Iran has intensified its cyber operations targeting critical infrastructure in the United States, signaling a potential escalation in hostilities amid ongoing tensions in the Gulf region. An Iranian hacking group known as APT IRAN has issued a warning about forthcoming cyberattacks on American energy, telecommunications, and water supply systems, describing the anticipated incidents as “unexpected and critical events.”

These developments follow reports that Iranian cyber operators recently attempted, though unsuccessfully, to breach networks controlling U.S. municipal water systems. The Federal Bureau of Investigation (FBI) disclosed last month that investigations are underway into cyberattacks targeting water facilities in at least seven states, including attempts to compromise more than 30 municipal water plants in Minnesota alone. Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued multiple alerts advising critical infrastructure entities to strengthen their defenses against Iranian hacking efforts aimed at internet-connected devices integral to managing essential services.

The rise in cyber threats coincides with renewed confrontations in and around the Strait of Hormuz, a strategic waterway through which much of the world’s oil passes. After a lull of approximately one month, tensions flared again following U.S. operations to clear mines from the strait, which Washington asserts has restored safer passage for vessels, particularly under the cover of night.

President Donald Trump has issued stern warnings to Iran, declaring on Tuesday that retaliatory attacks against the United States would be met with a “much harder and higher level” response. Following Iranian counterattacks employing missiles and drones targeting U.S. bases across several Middle Eastern countries—including Jordan, the United Arab Emirates, Kuwait, Bahrain, and Iraq’s autonomous Kurdistan region—Trump posted a provocative message on social media suggesting renaming the Strait of Hormuz to “TRUMP STRAIT,” emphasizing American control and strength in the region.

Iranian state media reported an American missile strike on Tuesday in Kuhestak, a coastal town, which it claims resulted in the deaths of four civilians at a wedding party, including two women and two children aged four and sixteen, as well as injuries to 68 others. Tehran also stated that the U.S. attacks killed four members of the Iranian Revolutionary Guard and ten members of the paramilitary Basij forces. Ebrahim Azizi, chairman of Iran’s parliamentary national security and foreign policy committee, condemned the strikes and vowed that these “crimes will not go unpunished.”

The U.S. Central Command (Centcom) acknowledged awareness of the reports originating from Iranian media and indicated it was looking into the claims but provided no confirmation of a formal investigation.

Separately, cybersecurity experts have highlighted vulnerabilities in American infrastructure systems, which often rely on basic computer technologies. The successful Iranian cyberattack last month that temporarily disabled an unspecified British power plant has been characterized by some officials as a “warning shot” demonstrating Tehran’s growing cyber capabilities to disrupt critical services abroad.

As the cyber threat landscape evolves alongside kinetic military exchanges, both U.S. agencies and private sector cybersecurity firms continue to monitor and prepare for possible escalations affecting vital infrastructure sectors.