At least 12 states have now reported cyberattacks on water systems, and investigators are treating Iran-backed hackers as the leading suspect.
Story Snapshot
- Federal agencies warned that Iranian-affiliated actors are targeting water and wastewater systems with disruptive cyber activity.
- Sources told reporters the campaign has spread to at least a dozen states, widening from the first reports in Minnesota.
- Officials said some utilities lost monitoring and control functions, but drinking water has remained safe so far.
- President Trump said he does not think Iran was behind the Minnesota attack, even as investigators kept looking at that angle.
How the Water Attacks Spread
The first wave drew attention in Minnesota, where more than 30 municipal water systems were hit in a coordinated cyber incident. From there, the scope widened fast.
ABC News reported that possible intrusions had now been seen in at least 12 states, while CBS News said sources familiar with the matter were seeing signs tied to Iran-backed hackers.
More than a dozen states have been targeted by cyberattacks on water systems as new evidence increasingly points to Iran. pic.twitter.com/qmw0SSOJUS
— Breaking911 (@Breaking911) August 6, 2026
The damage pattern matters more than the head count. Federal and local reporting says attackers targeted the technology that lets operators watch pumps, valves, pressure, and alarms.
In some cases, that meant a loss of monitoring and control, plus forced manual operations. Authorities said those disruptions did not translate into unsafe drinking water, which remained protected.
Why Officials Are Looking at Iran
The Iran angle did not appear out of nowhere. The Environmental Protection Agency, Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, and National Security Agency issued a joint warning about an urgent Iranian-affiliated threat to the water sector.
That advisory built on earlier federal warnings about Iranian-linked actors exploiting programmable logic controllers across critical infrastructure.
That history gives the current case its shape. Water systems are attractive targets because a small breach can create outsized fear, even when the physical outcome stays limited.
Federal sources have previously warned that Iranian-affiliated actors have used internet-facing devices and control systems to disrupt operations, and investigators now appear to be reading this campaign through that same lens.
What Has and Has Not Been Hurt
The most important fact for residents is also the least dramatic one: there has been no confirmed widespread contamination of drinking water. Reporting from ABC News, Axios, and other outlets says utilities have kept operating safely, even when they had to switch modes or issue precautionary notices after pressure problems.
That distinction is easy to miss, but it is the whole story. Cyberattacks on water systems do not need to poison water to be serious. They can blind operators, break alarms, and force slow, manual work that raises risk. For the people running these plants, that is enough to turn an ordinary night into a nerve test.
Trump’s Response and the Open Question
President Trump said he does not think Iran was behind the Minnesota cyberattack, creating a public split between his comments and the direction of the investigation reported by other officials and news outlets. That disagreement does not erase the federal warnings.
It does show how quickly cyber cases move from technical intrusion to political argument, especially when the target is basic infrastructure.
For now, the practical takeaway is simple. Water utilities across the country are being told to harden internet-facing systems, watch for strange controller behavior, and prepare for manual fallback.
The reported attacks have already shown how a digital breach can unsettle a physical system without yet making the water unsafe. That is why the federal alarm is so high, and why the next disclosure may matter even more than the first.
Sources:
cbsnews.com, epa.gov, time.com, bbc.com, bloomberg.com, washingtonpost.com, insidecybersecurity.com, cisa.gov, reuters.com













