Drooid Logo
Back to story perspectives

Full Breakdown

Iran-Linked Cyberattacks Disrupt U.S. Municipal Water Systems

8/4/2026, 8:01:18 AM

Core Event

  • The FBI and EPA reported cyber incidents affecting water and wastewater utilities in at least seven states since July 27, 2026.
  • Minnesota saw attacks on more than 30 municipal water systems; Michigan reported nine; Georgia and South Dakota also confirmed activity.
  • Hackers accessed internet-facing programmable logic controllers (PLCs), altered IP addresses and passwords, causing loss of monitoring, pressure drops and, in some cases, boil-water notices.

Background & Context

  • A July 22 federal advisory warned that Iranian-affiliated hackers were targeting PLCs used in critical infrastructure.
  • The United States operates roughly 152,000 public drinking-water facilities, many with outdated control software and limited cybersecurity staff.

Data & Statistics

  • Only about 0.5 % of U.S. water plants participate in the Water Information Sharing and Analysis Center (WaterISAC), highlighting limited sector-wide threat sharing.

Official Statements & Responses

  • CISA urged utilities to remove PLCs from public internet, use strong passwords, and install firewalls and access-control lists.
  • In a March 18, 2024 letter, EPA Administrator Michael Regan and National Security Advisor Jake Sullivan called on states to adopt cybersecurity plans for water systems.

Criticism & Opposition

  • President Donald Trump rejected the Iranian attribution, stating, “I think Minnesota is behind it” and labeling Governor Tim Walzgrossly incompetent.”
  • Michigan Department of Environment spokesperson Dale George noted that “all systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern.”

Conflicting Reports & Gaps

  • Outlets such as The New York Times, PBS and Wired cite federal officials who view Iran as the “most likely” actor based on similarity to prior campaigns.
  • Other sources—including ABC News, NBC News, and the FBI—emphasize that no formal attribution has been made and that technical analysis is ongoing.
  • Details on the specific PLC models compromised, any data exfiltration, and whether the actors attempted to masquerade as Iranian remain undisclosed.

Verbatim Quotes

  • “We heard in Minnesota there was a cyberattack and they blame it on Iran. I don't think so. I think, I blame it on Minnesota because they're grossly incompetent,” — Donald Trump
  • “We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor,” — John Israel, Minnesota’s chief information security officer

What’s Next

  • CISA’s advisory calls for utilities to complete a “disconnect-from-internet” audit of PLCs by the end of the current fiscal year.
  • Federal legislators are debating renewal of cybersecurity grant programs for state and local water agencies, with a Senate decision expected before the fall.