In late July, Minnesota authorities disclosed that hackers had attacked not one or two water systems—but more than 30 across the state. The following weeks saw additional revelations in other states. Officials are beginning to understand the scope of what is likely an Iranian cyber campaign months in the making. Although the U.S. government has not publicly attributed the attacks, an Iranian actor linked to the Islamic Revolutionary Guard Corps (IRGC) known as the CyberAv3ngers has claimed responsibility, stating their intention was to “warn America to back down.”
The following set of charts brings together existing press reporting and CSIS expert analysis to provide a picture of what is known about the cyberattacks on the U.S. water sector so far. It is important to acknowledge that the reporting is thus far incomplete; the current understanding of the scope and scale of the attacks is reliant on states self-reporting incidents as they search their technical logs from recent weeks, and reporting requirements are inconsistent at best.
This style of attack is not new for Iran; water facilities have become something of an Iranian specialty. Actors linked to Iran attacked water facilities in the United States as far back as 2013 in New York and Pennsylvania in 2023; they also attacked water systems in Israel in 2020 and 2023. But these earlier attacks went after only one or a handful of targets, whereas the 2026 attacks simultaneously hit at least 12 states and multiple targets.
Notably, the damage from the 2026 attacks has been relatively minor. So far, there have been no reports of the cyberattacks degrading water quality to a point where it endangers consumers. The most severe consequences have been in Georgia, where hackers shut down a pump station, which caused water pressure to drop. That, in turn, increased the risk of contamination and led to an advisory to affected residents to boil water, though no related illnesses were reported.
Some will argue that Iran may be seeking to send a message with these attacks rather than cause damage, likely intending to limit escalation. Others will argue that this is a significant escalation by Iran, as the scope of these attacks has been far broader than earlier incidents. Likewise, this campaign has brought impacts from the current conflict in the Middle East home to the U.S. domestic landscape. Either way, it is impossible to rule out Iranian intent to harm Americans through these cyberattacks. These incidents provide an important moment to take stock of how vulnerable U.S. critical infrastructure is to adversaries, and to revive momentum at all levels for securing critical systems across the country.
The cyber actors targeted water systems in at least 12 states, according to ABC and other news outlets. The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have not publicly identified all 12 states, but 9 states have publicly confirmed that they were targeted, as shown in Figure 1. At the moment, there seems to be no discernable pattern to the attacks, suggesting that the campaign was broad rather than targeted, for example, at electoral swing states, red states, or blue states.
The New York Timesreported that at least 100 facilities across the United States have been targeted, though the names and locations of these facilities were not released. Through open-lities
Managing Dispersed Water Systems
The United States has more than 150,000 water systems, many managed at the city, county, or local level. Only a handful of U.S. states had pending state-level legislation to improve cybersecurity regulations and funding for water and wastewater systems when these attacks occurred. Federal government regulations require mandatory inspections for water providers supplying populations of over 3,300 people, but previous attempts to strengthen federal government rules and oversight about cybersecurity of water providers have failed under criticism from states and utilities about the lack of resourcing at the local levels and likely additional costs to consumers.
In the aftermath of this campaign by Iran, several members of Congress have introduced pieces of legislation to address the gap. As just one example of recent legislation revealing growing urgency at the national level, the recently proposed Water Cyber Shield Act seeks to improve oversight of the water sector by the Environmental Protection Agency (EPA) to ensure these systems are secure. This proposal follows earlier efforts to strengthen cybersecurity oversight and requirements for water systems. For instance, in April 2025, congressional members introduced the Water Risk and Resilience Organization (WRRO) Establishment Act, which would serve as a new governing body to work with the EPA to develop and enforce cybersecurity requirements for drinking water and wastewater systems.
Conclusion
Critical infrastructure, and specifically a utility such as water, is an attractive target for adversaries for two reasons. First, it is critical to the functioning of society and the economy, meaning any disruption can have an outsized effect and cause maximum embarrassment for the government. Second, utilities in the United States tend to be under-resourced (e.g., limited staff, limited cybersecurity capacity) and are often locally owned. In essence, the high-impact targets require little effort to penetrate.
China has similarly taken advantage of this relative weakness. The Volt Typhoon threat actor, directly linked to the People’s Liberation Army, has infiltrated U.S. military installations overseas—including water facilities—to pre-position ahead of time and maintain a persistent presence. The goal of these operations is almost certainly to give China the ability to disrupt U.S. critical infrastructure amid a conflict, should one arise.
These attacks on water facilities should be a wake-up call that shifts the risk calculus for critical infrastructure providers. Rather than think about cybersecurity as a “tomorrow” problem, infrastructure providers and owners should assume that they are targets, whether for state or nonstate actors. Efforts are underway at the federal and local level to reevaluate mandates and collaboration between governments and private utility providers; that momentum needs to continue long after the immediate threat has passed. While Iran may have only intended to send a message amid the ongoing Middle East conflict, it certainly proved the vulnerability of U.S. critical infrastructure to cyber threats. And, armed with that knowledge, the next adversary could attempt to do far worse.
Emily Harding is director of the Intelligence, National Security, and Technology Program and vice president of the Defense and Security Department at the Center for Strategic and International Studies in Washington, D.C. Aosheng Pusztaszeri is a research associate with the Intelligence, National Security, and Technology Program at CSIS. Lauryn Williams is the deputy director and senior fellow in the Strategic Technologies Program at CSIS. Nikita Shah is a senior fellow with the Intelligence, National Security, and Technology Program at CSIS. Aashka Vyas is an intern in the Strategic Technologies Program at CSIS. Carter Musheno is an intern in the Strategic Technologies Program at CSIS.
