TodaySunday, August 02, 2026

Iran Suspected as FBI Investigates Water System Cyberattacks Across Seven States

Seven states reported incidents, Michigan confirmed nine water systems were hit, and the FBI is investigating what may be an Iranian campaign against US water infrastructure.
August 2, 2026
NASA Aqua MODIS satellite image of the Great Lakes showing Lake Michigan Lake Erie Lake Ontario Lake Superior lake water supply
A NASA Aqua satellite MODIS view of the Great Lakes on August 28, 2010, showing the largest collective body of fresh water on the planet. The Great Lakes supply drinking water to more than 30 million Americans, including communities in Michigan served by water systems targeted in recent cyberattacks. [Image Source: NASA Goddard Space Flight Center / Jeff Schmaltz, MODIS Rapid Response Team]

WASHINGTON – Whoever controls the programmable logic controllers inside a municipal water system controls something fundamental: the equipment that monitors treatment, regulates pressure, and ensures that what comes out of the tap has been processed correctly. Michigan officials confirmed this week that hackers had targeted those controls at nine water systems across the state. Minnesota had disclosed attacks on 30 water-related sites several days earlier. Federal authorities said the incidents extended to at least seven states in total, and the FBI was investigating what it described as a coordinated campaign against one of the most basic categories of American infrastructure.

The water kept flowing. Dale George, the communications director for Michigan's Department of Environment, Great Lakes and Energy, said the state's water systems continued to operate safely following the incidents. Minnesota, which first drew public attention to the problem when Governor Tim Walz addressed it directly, had asked some residents to modify water usage earlier in the week but said no restrictions remained active by Thursday. The systems held. The question federal investigators were working to answer was how close they had come to not holding.

Federal cybersecurity agencies had not arrived at this concern without warning. The FBI and the Cybersecurity and Infrastructure Security Agency had both issued advisories in prior years identifying water and wastewater systems as a specific target of Iranian-linked hacking groups. The threat was not abstract: federal prosecutors had previously filed indictments against Iranian nationals specifically for alleged cyberattacks against water infrastructure. The current wave of incidents was unfolding against that documented history.

No culprit has been officially named in the new attacks. Attribution in cybersecurity investigations takes time, and federal officials were careful not to make definitive claims that later investigations might complicate. What the FBI said publicly on Saturday was brief: "The FBI and our interagency partners are fully engaged to protect critical infrastructure." The statement confirmed the investigation was active. It did not name a suspect, and investigators at that stage were not expected to.

The week in which these incidents came to light was not quiet in the broader context of US-Iran relations. The Trump administration had been navigating a set of overlapping pressures: nuclear negotiations, military options, and diplomatic intervention from Gulf states pushing for restraint. Earlier reporting indicated that Trump stepped back from Iran strikes after Gulf partners urged a different path. Separately, the US and Israel had weighed targeting Iran energy infrastructure as part of a military pressure campaign. Those diplomatic threads were running alongside what the FBI was now investigating inside Michigan water systems.

Whether the timing was coincidental is something investigators would have to assess. What is documented in the cybersecurity research literature is that state-backed cyber operations tend to intensify when military and diplomatic pressure escalates, as a form of coercion below the threshold of kinetic conflict. Water systems make a pointed target for that kind of pressure. They are locally managed, often underfunded, and built on technology that in many cases predates any expectation of networked connectivity.

International Space Station photograph of Sault Ste Marie Michigan showing the St Marys River connecting Lake Huron and Lake Superior Great Lakes water supply
An International Space Station photograph from June 29, 2011, showing the Sault Ste Marie area where the St. Mary's River connects Lake Huron and Lake Superior on the Michigan-Canada border. The Great Lakes system supplies drinking water to millions of Americans in states whose water systems have been targeted in recent cyberattacks. [Image Source: NASA / Expedition 28]

Programmable logic controllers, the specific technology that federal officials identified as being targeted, were designed for industrial process control before remote monitoring was a standard feature. They operate inside wastewater treatment plants and water distribution systems, and in many smaller municipalities run on hardware that manufacturers stopped updating years ago. Federal agencies have issued advisories about the vulnerability of this equipment for more than a decade, recommending software patches, network segmentation, and access controls. Many systems have applied some of those recommendations. Many have not, because upgrades are expensive, require operational downtime that small water utilities cannot easily absorb, and in some cases mean replacing physical equipment outright.

The scope of the current incidents extended beyond what Michigan and Minnesota made public. Federal authorities acknowledged at least seven states had reported incidents. Five had not been named, and it was unclear whether that silence reflected ongoing investigations, decisions about public disclosure, or simply timing. Minnesota's involvement became known because Walz addressed it publicly. Michigan disclosed through its environmental agency. Whether other governors or state environmental departments would follow was an open question.

According to Al Jazeera, which reported Michigan's disclosure as it emerged, federal authorities had also issued a warning about Iranian capabilities in this specific area ahead of the current incidents. The warnings described Iranian hackers targeting operational technology used for remote monitoring and control, the same category of equipment that the attacks this week were reported to have reached.

US embassies across the Middle East were simultaneously advising Americans to leave as the Iran war continued expanding, which put the administration in the position of managing both cyber defense operations and military-diplomatic maneuvering simultaneously, across a span of days rather than the weeks that complex policy responses typically require.

What federal authorities could not say by Saturday evening was what, exactly, the hackers had accomplished inside the systems they reached. Michigan said operations remained safe. Minnesota said restrictions were lifted. But forensic analysis of cyberattacks routinely takes weeks, and the gap between systems operating and no unauthorized changes being made is not always closed immediately. Seven states were still working through that analysis. Michigan and Minnesota had disclosed what they knew. For the five others, what had happened inside their water systems, and what the people drinking from them might have reason to want to know, remained unanswered.

Dmitri Agafonov

Dmitri Agafonov

Dmitri Agafonov is a political analyst and contributor to The Eastern Herald based in Russia, covering Russian foreign policy, international relations, and the geopolitics of Eastern Europe.

Leave a Reply

Don't Miss