Federal and state authorities in the United States are responding urgently to a series of cyberattacks targeting municipal water systems, incidents believed to be linked to hackers affiliated with Iran’s Islamic Revolutionary Guards Corps. Over the past week, at least seven states, including Minnesota and Michigan, have reported disruptions to the Federal Bureau of Investigation, with the number of states affected now estimated to be at least a dozen, according to sources familiar with the ongoing investigation.
These breaches have affected more than 100 municipalities, though some incidents may be unrelated. Officials emphasize that so far there is no evidence that any water supply was contaminated or rendered unsafe. However, the attacks have necessitated manual overrides of automated systems and precautionary boil-water advisories in several locations. For example, on July 21, Clayton County, Georgia, experienced unauthorized cyberactivity resulting in reduced water pressure and temporary service disruption. Officials there said service was restored within hours and that the incident remains under investigation.
Similarly, Rapid City, South Dakota, recently disclosed a cybersecurity incident involving a pump in its wastewater system. The city indicated it is cooperating with federal investigators, assuring the public that water services remain safe. Other municipalities have either not publicly disclosed similar attacks or have reported disruptions to federal authorities but withheld further details.
The scale of these intrusions underscores long-standing concerns about the vulnerability of the nation’s water infrastructure. The Environmental Protection Agency estimates there are roughly 150,000 public water systems in the U.S., many of which are small and lack robust cybersecurity defenses. Efforts to establish stronger protections for water utilities have encountered resistance in recent years. In 2023, the EPA under the Biden administration proposed cybersecurity rules intended to establish minimum standards for water system defenses, but the agency rescinded the order following legal challenges from Republican-led states and industry groups, which contended the EPA lacked the authority to impose such rules and that smaller utilities would struggle to comply.
The Biden administration and cybersecurity experts warn these attacks may be a prelude to more damaging incursions if left unchecked. “We are facing a reckoning of the consequences of ignoring the importance of investing in our nation’s cybersecurity for our critical infrastructure,” said Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition. Bolton’s organization has called on Congress for increased funding and legislative action to strengthen digital protections for state and local governments.
U.S. intelligence agencies have monitored Iranian cyber threats targeting critical infrastructure for years. Notably, a decade ago, Iranian hackers attempted to manipulate controls at a small dam in upstate New York, but a maintenance outage prevented potential damage. While recent water system attacks have employed relatively basic tactics, officials caution that more sophisticated attacks could emerge as geopolitical tensions with Iran escalate.
The Biden administration has urged vigilance and swift action to bolster infrastructure defenses. Meanwhile, former President Donald Trump dismissed allegations that Iran was responsible for the water system hacks, instead attributing the Minnesota incidents to local political leadership, reflecting the deep partisan divide surrounding cybersecurity and national security issues.
As investigations continue, federal agencies are working to identify vulnerabilities across the nation’s thousands of water systems, emphasizing that prompt reporting and coordinated response are critical to preventing more severe disruptions. Congress enacted legislation last year requiring utilities to report significant cyber incidents within 72 hours, but enforcement mechanisms have yet to be fully implemented. Officials stress that enhanced cybersecurity measures remain vital to protecting critical infrastructure and public safety.
