Technology

US Water Systems Face Cyber Threats Amidst Suspected Iranian Activity

US Water Systems Face Cyber Threats Amidst Suspected Iranian Activity

Widespread Cyberattacks Target US Water Infrastructure

In a series of concerning developments, numerous water systems across the United States have reportedly been subjected to cyberattacks. Initially, the state of Minnesota disclosed that over 30 of its water systems experienced what was described as a “co-ordinated cyber-attack.” This revelation was swiftly followed by an alert from the FBI, which indicated that similar cyber incidents had been reported in seven states, with some of these activities leading to disruptions in water operations. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly investigating potential links between these incidents and Iranian actors, although CISA has refrained from making official comments on the matter.

Despite the absence of direct accusations from U.S. President Donald Trump, cybersecurity experts have suggested that the attacks bear hallmarks consistent with Iranian state-sponsored activity. Morgan Wright, a former anti-terrorism adviser for the U.S. State Department, highlighted that such sophisticated attacks are frequently attributed to nations like North Korea or Iran. Given the current geopolitical tensions, Wright pointed to Iran as a primary suspect, possessing both the capability and potential motivation for such actions. However, U.S. investigators are also exploring the possibility that the attackers might be impersonating Iranian groups as a deceptive tactic to escalate discord amidst the ongoing conflict between the U.S. and Iran, a detail reported by CBS, the BBC’s U.S. partner.

Jake Braun, who previously served as the acting White House Deputy National Cyber Director, suggested that the current administration’s involvement in its own information warfare could make it hesitant to acknowledge Iranian infiltration of U.S. water infrastructure, even if confirmed. President Trump, during a recent cabinet meeting, attributed the Minnesota water hack to “grossly incompetent” state officials, including Governor Tim Walz. Governor Walz, a Democrat, retorted, stating that Trump was aware of the true perpetrators and that other states had also been affected, implying a broader, potentially state-sponsored, threat rather than local negligence.

Iran has yet to issue an official statement regarding these specific incidents. However, Tehran has historically denied involvement in various cyberattacks over the years, including those targeting water systems, political campaigns, hospitals, and even a Las Vegas casino company in 2014. Following accusations in 2016 concerning attacks on banks and a dam near New York City, Iran’s foreign ministry spokesman, Hossein Jaberi Ansari, asserted on state television that the U.S. should provide proof for such claims, adding that Iran has “never had on its agenda any dangerous measures in cyberspace and does not support such moves.”

Tracing the Pattern: Iran's Cyber Activities

Experts indicate that these recent incidents align with a documented pattern of cyber activity linked to Iran. It is also noted that groups supportive of Iran, but operating outside its borders, could be responsible, complicating attribution efforts. Wright explained that this tactic provides plausible deniability, making it more challenging to directly link the attacks to the Iranian government. “They do it so that their fingerprints aren't directly on it,” he remarked.

BBC Verify’s investigations reveal that a group known as Handala has been responsible for the majority of Iranian cyberattacks against the U.S. and Israel this year. The U.S. Justice Department has connected Handala to Iran, stating that the group operates on behalf of the Islamic Republic of Iran’s Ministry of Intelligence and Security (MOIS). Handala was previously accused of accessing personal details and emails during the early stages of the Iran conflict. The group’s most recent claimed cyberattack in the U.S., according to BBC Verify, occurred in mid-June, where they asserted a breach of a California water facility, purportedly in retaliation for a U.S. attack on Iranian water infrastructure.

Other significant hacking operations linked to Iran include a 2026 incident where the Justice Department disrupted a Handala operation targeting a medical technologies firm, which also exposed sensitive information about Israeli government and military personnel. In 2024, Iran was accused of hacking into U.S. presidential campaigns to “stoke discord, erode confidence in the U.S. electoral process, and unlawfully acquire information” to aid Iran. Both in 2023 and 2024, U.S. water and wastewater systems were reportedly hacked by a group affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC), according to CISA, leading to temporary shutdowns of equipment regulating water pressure in two Pennsylvania towns. In 2020, two Iranian nationals were indicted for allegedly attempting to meddle in the presidential election by obtaining confidential U.S. voter information and sending threatening messages to influence votes. Additionally, Iran-based hackers were accused in 2017 of a years-long ransomware campaign targeting local governments, schools, healthcare, and financial institutions, although CISA noted that these activities were “likely not sanctioned” by the Iranian government.

Potential Dangers to Water Supplies and Public Trust

Cybersecurity experts emphasize that the primary threat posed by these hacks is not necessarily an immediate danger to the physical water supply itself, but rather a degradation of public confidence in the security and reliability of essential services. Braun articulated that such attacks erode trust in the government’s ability to deliver basic services, especially in a period of deep national division. However, experts also caution that the possibility of Iranian hackers eventually succeeding in endangering U.S. water supplies cannot be entirely dismissed. Malicious actions could potentially lead to the harmful distribution of chemicals, complete water supply shutdowns, or damage to critical equipment, as suggested by Wright. Both CISA and the U.S. Environmental Protection Agency have jointly recognized cyberattacks as “a serious concern” for water utilities, underscoring the vulnerability of the nation’s 152,000 public drinking water systems and over 16,000 wastewater treatment facilities. Wright starkly concluded, “Look, if you want to bring a nation to its knees, you go after two things, you go after power and water.”

Strategies for Prevention and Enhanced Security

A significant challenge in securing water infrastructure lies in the vulnerability of many operational devices, often due to aging infrastructure or outdated technology. Experts warn that without substantial upgrades to the security of these systems, the U.S. will continue to face this national security threat. Given that the vast majority of U.S. water utilities are publicly operated, unlike much other critical infrastructure, the onus for implementing robust security measures falls largely on the government.

CISA has issued various recommendations to governments across the U.S. aimed at mitigating this threat. Immediate actions suggested to hinder hacking attempts include promptly disconnecting water systems from the internet where possible and enforcing password resets. These measures are critical steps in enhancing the resilience of the nation’s vital water infrastructure against persistent cyber threats.