America is grappling with a mysterious campaign of apparent cyber intrusions. Since late July, water and wastewater utility companies in several states have reported suspicious incidents to the Federal Bureau of Investigation.
Michigan, Georgia and South Dakota have since confirmed similar incidents, bringing the number of affected states to 12. In each case, officials said operations were disrupted only briefly and that water supplies were never put at risk. The identities of the remaining affected states have not been made public.
Despite multiple federal agencies investigating what they describe as "cyber threat actors", President Trump has instead blamed Democratic state leadership for the disruptions.
Agencies Identify Malicious Cyber Activity
The FBI, in coordination with the Environmental Protection Agency (EPA), issued a public service announcement warning owners and operators of critical infrastructure assets that malicious cyber actors are carrying out cyberattacks targeting what it termed Operational Technology (OT) devices. These are the systems used to monitor and control industrial processes, including water provision and wastewater treatment.
According to the FBI announcement, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents since late July, and "some of that activity degraded water operations". The agency noted that while this behavior has so far only been observed targeting particular devices, the threat may not be limited to those devices alone.
The malicious actors, the FBI explained, remotely accessed internet-facing devices and changed their IP addresses and passwords, cutting off operators' ability to monitor and control the equipment.
Affected sites reported specific operational effects to the FBI, including loss of pressure, which could allow untreated groundwater to seep into the pipes, and flooding of water systems.
Meanwhile, the Cybersecurity and Infrastructure Security Agency (CISA) issued its own warning about the incidents, urging affected utilities to remove the targeted technologies from the internet "as soon as possible".
The agency noted that threat actors are targeting water entities of all sizes, and cautioned that even organizations with robust cybersecurity measures should double-check for vulnerabilities.
Neither agency's latest statements accused a particular organization or nation-state of the "malicious" activity. They did, however, recently issue a joint update to a cybersecurity advisory published in April this year, which warned American organizations of Iranian-affiliated cyber activity targeting the types of devices affected in the latest incidents.
"Iranian cyber actors continue to target US critical infrastructure, and the FBI is committed to identifying, disrupting, and imposing costs on those responsible", Brett Leatherman, assistant director of the FBI's Cyber Division, said on 22 July.
The purpose of the advisory, he added, was to identify suspect activity and "reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on".
Jess Kramer, the EPA's assistant administrator for water, described the threats as a serious concern for drinking water and wastewater systems, adding that they posed a legitimate risk to the various communities and sectors reliant on those services.
Trump Blames Minnesota, Not Iran
Officials in one of the affected states, Minnesota, reported that more than 30 community water systems had been targeted in the ongoing wave of attacks. Minnesota's state IT agency confirmed that its investigation remains active, though it has not attributed the activity to a specific actor.
Despite those comments, Minnesota Governor Tim Walz implied that the disruptions were part of modern warfare, alluding to America's ongoing conflict with Iran. His remarks came after President Trump blamed Minnesota's leadership, saying last week that the state's leaders were grossly incompetent.
"We heard in Minnesota there was a cyberattack and they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent", the president told a cabinet meeting at Camp David, Maryland.
Responding to Trump's criticism, the Minnesota governor claimed that the American president "knows exactly" who is responsible for the attacks.
"This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran", Walz added.
Walz further claimed that the Department of Government Efficiency (DOGE) "took an axe to CISA", leaving the US "exposed to cyber attacks".
US media, including the New York Times, has reported on unnamed government officials claiming that Iran is likely behind the current attacks.
A Pattern of Prior Attacks
The current incidents are not the first cyberattacks to target water infrastructure in the US. Previous foreign-orchestrated campaigns have already caused significant disruption to water supplies at a local level.
In 2024, a number of small, rural towns in Texas were hit by hacks that caused their water systems to overflow. The incidents were ultimately linked to a Russian hacktivist group called CyberArmyofRussia_Reborn.
American authorities have also previously identified and targeted Iranian cyber operations.
Earlier this year, the US Department of Justice (DOJ) announced the seizure of a number of website domains linked to Iran's Ministry of Intelligence and Security (MOIS).
The Department of Justice said that the seized domains were used by the MOIS as part of "attempted psychological operations" targeting adversaries of the Islamic regime.
According to the DOJ, the domains were used to claim credit for hacking activity, publish sensitive data stolen in such hacks, and call for the killing of journalists, dissidents, and Israeli individuals.