Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control

Wait 5 sec.

Seven states have reported cyberattacks on their water supply control systems, with some officials suspecting that Iran is behind these actions. According to the New York Times, there isn’t any definitive proof yet that Iran orchestrated these attacks but it said that moves like this have been escalating since the U.S. began its bombing campaign of the country. It was also noted that the attackers made zero financial demands, making it more likely to have been conducted by state actors that aren’t just motivated by money.Minnesota was the first to report this kind of attack, with Michigan soon saying that it was targeted, too. While there have been no major disruptions that have made tap water unsafe to drink, the authorities across local and state governments are still on the lookout for potential problems. They’re particularly concerned about older computer systems that monitor water quality, adjust chemical treatments, and control water pressure, especially those that are connected to the internet.Braham, Minnesota, is one of the areas affected by the cyberattacks. The mayor of the small city, which has a population of less than 2,000 people and is located about 50 miles north of Minneapolis, said it has already received guidance on how to resolve the issue and strengthen its defenses against future attacks. It’s currently using manual control to keep the water service on, but its mayor, Nate George, told the publication, “I think the troubling thing on the horizon is how do we move forward to a more secure system. IT infrastructure upgrades are very costly, and we are a very small municipality.” He also repeated the suspicions that some federal officials had but declined to confirm. “We’re getting bits and pieces of information from the state of Minnesota and the F.B.I. They are pretty sure it’s Iranian actors.”While states scramble to protect their utilities and other critical infrastructure, the White House has downplayed the suspected state-sponsored cyberattacks. President Donald Trump told a reporter, “I think Minnesota is behind it. I don’t think there was an Iranian cyberattack.”This isn’t the first time that Iranian hackers have hit a U.S. institution during the 2026 war, but it’s the first time that essential services and infrastructure within the mainland have been affected. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously warned about potential Iranian cyberattacks, but smaller municipalities remain vulnerable. Iran was also once on the receiving end of a cyberattack that many experts link to the U.S. The most famous of these was Stuxnet, which was supposedly used in 2009 to significantly damage and destroy critical tools used by the Iranian nuclear program. More recently, the CanisterWorm malware attacked Iranian machines and wiped them clean for no apparent reason. Again, no one has claimed responsibility for this attack.Wars have always been fought on land and on sea, and more recently, in the air and in space. But as the internet has become indispensable for society, cyberspace has quickly become a fifth domain that states must protect and dominate. “This is what modern warfare looks like,” Gov. Tim Walz said on X.