A growing cybersecurity threat has put the US water infrastructure in the spotlight after hackers attacked water and wastewater systems in several states.
Although the first attacks were reported in seven states, the number of states affected has since increased to at least 12, U.S. officials and other sources said.
These incidents have raised concerns about critical infrastructure vulnerability to foreign-backed cyber operations. US officials believe Iran-linked hackers could be behind at least some of the activity, said one senior U.S. official who spoke on condition of anonymity.
But none of the names have been publicly disclosed so the investigation is still ongoing.
Water Utilities Become A Cybersecurity Target
Water treatment and distribution facilities are increasingly using internet-connected technology to monitor equipment, manage operations and control industrial systems. And this connectivity can also create openings for cybercriminals and state-based hacking groups.
Federal agencies have warned that Iranian-associated cyber actors have targeted operational technology used by US water systems. A congressional report said such attacks may involve programmable logic controllers, human-machine interfaces and sensors that are critical to industrial operations.
There were also some utilities that experienced disruptions in the last weeks that involved automated operations and remote monitoring.
Minnesota, one of the hardest-hit areas of the country, had dozens of water systems affected. Some facilities had to resort to manual processes as officials scrambled to secure their networks, municipal officials said.
Was Drinking Water Contaminated
Despite the serious nature of the cyber intrusions, so far the public report has not shown widespread contamination of drinking water. The immediate problems were more related to operational disruptions such as water pressure problems or downtime for automated systems.
But that distinction matters because a successful cyber-attack on a water utility does not mean that drinking water is unsafe. Even if attackers are able to get into the treatment or distribution control, experts say, it could be very bad news.
Why Iran Is Being Investigated
Iran-linked cyber groups have a history of targeting critical infrastructure. Previous incidents involving US water utilities have shown how internet-connected industrial control equipment can be exploited.
The current attacks are being looked at from that larger perspective. Security experts warn that attackers may take advantage of weaknesses in smaller municipal utilities, which may lack the cybersecurity resources available to major infrastructure operators.
The FBI and other federal agencies have said water and wastewater utilities should strengthen their defenses, review remote-access systems and consider disconnecting vulnerable operational technology from the internet where appropriate.
A Warning For US Critical Infrastructure
The attacks reflect a larger national security concern: essential services such as water, electricity, healthcare and transportation now depend on digital systems.
For US water utilities, recent incidents are a reminder that cybersecurity is no longer just an IT problem. Physical operations affecting communities can be disrupted when there is a compromised digital control system.
Even as investigators probe what might have been the Iran connection, the attacks have already revived calls for stronger cybersecurity standards, greater federal help and better protection of America’s aging water infrastructure.