Suspected Iranian Cyberattacks Target U.S. Water Systems
AI-generated context summary requested by a Free News Reader user. Sourced via Gemini from publicly available information — no paywalled content was accessed.
You hit a paywall. Here’s the context on this topic based on publicly available information. We did not access any paywalled content. View original article.
Suspected Iranian Cyberattacks Target U.S. Water Systems
- Malicious cyber activity impacted water systems in at least seven U.S. states in late July 2026, with Minnesota reporting over 30 targeted municipal water facilities.
- Federal agencies, including the FBI and EPA, issued a joint warning on July 30, 2026, regarding ongoing Iranian-affiliated cyber activity against U.S. critical infrastructure.
Full Summary — powered by AI
U.S. federal and state officials are currently investigating a series of cyberattacks on the nation’s water supply, with suspicions pointing towards Iranian hackers. The incidents, which occurred in late July 2026, affected water systems in at least seven states, including Minnesota and Michigan, forcing some facilities to switch to manual operations. In Minnesota alone, more than 30 municipal water facilities were targeted between July 26-27, 2026. Michigan also reported cyberattacks on nine water systems over that weekend.
The attacks involved hackers remotely accessing internet-connected control systems, changing administrator passwords, and causing operational disruptions such as flooding and pressure loss. While these incidents caused interruptions in service, there have been no confirmed reports of drinking water contamination or risks to public health.
Days before the attacks, on July 22, 2026, federal agencies updated a warning about ongoing Iranian cyber threats targeting U.S. critical infrastructure, specifically mentioning water and wastewater systems. The FBI, EPA, and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint statement on July 30, 2026, highlighting “ongoing Iranian-affiliated cyber activity” targeting operational technology devices like programmable logic controllers (PLCs) used in water systems. These devices are often vulnerable due to outdated software, poor network security, weak access controls, and the use of default passwords.
The U.S. government has been aware of cybersecurity vulnerabilities in municipal water components for several years, with CISA issuing warnings since 2020 and specific advisories about unconfigured PLCs in water systems in 2023 and April 2026. In March 2023, the EPA mandated that all public water system audits include cybersecurity evaluations. However, this requirement faced legal challenges and was later withdrawn, though the EPA continues to urge voluntary action and provides guidance and technical assistance. Experts emphasize the need for utilities to implement basic cyber hygiene practices, such as removing internet exposure of industrial control systems, using complex passwords, and providing cybersecurity training for personnel.