
At least 12 states are now reporting cyberattacks on water systems, and officials suspect Iran-backed hackers may be behind them.
Quick Take
- Cyber intrusions have spread across at least a dozen states, according to multiple reports.
- Officials say the attacks targeted water and wastewater technology, not the water itself.
- Sources say the hackers could blind operators by changing passwords and disabling alarms.
- Federal agencies had already warned of an urgent Iranian-affiliated threat to the water sector.
A Fast-Moving Threat Across State Lines
Cyberattacks on U.S. water systems have expanded quickly, with reporting now placing the tally at at least 12 states. ABC News reported that possible intrusions have affected water and wastewater utilities from Michigan and Minnesota to Georgia, New Jersey, and South Dakota.
Sources told the outlet that the attacks have not caused widespread disruption to water supplies or wastewater treatment, and Michigan officials said systems kept operating safely.
More than a dozen states have been targeted by cyberattacks on water systems as new evidence increasingly points to Iran. pic.twitter.com/qmw0SSOJUS
— Breaking911 (@Breaking911) August 6, 2026
The pattern matters because the target is not a single utility or one weak town. It is the shared digital gear that keeps water moving, pressure steady, and alarms visible.
When attackers reach those systems, they can force staff into manual mode or lock them out by changing passwords and disabling alarms. That is how a modern water attack can create fear without immediately poisoning a drop of water.
Why Iran Keeps Coming Up
Iran has become the leading suspect because federal agencies have warned for years about Iranian-affiliated actors probing U.S. critical infrastructure.
In April, the Environmental Protection Agency, the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and the National Security Agency issued a joint advisory on an urgent Iranian-affiliated threat to water and wastewater systems.
Bloomberg also reported that the Trump administration warned of Iran-linked cyber activity against water and sewer technology.
That warning did not come out of nowhere. Federal advisories have repeatedly described Iranian-affiliated actors exploiting programmable logic controllers, the industrial devices that help run pumps, valves, and other operations.
Those same controllers show up in water plants, and the federal warning said the attacks have caused disruptions in some cases. In plain terms, the concern is not just hacking. It is the ability to reach into the bones of a utility and make staff lose control.
What the Latest Reporting Shows
The newest reporting does not describe a single dramatic shutdown. It describes a broad campaign of small intrusions, many of them detected early.
In Minnesota, officials said more than 30 municipal water systems were touched, but no one found unsafe drinking water. Reuters reported that President Trump said he did not think Iran was behind the Minnesota attack, which shows attribution still matters and not every official is using the same language.
Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, sources familiar with the matter told CBS News on Wednesday. https://t.co/EB7syBacjw pic.twitter.com/DwKkxyYQNb
— CBS Mornings (@CBSMornings) August 6, 2026
That disagreement is worth watching, but it does not erase the larger picture. Federal agencies are still warning water operators to harden their systems, and sources say the same style of activity is now showing up in more states.
The practical lesson is simple. Water remained safe in the incidents described so far, but the systems that keep it safe proved vulnerable enough to draw a nationwide alarm.
Why This Story Hits a Nerve
Water is one of the few things Americans expect to work without drama. You turn on the tap and assume the system behind it is quiet, boring, and secure.
These attacks remind people that modern water service depends on internet-connected controls, passwords, and alarms that can be reached from far away. That makes the threat feel both distant and personal at the same time.
The deeper concern is not panic. It is exposure. If attackers can keep finding their way into utilities in more than one state, then the next headline may not be about a warning at all. It may be about a utility that has already lost visibility, already lost control, and already had to scramble before the public ever heard its name.