Skip to main content Scroll Top
Advertising Banner
920x90
Top 5 This Week
Advertising Banner
305x250
Recent Posts
Subscribe to our newsletter and get your daily dose of TheGem straight to your inbox:
Popular Posts
Water Systems Under Attack: What We Know About the Suspected Iranian Hacks

The question of whether Iran hacked US water systems moved from speculation to national concern last week, when Minnesota disclosed that more than 30 of its state water systems had been hit by what officials described as a coordinated cyber-attack.

The FBI followed days later with a broader warning: incidents had been reported across seven states, and in some cases the activity actually degraded water operations.

Who Is Being Blamed

The Cybersecurity and Infrastructure Security Agency is reportedly examining a possible Iranian link to the Minnesota intrusions, according to US media accounts. CISA declined to comment.

President Trump has not publicly attributed the attacks to Iran. Cybersecurity specialists speaking with the BBC consider Tehran the likely source anyway.

Morgan Wright, formerly an anti-terror adviser at the State Department, explained the logic behind that assessment. Attacks of this type typically trace back to either North Korea or Iran. Given that the United States is currently in conflict with Iran, he said, Tehran rises to the top of the list among nations that possess both the capability and the motivation.

There is a complication. Investigators are also weighing whether attackers deliberately made themselves appear Iranian as a deception, hoping to deepen division during the war, according to CBS, the BBC’s US partner.

Politics Muddies the Picture

Jake Braun, who previously served as acting White House Deputy National Cyber Director, raised a different problem with attribution. The administration is running its own information campaign, which he suggested makes it less likely to publicly acknowledge an Iranian breach of water infrastructure even if intelligence confirmed one.

The domestic response has been openly partisan. At a cabinet meeting Friday, Trump blamed what he called grossly incompetent Minnesota officials, singling out Governor Tim Walz.

Walz fired back, saying Trump knows precisely who carried out the attack and is aware that other states were also affected.

Tehran’s Silence

Iran has not commented on the current incidents.

Its historical position has been consistent denial. Over the years, Tehran has rejected responsibility for cyber operations targeting water systems, presidential campaigns, hospitals, and a Las Vegas casino company in 2014.

After 2016 accusations involving banks and a dam north of New York City, foreign ministry spokesman Hossein Jaberi Ansari said on state television that Washington should produce proof, adding that Iran has never pursued dangerous activity in cyberspace and does not back such efforts.

The Deniability Strategy

Experts pointed to a structural feature of Iranian cyber activity that complicates attribution: sympathetic groups often operate from outside Iran’s borders.

Wright described the advantage plainly. If every attack originated inside Iran, linking them to the state would be relatively simple. Dispersing operations breaks that chain, keeping direct fingerprints off the work.

One group has dominated this year’s activity. BBC Verify found that most Iranian-linked cyber-attacks against the United States and Israel in 2026 have been conducted by Handala.

The US Justice Department has connected Handala to Iran’s Ministry of Intelligence and Security. FBI Director Kash Patel accused the group of accessing personal details and emails during the early stages of the war.

Handala’s most recent claimed US operation came in mid-June, when it said it had breached a California water facility in retaliation for a US strike on Iranian water infrastructure.

A Long Track Record

The pattern extends back years:

  • 2026 — The Justice Department disrupted a Handala operation targeting a medical technology company. The same effort published sensitive information about Israeli government and military personnel.
  • 2024 — Iran was accused of penetrating US presidential campaigns to sow discord, undermine faith in the electoral process, and illegally gather information on officials.
  • 2023 and 2024 — CISA reported that a group tied to the Islamic Revolutionary Guard Corps hacked American water and wastewater systems. Equipment controlling water pressure in two Pennsylvania towns had to be shut down temporarily.
  • 2020 — Two Iranian nationals were indicted over an alleged scheme to interfere in the presidential election by obtaining confidential voter data and sending threatening messages urging people to vote for Trump.
  • 2017 — Iran-based hackers were accused of a multi-year ransomware campaign against local governments, schools, healthcare providers and financial institutions, though CISA assessed that the activity was likely not government-sanctioned.

The Real Damage May Be Psychological

Experts were fairly consistent on what the immediate threat is, and it is not contaminated drinking water.

Braun described the target as public trust. These attacks undermine confidence in the government’s ability to deliver basic services, he said, at a moment when the country is already sharply divided over the war.

That said, nobody ruled out physical consequences down the line. Wright outlined what a successful operation could achieve: dangerous chemical distribution, shutting off supply entirely, or destroying equipment.

CISA and the Environmental Protection Agency have jointly identified cyber-attacks as a serious concern for water utilities. The scale of exposure is considerable, with 152,000 public drinking water systems and over 16,000 wastewater treatment facilities across the country.

Wright summarized the strategic calculation in stark terms. If you want to bring a nation to its knees, you target power and water.

Why These Systems Are Vulnerable

The weakness is largely technological age. Wright noted that much of the equipment running water and wastewater processes is exposed because the infrastructure itself is old or the technology controlling it is outdated.

Unless those systems are hardened, experts warned, this will remain a persistent national security problem.

There is also an ownership distinction that matters. Unlike most other critical infrastructure in the United States, the overwhelming majority of water utilities are publicly operated. That places responsibility for fixing the problem squarely with government.

CISA has issued recommendations to authorities nationwide aimed at reducing the risk. Two of its immediate instructions are notably basic: disconnect water systems from the internet as quickly as possible, and reset passwords.

Author

  • Lucienne

    Lucienne Albrecht is Luxe Chronicle’s wealth and lifestyle editor, celebrated for her elegant perspective on finance, legacy, and global luxury culture. With a flair for blending sophistication with insight, she brings a distinctly feminine voice to the world of high society and wealth.

Related Posts
More news