Iran Suspected in Cyberattacks on 12 State Water Systems
Federal agencies investigate Iranian hackers for targeting water utilities in 12 states, sparking a political clash between President Donald Trump and Minnesota Governor Tim Walz.
A coordinated cyberattack campaign targeted municipal water and wastewater systems across at least 12 U.S. states between late July and early August 2026. The intrusions focused on internet-facing programmable logic controllers (PLCs), specifically Rockwell Automation MicroLogix series, allowing hackers to change passwords, disable alarms, and lock out operators. Minnesota was the hardest hit, with over 30 systems targeted, while Michigan reported nine affected facilities. Operational impacts included water pressure loss, flooding, and temporary plant outages in Braham, Minnesota, and Clayton County, Georgia, leading to some boil-water notices. Federal officials report no evidence that drinking water was contaminated.
Donald Trump dismissed intelligence suggesting Iranian involvement, instead attributing the vulnerabilities to the "grossly incompetent" leadership of Minnesota Governor Tim Walz. Governor Walz countered that the attacks are an example of "modern warfare" and accused the Trump administration's Department of Government Efficiency of gutting the Cybersecurity and Infrastructure Security Agency (CISA), leaving the nation exposed.
While the U.S. government has not issued a formal public attribution, the FBI, EPA, and CISA have warned of a surge in Iranian-affiliated actors targeting critical infrastructure. Leaked memos and intelligence briefings suggest the attacks align with campaigns by the Islamic Revolutionary Guard Corps. Federal agencies have urged utilities to disconnect operational technology from the public internet and strengthen password protocols to prevent further disruptions.