The war taps the pipes: Iranian hackers test a dozen states’ water systems

The war between the United States and Iran has a new front, and it runs through the pipes. Over the past several weeks, hackers believed to be linked to Iran’s Revolutionary Guards have targeted water treatment and distribution systems in roughly a dozen American states, according to French reporting that matches what US officials and security researchers have described. The intrusions have been clumsy and have mostly failed to do lasting harm. That is not the point. The point, analysts say, is the pressure they create, and the election they may be trying to influence.

The most visible incident happened last week in Georgia, in Clayton County, where a cyberattack caused a drop in pressure in the water network. As a precaution, authorities told residents to boil their water before drinking it. It later turned out there was no danger, and the disruption was described as minimal. But the episode showed how a small intrusion into a small system can produce a large scare, and how the fear itself becomes part of the attack. Journalists in Atlanta described the technical detail: the hackers appear to have reached the programmable controllers, the small computers that start and stop pumps and regulate the chlorine in the water. When those devices are connected to the internet, they become targets.

Georgia was not alone. Minnesota was hit first, in late July, with upward of 30 community water systems reporting intrusions over a single weekend, the largest such attack in the state’s history. Michigan followed, with nine systems reporting hostile activity. The FBI has said water utilities in at least seven states reported incidents, and that some of the activity degraded operations. Security firms were the first to point the finger at an Iran-linked group known as CyberAv3ngers, which has a history of hitting US water facilities, including a Pennsylvania authority in 2023, and which the State Department has linked to Iranian military officials through a ten-million-dollar reward offer.

The response in Washington was not what the security establishment expected. President Trump rejected the Iran theory without offering evidence, blaming instead the governor of Minnesota, whom he called incompetent, and suggesting the governor was behind the attacks. The governor, Tim Walz, a Democrat, answered that the president knows who is responsible, that other states were hit as well, and that cuts to the cybersecurity agency had left the country exposed. The exchange turned a technical story into a political one, which may be exactly what the attackers wanted.

If our reporting has earned your trust, consider helping us continue our work.

Contribute today

The deeper alarm comes from the researchers who saw this coming. Two years ago, a Georgia Tech professor warned water companies in the state that their systems were vulnerable after his team broke into 7,000 programmable controllers with weak passwords. The fact that such a rudimentary attack could degrade service, he said, shows how poorly protected the water sector is. He argued the hackers are not trying to cause a health catastrophe but to destabilize: if the water quality degrades and the networks are disrupted before the presidential election, the government could face difficulties, and that could influence the choice of the next president. That, he said, is what the Iranians are trying to do. The attacks may be primitive. The strategy behind them is not.

The pattern is not new, only the scale. In 2021, a hacker remotely accessed a water treatment plant in Oldsmar, Florida, and briefly changed chemical settings before an operator intervened. In 2023, an Iran-linked group defaced a Pennsylvania water authority’s systems after exploiting a device left exposed on the internet with default login credentials. Those were isolated incidents, treated as warnings. The current campaign has hit dozens of municipalities across at least seven states. The federal advisory names the hardware under attack, programmable controllers made by Rockwell Automation and other manufacturers, and warns that the same techniques could be turned on other internet-connected industrial systems. The water sector is learning, state by state, what the researchers have been saying for years: the pipes were never designed to be defended, and the war has found them.

Scroll to Top