact may be psychological: widespread national and local media coverage has fueled anxiety about the safety of something as fundamental as drinking water, potentially fulfilling the hackers' goal of sowing panic and fear. Cybersecurity experts have long viewed Iranian hackers as targeting easy opportunities in one-off attacks, so a coordinated strike across multiple states would signal a notable shift in strategy. For business leaders and infrastructure operators, the campaign underscores that adversaries are willing to exploit dispersed, under-resourced targets simultaneously rather than focusing firepower on a single high-value asset—a reminder that defense can't rely solely on hardening the crown jewels when the perimeter is porous everywhere else.