U.S. officials have identified a series of cyberattacks targeting water systems across at least seven states, with Iran suspected as the likely source. The intrusions, first publicly revealed by Minnesota and later confirmed in Michigan, involved attempts to access and manipulate computerized controls used to monitor and adjust water quality, including chemical treatment levels and water pressure. Authorities caution that there is no evidence that any water supply was compromised or rendered unsafe for consumption.

The attacks have raised concerns due to their scale and sophistication, marking a rare instance of foreign cyber operations directed at critical infrastructure related to public health. Officials described the incident as an unprecedented example of cyber activity that, if successful, could pose significant risks to American communities. The investigation into the attacks remains preliminary, and while Iran is the primary suspect, definitive forensic proof has yet to be established.

The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) issued security alerts last week encouraging heightened vigilance among state and local water agencies and urging immediate reporting of suspicious activities. According to the Environmental Protection Agency (EPA), at least seven states have reported incidents consistent with the hacking activity, with some cases resulting in degraded water operations. Michigan authorities acknowledged receiving reports from multiple communities exhibiting behavior aligned with the federal descriptions, but assured that all systems remain safe and no public health threats have been identified.

Experts suggest the recent attacks may be part of an escalation in Iranian cyber operations following the U.S. and Israel’s initiation of hostilities against Iran five months ago. Alex Orleans, a cybersecurity analyst specializing in Iranian hacking groups, noted that while Tehran has long engaged in cyber campaigns against U.S. and regional targets, this latest activity represents a more direct intrusion into live industrial control systems within critical U.S. infrastructure.

Officials believe the hackers exploited known vulnerabilities in internet-connected operational technology systems common in water utilities, often selecting targets opportunistically rather than focusing on specific municipalities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommended that water facilities disconnect susceptible control systems from the internet to mitigate risks.

Responses at the local level have involved implementing manual workarounds and receiving federal guidance to patch affected systems and enhance defenses. Braham, Minnesota’s mayor, Nate George, emphasized the challenges faced by smaller municipalities operating on limited budgets and infrastructure, underscoring the need for significant investment in cybersecurity upgrades to protect critical services.

President Donald Trump expressed skepticism about Iran’s involvement after the initial reports, suggesting the state of Minnesota might have been responsible for the disruptions. This statement was rejected by Minnesota’s Governor Tim Walz, who described the attacks as illustrative of the evolving nature of modern warfare. Despite the president’s remarks, federal investigators maintain Iran remains the leading suspect as they continue to examine the scope and origin of the cyber intrusions.