According to CBS News, cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, including Michigan, Minnesota, Georgia, New Jersey and South Dakota. In Braham, public works staff isolated the affected system, restored a backup and restarted the plant, with residents drawing on the town's water tower in the meantime; the plant was offline while public works isolated the affected system, restored a backup, and restarted the plant within approximately 90 minutes, with residents continuing to receive water from the city's water tower during that time.
The attack exploited programmable logic controllers, the industrial computers that manage chemical dosing, pumps, valves and flow at treatment plants. CISA has said the hackers are targeting these exposed devices and locking out operators by changing their passwords and IP addresses, according to CBS News. In Georgia, the disruption in Clayton County caused a drop in water pressure and forced the agency to issue a boil-water advisory, though service was restored within hours. More broadly, some utilities have lost critical remote-control capabilities, forcing operators to switch to manual mode, and in several cases hackers gained remote access to pumps, valves and water pressure. Officials have stressed that the cyberattacks have had no impact on drinking water, which has remained safe, though federal investigators have not made a formal attribution, and the tactics resemble a 2023 campaign by CyberAv3ngers, a group linked to the Iranian Revolutionary Guard, which exploited default passwords on water-system controllers. That earlier campaign, in late 2023, breached a Pennsylvania water authority near Pittsburgh among other targets, with a multiagency advisory noting the victims spanned multiple states, according to the Associated Press.
The vulnerability extends well beyond this single episode. A DEF CON Franklin volunteer defense programme, aimed at connecting cybersecurity experts with small rural utilities, found that most of the plants it examined had no incident-response plans at all. Its founder, Jake Braun, formerly the White House's acting Principal National Cyber Director, said of the utilities assessed that "Almost none of them had any documentation of what to do in case of an attack." The same report noted that the volunteer defense programme has reached only 21 of 50,000 unprotected small utilities, revealing a structural gap no federal law currently requires water systems to fill, since, unlike the electricity sector under NERC's mandatory standards, no comparable statute grants EPA or any other agency the authority to impose binding, financial-penalty-backed cybersecurity requirements on water utilities.
No deaths or serious harm have resulted from the latest wave of intrusions, and most affected towns restored service within hours by switching to manual operation or backup systems. But cybersecurity specialists point to a pattern of prior incidents, including Russian hackers opening floodgates at a Norwegian dam and the 2021 attempt to spike sodium hydroxide levels at a Florida treatment plant, as evidence that foreign state actors, potentially including China, may already have dormant footholds in American utilities that could be activated as leverage in a future conflict.
President Trump has publicly denied Iranian involvement, instead blaming Minnesota's governor, and has separately proposed $707 million in cuts to CISA, an agency whose director post has been vacant for eighteen months. Only a small fraction of the roughly 151,000 US water facilities, most of which are small, locally run operations without dedicated IT staff, participate in voluntary cybersecurity information-sharing programmes.