Cyberattacks hit water systems in seven US states; Iran suspected
In brief
- Cyberattacks targeted water utilities in seven states July 28–31, 2026; Minnesota hit hardest with 30+ systems affected
- Facilities abandoned digital controls and switched to manual operations during disruptions
- FBI and EPA issued joint advisory; investigators exploring Iranian-backed actor links
- No ransom demands made, suggesting disruption rather than financial motive
Scope and Initial Response
Minnesota experienced the most severe impact, with disruptions affecting more than 30 municipal water systems. Federal agencies have not publicly specified which states beyond Minnesota were affected, though the coordinated four-day window across multiple jurisdictions suggests a sophisticated operation. Affected utilities reported significant degradation in system performance, requiring personnel to physically take over automated processes.
The speed and scale of the campaign point to careful preparation. The four-day timeframe across seven states suggests attackers had pre-positioned access before the visible disruption began, meaning adversaries likely had footholds in these networks well before the attacks became visible.
Attribution and Motive
Federal investigators are exploring links to Iranian-backed hackers, citing identifiable tradecraft patterns consistent with prior operations. Attribution has not been formally confirmed, and investigators say evidence collection is ongoing. Prior incidents tied to Iranian actors targeted water facilities in Pennsylvania and Texas, including a facility in Aliquippa, Pennsylvania.
What distinguishes this campaign is the absence of financial demands. No ransom demands were made in connection with the attacks, which investigators flagged as unusual. The pattern suggests disruption itself is the goal, not extortion. Critical infrastructure attacks without a ransom note indicate a different calculus—one centered on operational disruption or intelligence gathering rather than quick financial gain.
Federal and state water utilities are now reassessing their network architecture and access controls. The incident underscores how vulnerable essential services remain, even when federal agencies have known about the threat for years.


