Cyberattacks targeting municipal water and wastewater systems in several US states have drawn attention to vulnerabilities in critical infrastructure, with investigators examining whether Iranian-linked hackers could be involved. Minnesota reported that at least 30 municipal water systems were affected in late July, while the FBI subsequently warned that malicious cyber actors had breached water and wastewater facilities in at least seven states and caused operational disruptions.
The attacks have raised concerns because the US has a vast and highly distributed water infrastructure network. Federal data shows that the country has about 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities. Water is typically drawn from sources such as lakes, rivers, reservoirs and underground aquifers before being treated, stored and distributed through extensive networks of pumps and pipes.
Cybersecurity experts have identified internet-connected programmable logic controllers (PLCs) and remote-access systems as potential entry points. These controllers help monitor and manage functions such as water pressure and chemical dosing at treatment facilities. Attackers who gain access through stolen or default credentials, unpatched vulnerabilities or improperly configured remote-access services could potentially interfere with operational systems, according to experts cited in reports on the attacks.
Also Read: Iran Proposes Service Charges For Vessels Using Strait Of Hormuz
The possibility of Iranian involvement has added a geopolitical dimension to the incidents. US officials are investigating whether Iranian hackers were behind some of the attacks, although the US government has not formally attributed the activity to Iran. Investigators are also considering whether another actor could have deliberately copied tactics associated with Iranian cyber groups in an attempt to mislead authorities. President Donald Trump has also questioned the assumption that Iran was responsible.
So far, there has been no indication that the attacks contaminated drinking water or made supplies broadly unsafe for consumption. However, some incidents caused operational disruptions that required manual intervention, while precautionary boil-water advisories were issued in affected areas. Cybersecurity experts have warned that attacks on water infrastructure could also undermine public confidence in essential government services even when the physical water supply remains safe.
Experts have urged water utilities to reduce the exposure of operational equipment to the public internet and strengthen protections around remote access. Recommended measures include properly configured firewalls, secure gateways or VPNs, multi-factor authentication, updated software, removal of default passwords and restrictions on user access. Utilities have also been advised to separate operational networks from business systems, maintain backups of controller programs, monitor remote access and regularly practise restoring systems and operating manually.
Also Read: Trump Signals Cautious Iran Talks As Hormuz Standoff Tests Diplomatic Efforts