Please ensure Javascript is enabled for purposes of website accessibility
Scope of Hacks on US Water Supply Widens as Evidence Points to Iran
d8a347b41db1ddee634e2d67d08798c102ef09ac
By The New York Times
Published 2 hours ago on
August 1, 2026

A water tower in Flint, Mich., Aug. 20, 2020. Michigan and Minnesota are among at least seven states coping with cyberattacks aimed at disrupting water systems nationwide. (Erin Kirkland/The New York Times)

Share

Getting your Trinity Audio player ready...

The scope of cyberattacks on U.S. water systems has grown to include at least seven states and may be far wider, officials and experts warned, as authorities raced to safeguard the nation’s water supply against an assault that increasingly appeared to be the work of Iran.

While there were no indications that any water supply had been altered or made unsafe to drink, state and local officials throughout the country were on high alert for potential problems in vulnerable computers that are commonly used to monitor and adjust water quality, including chemical-treatment levels and water pressure. Minnesota first publicly reported the attacks, and now Michigan says its systems have also been targeted.

The attack has little precedent, experts said, but has long been the stuff of nightmares and sensationalized Hollywood thrillers: an apparent cyberattack by a foreign power during a time of war that could, at least in theory, jeopardize the health and safety of Americans.

Officials cautioned that they had not definitively determined that Iran was responsible for the attack and that the investigation was still preliminary. But they said Iran had stepped up cyberattacks since the U.S. and Israel launched a war against the country five months ago, and had previously targeted similar water systems and other critical infrastructure in the U.S. There seemed no financial motive, making a criminal attack less likely.

Despite growing concerns, President Donald Trump sought to downplay the matter on Friday by blaming Minnesota — which was early to spot and report the recent surge in malicious hacking activity, helping to prompt other states to probe their own water systems — for suffering intrusions his own intelligence agencies believe were highly likely carried out by Iran, officials familiar with the assessment said.

“I think Minnesota is behind it,” Trump said Friday in response to a reporter’s question about Iran’s possible involvement, which The New York Times earlier reported. “I don’t think there was an Iranian cyberattack.”

The state’s Democratic governor, Tim Walz, dismissed the accusation, warning in a social media post that this “is what modern warfare looks like.”

After Trump’s remarks, federal officials privately said Iran remains the top suspect but that the assessment remained preliminary and had not yet established definitive forensic proof. That is not unusual in complex cyber-investigations, which can often take months to reach authoritative conclusions, if at all.

Nate George, the mayor of Braham, a small city north of Minneapolis that was among those affected by the cyberattack, said federal and local officials had little doubt about the likely culprit.

“We’re getting bits and pieces of information from the state of Minnesota and the FBI,” he said in an interview Friday afternoon. “They are pretty sure it’s Iranian actors” but are reluctant to say so publicly, he added. A memo sent by an industry group that shares cyberthreat information among water utilities that was obtained by Wired magazine said the attacks aligned with hacking activity being conducted by Iran-affiliated actors.

George, a Republican who is running for state auditor, said he had heard the president’s remarks casting doubt on Iranian culpability. He said the president was “entitled to his opinion,” but that it is incumbent on state officials to help cities harden their defenses against cyberattacks.

Minnesota was not the only state to suffer intrusions. In a public advisory published late Thursday, after the Times report, the FBI and the Environmental Protection Agency said that since Monday “at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.”

Officials have declined to say which states have been affected, but a spokesperson for the Michigan state government confirmed that state’s system was attacked.

“We received a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” Dale George, the spokesperson, said in an email. George added that all systems affected continued to operate safely and there were “no known impacts that posed a public health concern.”

Alex Orleans, a former U.S. government cybersecurity contractor who specializes in tracking Iranian hacking groups, said Iran had been engaging in a wide variety of hacking operations against U.S., Israeli and Middle Eastern targets since the start of the war in February. But the intrusions into U.S. water systems appeared to be a significant escalation.

“What’s unprecedented here is that we’re seeing direct, tangible effects to live industrial control systems inside U.S. critical infrastructure,” said Orleans, who is now the chief of threat intelligence at Sublime Security, an email protection company.

The U.S. Cybersecurity and Infrastructure Security Agency, in an advisory issued Thursday, said the hackers were “targeting water entities of all sizes” and recommended facilities unplug vulnerable controllers from the internet. The hacking activity, it added, had “resulted in boil water notices and sustained manual operations.”

The agency has for months been warning the public that Iran may seek to compromise water utilities and other critical infrastructure.

Former intelligence officials and cybersecurity experts said the hackers were likely engaging in opportunistic behavior rather than selecting specific cities and towns to infiltrate. That means that potentially any facility using the vulnerable internet-connected operational systems was at risk.

Iran, Orleans said, was likely looking to infiltrate as many networks as possible across the country before they can protect against “the opportunistic tradecraft that the U.S. government has offered multiple, explicit warnings about.”

George, the mayor in Minnesota, said city officials had received guidance on how to patch water systems that had been affected and how to bolster defenses against attacks Iranian hackers are capable of carrying out.

While manual workarounds are keeping water flowing for now, he said the attack highlighted the rudimentary nature of critical infrastructure in many small cities.

“I think the troubling thing on the horizon is how do we move forward to a more secure system,” George said.

“IT infrastructure upgrades are very costly and we are a very small municipality.”

This article originally appeared in The New York Times.

By Dustin Volz/Ernesto Londoño/Erin Kirkland

c.2026 The New York Times Company

 

RELATED TOPICS:

Send this to a friend