Cyberattacks hit water systems in seven US states, Iran suspected

Via foxnews.com

Cyberattacks hit water systems in seven US states, Iran suspected

Federal agencies issue joint advisory after attacks on municipal water utilities cause operational disruptions across multiple states

Someone turned off the taps, metaphorically speaking. Between July 28 and July 31, 2026, malicious cyber actors targeted water and wastewater utilities across at least seven US states, forcing some facilities to abandon digital controls entirely and revert to manual operations.

Minnesota bore the heaviest damage, with disruptions reported across more than 30 municipal water systems.

What happened and who is responsible

The FBI and the Environmental Protection Agency issued a joint advisory on the attacks, flagging the incidents as unusual for one specific reason: no ransom demands were made.

Advertisement

Federal investigators are exploring links to Iranian-backed hackers, citing identifiable tradecraft patterns consistent with prior Iranian cyber operations. Attribution has not been formally confirmed, and investigators say evidence collection is ongoing.

Prior incidents tied to Iranian actors targeted water facilities in Pennsylvania and Texas, including a facility in Aliquippa, Pennsylvania. The pattern of targeting critical infrastructure without a financial ask points toward disruption as the goal itself, not a payday.

Affected utilities reported significant degradation, meaning systems did not just slow down. Personnel had to physically take over processes that are normally automated.

The geopolitical backdrop

The July 28 to July 31 window is notable for its compactness. Four days, seven states, more than 30 systems in Minnesota alone. That tempo suggests pre-positioned access, meaning attackers likely had footholds in these networks before the visible disruption began.

Federal agencies have not publicly specified which states beyond Minnesota were affected, and the joint FBI and EPA advisory stopped short of formal attribution to Iran. The language used, linking the attacks to identifiable tradecraft patterns consistent with Iranian-backed actors, is the kind of careful phrasing that leaves room for the evidence to develop without committing prematurely.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Cyberattacks hit water systems in seven US states, Iran suspected

Cyberattacks hit water systems in seven US states, Iran suspected

Federal agencies issue joint advisory after attacks on municipal water utilities cause operational disruptions across multiple states

Via foxnews.com

Someone turned off the taps, metaphorically speaking. Between July 28 and July 31, 2026, malicious cyber actors targeted water and wastewater utilities across at least seven US states, forcing some facilities to abandon digital controls entirely and revert to manual operations.

Minnesota bore the heaviest damage, with disruptions reported across more than 30 municipal water systems.

What happened and who is responsible

The FBI and the Environmental Protection Agency issued a joint advisory on the attacks, flagging the incidents as unusual for one specific reason: no ransom demands were made.

Advertisement

Federal investigators are exploring links to Iranian-backed hackers, citing identifiable tradecraft patterns consistent with prior Iranian cyber operations. Attribution has not been formally confirmed, and investigators say evidence collection is ongoing.

Prior incidents tied to Iranian actors targeted water facilities in Pennsylvania and Texas, including a facility in Aliquippa, Pennsylvania. The pattern of targeting critical infrastructure without a financial ask points toward disruption as the goal itself, not a payday.

Affected utilities reported significant degradation, meaning systems did not just slow down. Personnel had to physically take over processes that are normally automated.

The geopolitical backdrop

The July 28 to July 31 window is notable for its compactness. Four days, seven states, more than 30 systems in Minnesota alone. That tempo suggests pre-positioned access, meaning attackers likely had footholds in these networks before the visible disruption began.

Federal agencies have not publicly specified which states beyond Minnesota were affected, and the joint FBI and EPA advisory stopped short of formal attribution to Iran. The language used, linking the attacks to identifiable tradecraft patterns consistent with Iranian-backed actors, is the kind of careful phrasing that leaves room for the evidence to develop without committing prematurely.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.