Suspected Iranian Cyberattack Hits 30 U.S. Water Systems
More than 30 municipal water systems in Minnesota were targeted in a coordinated cyberattack this week, and U.S. intelligence agencies believe Iran was likely behind it. While investigators have not reached a final conclusion, officials say the incident fits a growing pattern of cyber operations against America's critical infrastructure since the U.S.-Iran war began earlier this year.
Photo by Jason Richard
The next battlefield may not be in the Middle East.
It could be the water flowing into American homes.
Gear Spotlight- What Our Readers Are Picking Up
U.S. intelligence agencies have assessed that Iran was likely behind a coordinated cyberattack targeting more than 30 municipal water systems across Minnesota, according to several U.S. officials familiar with the investigation.
The assessment is not yet final.
The FBI is continuing its investigation, but officials say the operation closely resembles previous cyber campaigns linked to Iranian state-backed hackers.
The attack comes more than five months after the conflict between the United States and Iran erupted.
The war began on February 28, 2026, when the United States launched Operation Epic Fury, targeting Iranian military infrastructure following weeks of escalating tensions.
While missiles and drones dominated headlines, cybersecurity experts warned another battle had already begun.
According to federal officials, Iranian-linked hackers started probing American critical infrastructure shortly after the conflict erupted.
Their targets were not military bases.
They were water plants, wastewater facilities and energy systems that millions of Americans rely on every day.
Those warnings have continued throughout the spring and summer.
Now, investigators believe they may have become reality.
According to officials, the Minnesota attack affected more than 30 municipal water systems.
At least one system was briefly taken offline, while another experienced disruptions affecting remote monitoring equipment.
Despite the incident, the Minnesota Information Technology Services (MNIT) agency said there is no evidence that drinking water was contaminated and no advisory has been issued asking residents to change their water usage.
"It is not a secret that these things have been taking place since the spring," said Joe Slowik, Director of Threat Research at intelligence firm Dataminr.
"There have been disruptions in multiple critical infrastructure sectors. It's a big deal."
Federal cybersecurity officials say the latest incident fits a broader pattern.
For months, the Cybersecurity and Infrastructure Security Agency (CISA) has warned utilities about Iranian groups targeting internet-connected industrial control systems used to operate pumps, sensors and treatment facilities.
Previous advisories urged operators to disconnect vulnerable remote-access devices, strengthen authentication measures and monitor unusual network activity.
Officials have not publicly released the technical evidence behind the latest assessment.
They also have not said whether the hackers successfully accessed operational controls or were limited to surveillance and disruption.
The timing, however, has drawn attention.
The cyberattack comes as military tensions between Washington and Tehran continue to rise, with both countries accusing each other of escalating the conflict through conventional and unconventional means.
Security experts say attacks on civilian infrastructure have become an increasingly common feature of modern warfare because they can disrupt daily life without requiring direct military confrontation.
That makes water systems, electrical grids and transportation networks attractive targets.
The FBI, CISA and U.S. intelligence agencies continue to analyze forensic evidence to determine whether the operation was directly ordered by the Iranian government or carried out by an affiliated hacking group.
Officials have also not ruled out additional attempted intrusions in other states.
For now, authorities insist Americans can continue using their water safely.
But the investigation has reinforced a growing concern among defense and cybersecurity officials.
America's next major attack may not begin with explosions.
It could begin with a keyboard.
Editor's Note:
U.S. intelligence agencies currently assess that Iran was likely responsible for the cyberattack, but officials have not publicly confirmed definitive attribution. The FBI investigation remains ongoing, and additional findings may change the assessment