Skip to main content
Threat IntelligenceEmerging Threats

Iran-linked hackers target US water systems in multi-state cyberattacks

Control room of a water treatment plant with industrial systems and computer workstations.

"All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," said Dale George, communications director for Michigan's Department of Environment, Great Lakes, and Energy.

State-by-state detections: Michigan and Georgia confirm activity

Nine Michigan water systems reported hostile cyber activity to the state's Department of Environment, Great Lakes, and Energy, and the department described the reports as a "small number" consistent with activity seen in Minnesota, according to communications director Dale George. Officials said there were no public-health consequences and that local operators addressed the issues.

Georgia confirmed to ABC News that it was affected but described the damage as limited. Neither Georgia nor Michigan issued public-facing notifications about the incidents, the reporting shows.

FBI advisory: at least seven states, Rockwell Automation/Allen‑Bradley PLCs observed

The FBI posted an advisory saying that since 27 July 2026 water and wastewater companies in at least seven states have reported incidents to the bureau, and that "some of that activity degraded water operations." In its advisory the FBI said it had so far observed the activity only against Rockwell Automation/Allen‑Bradley programmable logic controllers (PLCs), while advising organizations deploying other manufacturers' devices to follow the same hardening guidance.

CISA advisory and security-research signals: other PLC brands in scope

A broader CISA advisory, updated on July 22, warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors. Security researchers at Tenable were among the first public analysts to suspect Iran's involvement, citing similarities with previous attacks by the IRGC-linked CyberAv3ngers group.

Minnesota: the earliest confirmed state and contested attributions

Minnesota was the first state to confirm it had been hit; the state's IT department (MNIT) said attacks took place over July 26–27 and that more than 30 community water systems were targeted. MNIT has not officially attributed the attacks.

WIRED reported that a restricted WaterISAC notice shared with water utilities said Minnesota activity aligned with an earlier Iran-affiliated campaign. WaterISAC told WIRED it had not assessed attribution "at any time" and publicly stated that it had not supplied the leaked document to WIRED.

Attribution dispute and political reactions

Public statements about who was responsible diverged sharply. The FBI did not name a culprit or mention Iran in its advisory. Tenable and CISA signaled Iran-affiliated activity as a plausible link based on technical similarities and targeting patterns, while MNIT and other state officials stopped short of formal attribution.

President Trump publicly rejected the Iran link, telling reporters after a cabinet meeting: "they blame it on Iran. I don't think so. I blame it on Minnesota because they're grossly incompetent." He added, "I think the governor is behind it. I don't think there was an Iranian cyberattack."

Minnesota's governor Tim Walz pushed back, suggesting Iran was behind the attacks and criticizing federal funding decisions. Walz said, "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," and added, "This is what modern warfare looks like, and it further illustrates there's no plan to win a war in Iran. 'DOGE took an axe to CISA and left the US exposed to cyberattacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.'"

What this means for technologists, policymakers, and local operators

  • Technologists and security teams: The FBI noted activity observed primarily against Rockwell Automation/Allen‑Bradley PLCs and advised hardening measures; CISA warned that Schneider Electric, Siemens, and other PLCs may also be targeted, so teams should treat PLC environments as a priority for remediation and monitoring.
  • Policymakers and regulators: With at least seven states reporting incidents and differing public statements on attribution, regulators will face pressure to clarify reporting expectations and public notifications; Minnesota, Michigan, and Georgia responses show variation in when and how states communicate incidents.
  • Local water-system operators: State officials emphasized that local operators addressed issues and maintained safe operations; operators will need to retain incident-response readiness and collaborate with state IT and federal agencies such as the FBI and CISA for follow-on guidance.

The FBI investigation into the multi-state intrusions is ongoing, while technical signals point in different directions: Tenable and CISA cite Iran-affiliated activity and past IRGC-linked campaigns, the FBI has not publicly attributed the incidents, and political leaders offered sharply contrasting public statements. One concrete, immediate fact remains: more than 30 Minnesota community water systems were targeted over July 26–27, and at least seven states reported related activity to the FBI. Whether that tally grows, and whether federal authorities will move from technical advisories to formal attribution, are the next public milestones to watch.

Source: The Register — Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict