No US agency has publicly blamed Iran, and investigators are examining whether hackers could have falsely claimed an Iranian connection to sow further discord during the war.
Monday 17/08/2026
WASHINGTON – US authorities are investigating a possible Iranian link to a wave of cyberattacks targeting water systems in several states, raising concerns that Tehran may be seeking to bring the impact of the Middle East war directly into Americans’ daily lives.
Minnesota reported late last month that more than 30 water systems had been hit in a “co-ordinated cyber-attack”, with hackers targeting equipment used to remotely manage water reservoirs and deploying malware that temporarily disrupted operations.
The FBI subsequently said cyberattacks had been reported against water utilities in at least seven states, adding that some of the activity had degraded water operations. Authorities in New Jersey, South Dakota and Georgia have since reported similar incidents, although it was unclear whether they were among the seven states cited by the FBI.
But cybersecurity experts say Iran is a leading suspect given its history of targeting US infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) is reportedly investigating a possible Iranian role. In July, the agency linked Iran to similar attacks in the spring against internet-connected US utility systems.
“The sort of cyber-attacks that have recently been reported are usually attributed to North Korea or Iran,” said Morgan Wright, a former US State Department anti-terror adviser.
“And who are we in conflict with right now? Well, it’s Iran,” he told the BBC.
The attacks have so far caused no reported disruption to drinking-water supplies. But experts warn that the greater danger could be the erosion of public confidence in the government’s ability to provide essential services.
Jake Braun, a former acting White House deputy national cyber director, said the hackers were “attacking our trust in our government to be able to deliver basic services” during a deeply divisive war.
The United States has about 152,000 public drinking-water systems and more than 16,000 wastewater treatment facilities. Many are operated locally and rely on ageing technology, making the sector particularly difficult to secure.
The water industry is also one of the few major areas of US critical infrastructure without mandatory federal cybersecurity standards.
Experts say some systems still use simple or default passwords and equipment that was never designed to withstand modern cyberattacks.
That makes water infrastructure an attractive target for hackers seeking to demonstrate capability without necessarily causing major physical damage.
In June, the Iran-linked Handala group claimed to have breached California Water Service, the largest water utility in the western United States, and published screenshots of internal systems. The group said it had deliberately avoided disrupting the water supply.
The US Justice Department has linked Handala to Iran’s Ministry of Intelligence and Security. The group has also claimed responsibility for other attacks in the United States since the war began, including an operation targeting a medical technology company and an earlier breach involving FBI Director Kash Patel’s personal information.
Iran has not commented on the latest incidents and has historically denied allegations of involvement in cyberattacks against US targets.
The threat extends beyond the possibility of temporarily disrupting water supplies. Experts warn that successful access to operational systems could potentially allow hackers to manipulate chemical levels, shut down services or damage equipment.
“If you want to bring a nation to its knees, you go after two things, you go after power and water,” Wright said.
CISA and the Environmental Protection Agency have warned that cyberattacks pose “a serious concern” for US water utilities and have urged operators to disconnect vulnerable systems from the internet where possible and reset passwords.
The attacks also highlight a broader strategic vulnerability as water scarcity and ageing infrastructure increasingly become security concerns worldwide.
For Iran, which has itself faced years of drought, collapsing water infrastructure and warnings of “Day Zero” conditions in some cities, the suspected attacks could offer a relatively low-cost way to signal that the consequences of the war can reach Americans at home.
But until US investigators establish who was responsible, the Iranian connection remains an allegation rather than a confirmed attribution.
