Cyberattacks Hit U.S. Water Plants Across Several States
A wave of coordinated cyberattacks disrupted water systems in Minnesota, Georgia, New Jersey and Michigan, with officials suspecting Iran-linked hackers.

A coordinated cyberattack disrupted water treatment systems in at least seven states in late July, prompting emergency responses from small-town operators to federal cybersecurity officials, who suspect Iran may be behind the intrusion.
In Braham, Minnesota, a town of about 1,700 residents, a water operator discovered on a Monday morning that the plant's pump had stopped working. Crews took the plant offline and residents were told to conserve water while the city drew on a backup tank supply. Workers restored flow within a couple of hours by taking manual control of the pump.
"It's not Braham in particular that's being targeted. It's the internet access points and the vulnerable technology," said Mayor Nate George, a U.S. Air Force reservist.
Between July 26 and July 28, similar problems surfaced in Maple Plain, Minnesota, where officials briefly declared a state of emergency; in Clayton County outside Atlanta, where a pump station failure triggered a boil-water advisory; and in New Jersey and Michigan.
The FBI has confirmed attacks on water and wastewater facilities in at least seven states, and its investigation is ongoing. Rob Lee, co-founder and CEO of the industrial cybersecurity firm Dragos, said he is aware of victims outside the water sector as well. "I can't recall a time when there's been this many targets at once with operational impact," Lee said, calling the situation "pretty significant."
Jake Braun, former acting principal deputy national cyber director under the Biden administration, said "it appears this is a shot across the bow from Iran" and that the attack should be assumed to be national in scope.
The U.S. government has not officially attributed the latest attacks, but Iranian-linked hackers have targeted American water and power infrastructure before, including a 2023 breach that defaced industrial equipment at a facility in Aliquippa, Pennsylvania, with anti-Israel messages during the Israel-Hamas war.
The Cybersecurity and Infrastructure Security Agency updated an advisory on Iranian-linked threats to industrial systems just days before the recent attacks began. Michael Crean of the cybersecurity firm SonicWall said his company detected a recent spike in scanning for vulnerable devices, similar to a pattern observed before Iran-linked hackers compromised medical technology company Stryker in March.
More than 150,000 water and wastewater systems operate across the United States, and officials are working to help operators secure their systems as they brace for the possibility of further attacks.
This article was produced with the assistance of artificial intelligence (AI), in accordance with our editorial policy.





