Iran-Linked Hackers Hit Water Systems Across at Least Seven US States

Michigan, South Dakota, and Georgia are among the states confirmed to have had water infrastructure targeted. This is not a Minnesota problem.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Hackers with ties to Iran have targeted drinking water systems in at least seven US states, extending well beyond the initial Minnesota incidents first reported by SecurityWeek.
  • Michigan, South Dakota, and Georgia are confirmed among the affected states.
  • Water treatment facilities are considered critical infrastructure, meaning successful attacks could affect the safety of tap water for ordinary residents.
  • No widespread service outages or confirmed water-quality failures have been publicly reported at this time.

Water comes out of your tap. You don't think much about what it took to get there. A network of pumps, chemical dosing systems, and sensors, all increasingly connected to the internet, sits between a reservoir and your kitchen. That connectivity is exactly what Iran-linked hackers have been probing.

At least seven US states have now had water-system infrastructure targeted, according to reporting from SecurityWeek. Michigan, South Dakota, and Georgia are named among the affected states, alongside others. The attacks had initially surfaced publicly around Minnesota, but the picture is considerably wider.

How did the hackers get in?

Water utilities often run industrial control systems, which are specialised computers that manage physical equipment like pumps and valves. Many of these systems were designed before internet connectivity was common and were bolted onto networks without strong protections later.

The failure mode here is familiar to anyone who has watched a healthcare or energy-sector postmortem: legacy equipment, thin security budgets, and a small IT team trying to manage everything at once. In practice, that often means default passwords that were never changed, remote-access portals left open to the internet, and software patches applied months late, if at all.

Iran-linked groups have targeted industrial control systems before. The US government has previously warned that Iranian hackers specifically hunted programmable logic controllers, which are small computers that directly operate physical machinery such as chemical pumps, made by Israeli firm Unitronics. Those controllers showed up in water facilities.

Should residents be worried?

Right now, no confirmed water-quality failures have been tied to these intrusions. That matters. Getting into a system and actually causing harm to water treatment are two very different steps.

Still, the breadth of the targeting is the story here. Seven states is not a coincidence and it is not opportunistic scanning. This looks like a deliberate, sustained effort against a category of infrastructure that the US government classifies as critical, meaning disruption would have direct consequences for public health.

Residents in the named states do not need to boil water or stockpile bottles based on current public information. If your local utility issues any advisory, follow it. Sign up for your water provider's alert system if one exists.

What does this mean for water utilities?

The operational takeaway is blunt: if your programmable logic controller or human-machine interface, the screen operators use to control equipment, is reachable from the open internet without multi-factor authentication (a security step requiring two forms of ID to log in), you are a soft target.

Patch cycles that work for office software do not map onto industrial systems, and that gap is where these intrusions live.

Operational takeaway: Any water utility still running internet-exposed control interfaces without multi-factor authentication should treat that as an active emergency, not a roadmap item.

© 2026 Threat Vectr