ThinkPatternGet the app
Perspective
TECHNOLOGY · JUL 31, 2026

The Water Attacks Didn't Stop With the Ceasefire

Iran's cyber campaign against US water utilities continued past the June 15 ceasefire, exploiting a vulnerability that predates the war — and the White House and federal agencies cannot agree on who is responsible.

In late October 2025, Canada's cyber defense agency issued a warning: hacktivists were inside community water systems, manipulating water pressure through industrial control equipment connected directly to the public internet. The attackers were pro-Russia groups exploiting unpatched vulnerabilities and weak credentials. Mandiant's Paul Shaver was blunt about why.

Their primary initial access method often involves opportunistically exploiting unpatched, publicly known vulnerabilities in internet-facing devices, weak security configurations, or the use of default credentials. — Paul Shaver

The door was open. Five months later, Iran walked through. The pipes were already failing. In March, a 42-inch transmission main burst in Shreveport, Louisiana, forcing citywide bottled-water distribution [1]. In May, the same diameter main failed in Oakland County, Michigan, cutting service across five communities and triggering an emergency declaration [2]. Neither event was a cyberattack. Both produced the same result: flooding and loss of water pressure. Meanwhile, AI data centers were projected to consume 161 billion gallons of water annually in Texas alone by 2030, requiring $58 billion in new infrastructure [3]. The system was strained before any adversary touched it. Iran's campaign began in earnest in March. On March 21, Iranian forces targeted Gulf desalination plants with missiles, drones, and cyberattacks — a strike on the water supply itself, with experts estimating Saudi Arabia could survive only days on stored reserves if its plants were crippled [4]. On April 8, six US federal agencies issued a joint advisory: Iran-affiliated actors had compromised programmable logic controllers — the computerized brains of water treatment and distribution — across the energy, water, and government sectors. Censys reported 3,900 vulnerable devices in the United States, nearly three-quarters of the global total [5]. By May, the same IRGC-linked unit blamed for the water attacks had breached automatic tank-gauge systems at gas stations across multiple states, exploiting password-free internet-connected devices [6]. That same month, Israeli researchers attributed the LA Metro cyberattack to Iran's Ministry of Intelligence and Security [7]. Then came the ceasefire. On June 15, the United States and Iran agreed to end kinetic hostilities and reopen the Strait of Hormuz. But the cyber war had its own logic. The Iran-linked hacking group Handala was explicit.

And let it be clear: The cyber war did not begin with the military conflict, and it will not end with any military ceasefire. — Handala

Israel's National Cyber Directorate confirmed the pattern independently: Iranian cyberattacks against Israel had tripled from roughly 1,600 in June 2025 to 4,800 in June 2026. Director Yossi Karadi put it plainly.

Unlike in the kinetic realm, there's no ceasefire in cyberspace. — Yossi Karadi

On July 26 and 27, the campaign reached American community water systems at a scale not seen before. More than 30 Minnesota cities were hit simultaneously. In Braham, the attack shut down computerized controls at the water treatment plant. Plymouth saw impacts to water towers and lift stations. Maple Plain declared a local emergency [8]. By July 31, the FBI, CISA, and EPA confirmed the attacks had spread to at least seven states — and that some had caused actual physical damage: flooding and loss of water pressure. Minnesota's chief information security officer warned that "this same threat activity has likely been occurring in other states throughout the nation" [9]. The symptoms were identical to Shreveport and Oakland County. The cause was different, but the water did not care. At this point, the response split. Six federal agencies and state fusion centers attributed the attacks to Iran-linked actors. On July 31, President Trump addressed the matter from Camp David.

We heard in Minnesota there was a cyberattack, and they blame it on Iran. I don’t think so. — Donald Trump

He blamed Minnesota Governor Tim Walz instead, calling him "grossly incompetent" [9]. The attribution fight has a concrete consequence. CISA's acting director Nick Andersen was direct about the remedy.

We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. — Nick Andersen

It is a known fix, simple to describe, and it was available before the war, before Iran's campaign, before the October 2025 warning from Canada. The door that pro-Russia hacktivists walked through last fall is the same door Iran used this summer. The argument over who to blame has not closed it.


Sources
  1. 1. Shreveport Distributes Bottled Water Following Major Main Break
  2. 2. Oakland County Water Main Break Prompts Emergency Declaration
  3. 3. AI Data Center Growth Strains US Water Infrastructure
  4. 4. Iran Targets GCC Desalination Plants in Regional Conflict
  5. 5. U.S. Agencies Warn of Iran-Linked Cyberattacks on Critical Infrastructure
  6. 6. Iranian Hackers Breach U.S. Gas Station Fuel Monitoring Systems
  7. 7. Israeli Researchers Link LA Metro Cyberattack to Iranian State
  8. 8. Cyberattack Targets Water Systems in Over 30 Minnesota Cities
  9. 9. US Agencies Warn of Widespread Water Utility Cyberattacks

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play