Thu 06 Aug 2026 / 09:44 ET
Kernel
Internet 3 min read

Iran-linked water hacks now span seven states, FBI says

The FBI says water and wastewater utilities in seven states were hit, with CISA warning some attacks disabled controls and triggered boil-water notices.

Dana Voss

By Dana Voss / Security Correspondent

Iran-linked water hacks now span seven states, FBI says
img: WIRED

Iran-linked water hacks against U.S. water and wastewater utilities have reached seven states, according to an FBI alert, expanding a campaign that federal agencies say has disrupted operational technology used to run physical water systems.

The FBI did not identify the affected states or describe the full scale of damage. The bureau said it is working with the Environmental Protection Agency and utilities that were hit. The warning follows reporting by WIRED that a memo tied dozens of attacks on Minnesota water and wastewater utilities to Iran, including more than 30 utilities in that state during the prior week.

The Cybersecurity and Infrastructure Security Agency said in its own advisory that some intrusions disabled digital controls and led to boil-water notices. A boil-water notice is a public warning to treat tap water before drinking it, usually because officials cannot rule out contamination or system failure. CISA’s wording does not say contamination occurred in every affected case, but it does mean the incidents crossed from ordinary IT nuisance into public-service disruption.

Who is behind the Iran-linked water hacks?

Federal agencies have pointed to Iranian-affiliated hackers as the leading suspect. CISA first laid out that attribution in an April advisory, and WIRED reported that a leaked memo connected the recent Minnesota utility attacks to the same suspected Iranian-linked activity.

President Donald Trump on Friday blamed the administration of Minnesota Gov. Tim Walz for the attacks. That claim sits awkwardly beside the federal cyber advisories, which focus on outside malicious actors and exposed control equipment rather than state officials as the operators of the campaign.

How the attacks can disrupt water systems

The technical weak point named by the FBI and CISA is the programmable logic controller, or PLC. A PLC is a rugged computer that connects software commands to real equipment, such as pumps, valves and treatment machinery. If that device is reachable from the public internet, attackers do not need to break into a fancy corporate network first. They can go after the box that talks to the machinery.

That is why the agencies’ mitigation advice is blunt and unglamorous. The FBI and CISA told utilities to remove internet-facing PLCs from direct exposure, use strong passwords, and create allow-lists so only approved devices can connect. In plain English: stop leaving industrial gear where random people on the internet can poke it, and stop trusting any device that shows up.

The campaign is notable because industrial control systems sit at the boundary between data and infrastructure. A stolen email archive is bad. A disabled control panel at a water facility can force operators into manual workarounds, reduce visibility into equipment, and trigger public-health precautions. The advisories do not provide enough detail to say how many people were affected or how long disruptions lasted.

Water utilities are also uneven defenders. Many local systems operate with small staffs and aging equipment, while attackers can scan the internet at scale for misconfigured devices. The FBI alert is a reminder that basic exposure management, boring as it sounds, is still the front line for critical infrastructure security.

This story draws on original reporting from WIRED.

More Internet/

view all ↗