US Water Systems Hit by Suspected Iranian Cyber Attacks
Is Iran behind the recent cyberattacks on US water systems? An assessment of the evidence, vulnerabilities, and risk of further escalation.
This week, a series of cyber intrusions bearing the hallmarks of Iranian cyber actors targeted water and wastewater systems across multiple US states. This situation report assesses the nature of the attacks, the broader strategic context pointing to Iranian involvement, and what it says about the growing threat of Iranian attacks on the US homeland and US cyber vulnerabilities.
OVERVIEW:
On July 28, Minnesota IT Services, the central information technology agency for the State of Minnesota, announced that it was coordinating with regional and federal agencies to respond to a significant cyber attack launched on July 26 targeting more than 30 municipal water supplies.
The attacks, which locked out users and compromised the ability of operators to monitor and control their systems, caused publicly reported outages in several towns and cities including Braham, Plymouth, South St. Paul and Maple Plain.
Two days later, on July 30, multiple federal agencies issued public advisory warnings of malicious cyber actors targeting Water and Wastewater Sector public utilities. The Cybersecurity and Infrastructure Security Agency (CISA) warned that it was observing a dramatic increase in intrusions targeting the large industrial computers known as programmable logic controllers (PLCs) used to automate operational processes by water and wastewater systems. According to CISA:
“These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”
CISA further advised that affected municipalities institute a boil water advisory.
The same day, the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) provided a more detailed warning, stating that since July 27, seven states had reported cyber attacks targeting operational technology used in water and wastewater systems. The announcement specifically warned that attacks had affected Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs. According to the FBI, the attacks risked significant damage to water systems and included “loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”

While the advisories did not explicitly name Iran, and Minnesota’s IT Services declined to attribute the attacks to any international actor, the attacks mirror tactics, techniques, and procedures used by Iranian cyber actors and follow other recent Iranian cyber attacks on US targets.
BIGGER PICTURE:
This week’s attacks follow previous warnings that Iranian cyber actors have been attempting to conduct cyber operations to disrupt US critical infrastructure, specifically in the Water and Wastewater Sector.
Attacks Bear Hallmarks of Iranian Involvement
Anticipating the growing Iranian cyber threat, on April 7, 2026, CISA, the FBI, the National Security Agency (NSA), the Environmental Protection Agency (EPA), the Department of Energy, United States Cyber Command, and the Department of the Treasury issued an advisory explicitly warning that Iranian cyber actors had been observed actively trying to compromise Rockwell Automation PLC programs employed by water and wastewater systems.
The advisory noted that an Iranian threat actor affiliated with the Cyber-Electronic Command of Iran’s Islamic Revolutionary Guard Corps (IRGC-CEC) known as “CyberAv3ngers” (aka UNC5691/Shahid Kaveh Group) had previously engaged in attacks on PLCs used by water and wastewater systems. As noted in the Homeland Security Brief - April 2026, between October and early November 2023, CyberAv3ngers compromised a series of PLCs regulating water pressure for the Municipal Water Authority of Aliquippa in western Pennsylvania, causing disruptions in service to 6,000 customers.
More recently, on June 11, 2026, a second Iranian cyber threat group, the “Handala Hack Team”, published evidence of an apparent intrusion into the networks of California Water Service (Cal Water). Handala passes itself off as a pro-Palestinian, pro-Iranian hacktivist group, but is generally believed to be part of Iran's Ministry of Intelligence. The group has become especially active since the beginning of the war with the US and Israel in February 2026. Handala has claimed responsibility for numerous recent high-profile hacks of US targets including major medical device company Stryker and the personal email account of FBI Director Kash Patel.
On July 23, 2026, Handala claimed responsibility for attacks on PLCs operating unknown critical infrastructure in Maryland. Handala further announced it would continue attacks specifically targeting water, energy, and transportation systems. The details of these attacks have not yet been publicly confirmed, but the fact that they occurred only days prior to the publicly acknowledged disruptions in Minnesota suggests the likelihood that Handala or other Iranian groups are behind the recent flurry of cyber attacks nationwide. It is also plausible that Maryland is among the seven states affected by recent attacks.
Municipal Water Systems Are Especially Vulnerable to Cyber Attacks
Municipal water systems have long been known to be vulnerable to cyber attacks due to a combination of uniform operational systems and poor industry-wide cyber hygiene.
While no two water and wastewater systems are exactly alike, they share commonalities in their operational processes and technology. Water networks follow similar processes for moving, storing, treating, distributing, and recycling water through a network of reservoirs and pumps, which make them easy for hackers to conceptually understand and assess single points of failure. Further, the operational technology used by most municipal water systems comes from only a handful of vendors. According to an analysis of CISA data by the Foundation for American Innovation, over half of operators used PLCs from only four companies: Rockwell, Siemens, ABB, and Schneider Electric. The relative uniformity of technology makes it easy for malicious actors to scan and identify vulnerabilities.

Hazards within this already vulnerable system are worsened by a poor industry track record for effective cybersecurity. A May 2024 report by the EPA found that 70% of all systems were assessed to violate basic requirements for cybersecurity under the Safe Drinking Water Act. An additional report published in November 2024 by the EPA’s Inspector General found that out of a survey of 1,062 water systems, 97 systems serving 26.6 million people had “critical or high-risk cybersecurity vulnerabilities.” The report suggested an additional 211 drinking water systems, serving 82.7 million people, also had unaddressed systemic cybersecurity issues.
Operators of small water systems are especially vulnerable as they often lack the resources and expertise for combatting continually evolving cyber capabilities. 97% of all US water systems are classified by the Safe Drinking Water Act as small systems serving 10,000 customers or less.
IMPLICATIONS:
While a response and investigation are ongoing, there are two early inferences that can be made from the attacks. First, ongoing vulnerabilities suggest significant regulatory gaps in cybersecurity for US water and wastewater systems. Second, Iran is likely signaling its capability and willingness to exploit these vulnerabilities to launch reciprocal attacks on US critical infrastructure.
Policy and Resource Gaps May Have Worsened Cyber Vulnerabilities in US Water Systems
An inadequate regulatory regime may have worsened the previously discussed systemic cyber vulnerabilities within water systems and contributed to the present crisis.
In October 2023, the EPA withdrew a contentious cybersecurity rule from March 2023 requiring cybersecurity inspections for rural water systems through state sanitary surveys. The rule had been designed to create enforceable standards for cybersecurity for small water operators. The move came after a lawsuit challenging the rule from the American Water Works Association (AWWA), the National Rural Water Association (NRWA), and the states of Missouri, Arkansas, and Iowa.
The lawsuit alleged that state sanitary surveys were not an effective means of instituting effective cybersecurity practices for small municipal water systems and were not consistent with other federal requirements. The plaintiffs instead promoted the “Cybersecurity for Rural Water Systems Act of 2023” as an alternative. Rather than requiring inspections, the Congressional legislation would provide resources and greater technical assistance to small municipal water systems for cybersecurity. Whether the act would have proven an adequate substitute for addressing ongoing cybersecurity issues is unknown as an updated version of this bill from 2025 has yet to pass through Congress.
In August 2025, the EPA released a series of ten recommendations for municipal water systems to improve their cybersecurity along with $9M in grants to upgrade aging infrastructure and conduct cybersecurity training. While the new resources represent a positive development, they likely do not negate the need for basic and enforceable safety standards of the kind that would have been provided by the state sanitary survey inspection regime initially proposed in 2023. Highlighting the need for enforceable standards, a May 2024 report by the EPA expressed serious concern at “alarming cybersecurity vulnerabilities” identified at municipal water systems by its inspectors. In many cases, the vulnerabilities appeared to be the product of negligence and complacency rather than insufficient resources and technical expertise, with the report noting that “some water systems failed to change default passwords, use single logins for all staff, or failed to curtail access by former employees.”
Another issue is that the new grants were allocated to agencies serving mid to large-size municipalities serving more than 10,000 customers, rather than small, rural systems which are known to be underserved.
The conspicuous gaps in resources and safety standards have allowed existing vulnerabilities to fester and become known to US adversaries. Handala has gloated that its June 2026 hack of Cal Water was specifically enabled by poor cybersecurity, stating, “The Handala Cyber Command emphasizes that this disruption occurred due to the lack of technical knowledge among the cybersecurity experts of the California water company in identifying the source of the attack, as well as shortcomings in cyber crisis management procedures.”
Iran is Signaling its Capability and Willingness to Retaliate Against US Critical Infrastructure
The recent attacks (assuming Iranian involvement) likely do not represent the full destructive capability of Iranian cyber threat actors, suggesting they were meant as a signal by Tehran that it had the means to launch reciprocal attacks on the US homeland in response to escalating threats of US attacks on Iranian critical infrastructure.
Iranian groups have been known to employ more dangerous forms of malware which could inflict longer lasting disruption to internal networks. Iranian cyber attacks on Albania in 2022 are illustrative of potential avenues for escalation.
Between July and September 2022, four groups affiliated with the Iranian government employed ransomware and wiper malware against Albania’s online government service portals in retaliation for the country hosting an Iranian opposition event, “Free Iran World Summit.” The Iranian groups also accessed the Albanian Parliament’s email server, and infiltrated databases used by customs and law enforcement, in a likely attempt to extract information about opposition figures attending the event. The attacks caused widespread disruptions of government services and froze the country’s border crossings. Albanian officials believed the attack aimed to completely delete government databases and sabotage the government’s ability to provide public services, of which 95% are coordinated online. The attack was severe enough for Albania to cut diplomatic ties with Iran and consider invoking NATO’s Article 5 collective defense clause.
The ongoing cyber attacks in the US, by contrast, have been much more limited in their effects. The current intrusions notably have not featured tampering with chemical levels, a well-known hazard for water systems, which has been attempted in at least one previous cyber attack in the US. In February 2021, unknown, possibly state-sponsored actors, briefly increased the amount of lye in the water supply for the town of Oldsmar, Florida, putting 15,000 residents at risk.
Further suggestive that recent attacks have been demonstrative in nature is the fact that Iranian cyber threat actors themselves have suggested that their operations have thus far been deliberately limited in scope. Following the June 2026 hack and leak operation on Cal Water, affiliates of the Handala Hack Team announced the group chose not to pursue more destructive operations, despite having the capability to do so.

As Vali Nasr, a Johns Hopkins SAIS professor and expert on Iranian grand strategy, notes, Iran’s war effort is carefully calibrated to “control American behavior and force the US to recalculate its options.” As part of such a measured strategy, Iran may choose to escalate the intensity and destructiveness of its cyber operations in response to threatened US attacks against energy sites and bridges, and other forms of critical infrastructure.
This briefing was compiled by Dan White. Dan is an independent foreign policy analyst based in the New York Metro Area. Dan is a former member of The Wilson Center and The Kennan Institute. Dan holds masters degrees from the Johns Hopkins University School of Advanced International Studies (SAIS), the Naval Postgraduate School, and the University of Washington. Dan is a former officer in the United States Army and a veteran of the War in Afghanistan.
For more information, corrections, or comments, please contact dan@opforjournal.com.
Thanks for reading! Please subscribe to stay informed on critical developments involving China, Russia, Iran and North Korea.




Very clear and informative. Thank you for this.