US Water Sector Attacks Spread to Seven States as Iran Link Emerges

Cyberattacks on US water and wastewater systems have spread to at least seven states, as investigators examine possible Iranian involvement in the campaign.
Table of Contents
    Add a header to begin generating the table of contents

    The cyberattack campaign against US water and wastewater operational technology has spread beyond Minnesota to at least seven states, according to reporting on the incident’s scope, with investigators examining Iran’s possible involvement. Minnesota reported that OT systems at more than 30 water and wastewater facilities were targeted on July 26 and July 27, and most cities reported no operational impact, with water remaining safe.

    The multi-state picture has since widened. Michigan officially confirmed that a small number of communities saw malicious cyber activity, with all systems operating safely and no public health concerns, while Rapid City, South Dakota reported a cyber incident involving one of its wastewater lift stations, saying water and wastewater infrastructure was never placed in jeopardy. Reports also identify Georgia among the seven targeted states, though the remaining state names have not been disclosed.

    The Campaign’s Expansion From Minnesota to Seven States

    Iran was immediately named the primary suspect, although the US government has not publicly blamed Iran. Media reports say federal investigators are looking into Iran’s potential involvement. The campaign’s widening footprint marks a material escalation of the earlier Minnesota-focused incident and confirms that affected systems extend well beyond a single state.

    Confirmed Incidents in Michigan, South Dakota, and Georgia

    The confirmed cases follow a similar pattern: malicious activity on operational networks with limited or no disruption to service. Michigan’s confirmation of a small number of affected communities, Rapid City’s disclosure involving a lift station, and Georgia’s reported inclusion all point to coordinated targeting rather than isolated incidents. In the Minnesota cases, one city noted the incident was limited to equipment connected via cellular communications.

    Cellular-Connected Equipment and the Iran Nexus

    The cellular angle is a notable technical detail. One Minnesota city noted the incident was limited to equipment connected via cellular communications, and Iran-linked hackers previously targeted water facilities in Israel through vulnerable cellular routers. The same pattern of reaching OT through cellular-connected equipment now appears in the US campaign. A report shared by WaterISAC, marked TLP:Amber and not intended for public release, says Minnesota’s Fusion Center found evidence the attacks were aligned with hacking campaigns previously linked by the US to Iran. The TLP:Amber designation means the analysis was distributed to members on a need-to-know basis, which has kept the underlying technical findings out of public view.

    Federal Advisories and Internet-Exposed PLCs

    Federal agencies recently updated an advisory on Iranian attacks on OT, warning that ICS equipment made by Siemens, Schneider Electric, and Rockwell Automation has been targeted. Censys has reported roughly 10,000 Rockwell, Siemens, and Schneider programmable logic controllers exposed to the internet, a figure that highlights the reachable attack surface across US industrial infrastructure. CISA urged the water sector to protect OT, with specific emphasis on PLCs.

    What the Escalation Means for Small Water Utilities

    The multi-state expansion concentrates attention on small utilities, the segment most likely to rely on cellular-connected OT endpoints and least able to maintain dedicated security staff. Even in incidents where no operational harm occurred, the campaign demonstrates that reachable control systems exist across many states at once, and that the sector’s defensive baseline may be uneven. For water systems the practical question raised by this escalation is whether internet-exposed PLCs and cellular-reachable equipment can continue to operate without network segmentation, since a campaign that touched at least seven states has already shown those links are being actively probed. The federal emphasis on PLC protection points in the same direction: when the device layer itself is the target, the controls that matter are the ones separating those controllers from the public internet and from the cellular channels used to reach them, rather than perimeter monitoring alone.

    Related Posts