US probes possible Iran link to cyber-attacks targeting water systems

Updated 05 Aug, 2026 04:41pm 4 min read
-- Reuters
-- Reuters

US authorities are investigating a series of cyber-attacks targeting water systems across multiple states, with cybersecurity experts saying the incidents fit a pattern previously associated with Iran, although no official attribution has been made.

Minnesota said last week that more than 30 state water systems had been hit by what it described as a “co-ordinated cyber-attack”.

Days later, the Federal Bureau of Investigation (FBI) said cyber-attacks had been reported in seven states and that “some of that activity degraded water operations.”

The US Cybersecurity and Infrastructure Security Agency (CISA) is reportedly examining a possible Iranian connection to the Minnesota attacks, according to US media. CISA declined to comment.

President Donald Trump has not blamed Iran for the incidents.

Morgan Wright, a former US State Department anti-terror adviser, told the BBC that attacks of this nature have often been linked to North Korea or Iran.

“And who are we in conflict with right now? Well, it’s Iran. So they become, they go to the top of the listed terms of nations capable, and also having a desire to do something like this,” Wright told the BBC.

According to CBS News, cited by the BBC, US investigators are also examining whether hackers may have posed as Iran-based actors in an attempt to create further discord during the US conflict with Iran.

Jake Braun, former acting White House deputy national cyber director, told the BBC that the Trump administration may be reluctant to publicly acknowledge an Iranian breach of US water infrastructure even if one were confirmed.

At a cabinet meeting last Friday, Trump blamed what he called “grossly incompetent” Minnesota officials, including Governor Tim Walz, for the cyber-attack.

Walz responded by saying Trump knew who was responsible for the attack and that other states had also been affected.

Iran has not commented on the latest incidents. Tehran has repeatedly denied involvement in previous cyber-attacks, including those targeting water systems, hospitals, presidential campaigns and a Las Vegas casino company.

Following US accusations in 2016 over attacks targeting banks and a dam near New York City, Iran’s foreign ministry said Washington should provide evidence and denied supporting malicious cyber activity.

Cybersecurity experts told the BBC that Iran has a documented history of cyber operations, although groups supportive of Tehran and operating outside the country could also be responsible, making attribution more difficult.

“They do it so that their fingerprints aren’t directly on it,” Wright told the BBC.

BBC Verify reported that most cyber-attacks against the United States and Israel this year linked to Iran have been attributed to a group called Handala.

The US Justice Department has said Handala operated on behalf of Iran’s Ministry of Intelligence and Security (MOIS).

The group was previously accused by FBI Director Kash Patel of accessing personal information and emails during the early stages of the Iran conflict.

According to BBC Verify, Handala’s most recent claimed attack in the United States occurred in mid-June, when it said it had breached a California water facility in response to a US strike on Iranian water infrastructure.

The Justice Department this year said it had disrupted a Handala hacking campaign targeting a medical technology company and involving the release of sensitive information related to Israeli government and military personnel.

US authorities have previously accused Iran of hacking presidential campaigns in 2024 to undermine confidence in the electoral process, while CISA has linked attacks on US water and wastewater systems in 2023 and 2024 to a group affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC).

Iranian nationals were also indicted in 2020 on charges of attempting to interfere in the US presidential election, while Iran-based hackers were accused in 2017 of ransomware campaigns targeting local governments, schools, healthcare providers and financial institutions.

Experts told the BBC the immediate risk from the latest attacks was less about contaminating water supplies than undermining public confidence in critical infrastructure.

“They’re attacking our trust in our government to be able to deliver basic services,” Braun told the BBC.

However, experts said future cyber-attacks could potentially disrupt water supplies, alter chemical distribution or damage infrastructure.

CISA and the US Environmental Protection Agency have previously warned that cyber-attacks pose “a serious concern” for water utilities. The United States has about 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities.

“If you want to bring a nation to its knees, you go after two things, you go after power and water,” Wright told the BBC.

Experts said many water systems remain vulnerable because they rely on ageing infrastructure and outdated technology.

They said stronger cybersecurity measures and government investment would be needed to reduce future risks.

CISA has recommended that water utilities disconnect internet-exposed systems where possible and reset passwords as immediate steps to reduce the risk of cyber intrusions.

For the latest news, follow us on Twitter @Aaj_Urdu. We are also on Facebook, Instagram and YouTube.