The United States is investigating a wave of cyberattacks against water systems in at least seven states, with Iran emerging as the leading suspect, though no definitive attribution has been made. Authorities stress that no water supplies have been contaminated or rendered unsafe, but the intrusions have disrupted operations and prompted heightened vigilance .
Minnesota was the first state to publicly report the intrusions, affecting over 30 municipal water facilities, followed by Michigan confirming similar activity . The FBI and EPA issued a joint advisory noting that some activity "negatively affected" water operations, leading to boil-water advisories and manual operations in some cases . The attacks targeted programmable logic controllers (PLCs) and human-machine interfaces (HMIs) exposed to the internet, which control chemical dosing and pressure .
While federal officials consider Iran the primary suspect, the investigation remains preliminary, and forensic proof may take months . President Donald Trump downplayed the threat, suggesting Minnesota was behind the attacks, a claim dismissed by Governor Tim Walz, who said "this is what modern warfare looks like" . Officials note the pattern suggests an "opportunistic" search for vulnerable systems rather than targeted selection .
CISA and the FBI have urged water utilities to disconnect vulnerable controllers from the internet and review remote access capabilities . The investigation continues, with no immediate public health threat reported.