Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control
Two can play the game.
Seven states have reported cyberattacks on their water supply control systems, with some officials suspecting that Iran is behind these actions. According to the New York Times, there isn’t any definitive proof yet that Iran orchestrated these attacks but it said that moves like this have been escalating since the U.S. began its bombing campaign of the country. It was also noted that the attackers made zero financial demands, making it more likely to have been conducted by state actors that aren’t just motivated by money.
Minnesota was the first to report this kind of attack, with Michigan soon saying that it was targeted, too. While there have been no major disruptions that have made tap water unsafe to drink, the authorities across local and state governments are still on the lookout for potential problems. They’re particularly concerned about older computer systems that monitor water quality, adjust chemical treatments, and control water pressure, especially those that are connected to the internet.
Braham, Minnesota, is one of the areas affected by the cyberattacks. The mayor of the small city, which has a population of less than 2,000 people and is located about 50 miles north of Minneapolis, said it has already received guidance on how to resolve the issue and strengthen its defenses against future attacks. It’s currently using manual control to keep the water service on, but its mayor, Nate George, told the publication, “I think the troubling thing on the horizon is how do we move forward to a more secure system. IT infrastructure upgrades are very costly, and we are a very small municipality.”
He also repeated the suspicions that some federal officials had but declined to confirm. “We’re getting bits and pieces of information from the state of Minnesota and the F.B.I. They are pretty sure it’s Iranian actors.”
While states scramble to protect their utilities and other critical infrastructure, the White House has downplayed the suspected state-sponsored cyberattacks. President Donald Trump told a reporter, “I think Minnesota is behind it. I don’t think there was an Iranian cyberattack.”
This isn’t the first time that Iranian hackers have hit a U.S. institution during the 2026 war, but it’s the first time that essential services and infrastructure within the mainland have been affected. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously warned about potential Iranian cyberattacks, but smaller municipalities remain vulnerable.
Iran was also once on the receiving end of a cyberattack that many experts link to the U.S. The most famous of these was Stuxnet, which was supposedly used in 2009 to significantly damage and destroy critical tools used by the Iranian nuclear program. More recently, the CanisterWorm malware attacked Iranian machines and wiped them clean for no apparent reason. Again, no one has claimed responsibility for this attack.
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.
Wars have always been fought on land and on sea, and more recently, in the air and in space. But as the internet has become indispensable for society, cyberspace has quickly become a fifth domain that states must protect and dominate. “This is what modern warfare looks like,” Gov. Tim Walz said on X.
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Jowi Morales is a tech enthusiast with years of experience working in the industry. He’s been writing with several tech publications since 2021, where he’s been interested in tech hardware and consumer electronics.
-
TechieTwo Regardless of who the hackers are it should be obvious that all entities need to make their infrastructures physically and digitally secure. Anything less is total negligence and should be punishable under U.S. law for such.Reply -
JayGau I don't get it. Why those systems have to be on the internet? At my workplace, every critical system is on a air gapped network, completely disconnected from the internet. If towns use cloud services for infrastructures as important as drinkable water systems, they might want to rethink their approach. And don't tell me they need connection for off-site backup. There are solutions for that too, like network diodes.Reply -
Gururu Reply
We can't even get the lead pipes fixed and you are asking for high tech air-gapped network infrastructure?JayGau said:I don't get it. Why those systems have to be on the internet? At my workplace, every critical system is on a air gapped network, completely disconnected from the internet. If towns use cloud services for infrastructures as important as drinkable water systems, they might want to rethink their approach. And don't tell me they need connection for off-site backup. There are solutions for that too, like network diodes. -
alan.campbell99 Probably didn't help that the FBI counterintel team tasked with tracking these threats was gutted.Reply -
Air2004 Well, if your just gonna accuse random countries of crimes without offering proof.... Then, I accuse Israel, after all , they have the most to gain from it.Reply
As, evidenced by our military acting as a proxy for them. -
chaos215bar2 Reply
How do you know the backup wasn't the first thing compromised? Or the "network diodes" (which is really just a fancy name for a specialized router)?JayGau said:And don't tell me they need connection for off-site backup. There are solutions for that too, like network diodes.