Iran-Linked Hackers Hit Water Systems Across at Least Seven US States
Michigan, South Dakota, and Georgia are among the states confirmed to have had water infrastructure targeted. This is not a Minnesota problem.

Key points
- Hackers with ties to Iran have targeted drinking water systems in at least seven US states, extending well beyond the initial Minnesota incidents first reported by SecurityWeek.
- Michigan, South Dakota, and Georgia are confirmed among the affected states, along with others.
- Water treatment facilities are critical infrastructure, meaning successful attacks could affect the safety of tap water for ordinary residents.
- No widespread service outages or confirmed water-quality failures have been publicly reported.
Water comes out of your tap. You don't think much about what it took to get there. Pumps, chemical dosing systems, sensors: all increasingly connected to the internet, all sitting between a reservoir and your kitchen. That connectivity is exactly what Iran-linked hackers have been probing.
At least seven US states have now had water-system infrastructure targeted, according to SecurityWeek. Michigan, South Dakota, and Georgia are named among the affected states. The attacks had initially surfaced publicly around Minnesota, but the picture is considerably wider. We first reported on the Minnesota wave on 29 July, when automated controls were knocked out across the state and one city shut its plant down entirely.
How did the hackers get in?
Water utilities often run industrial control systems: specialised computers managing physical equipment like pumps and valves. Many were designed before internet connectivity was common and bolted onto networks without strong protections later.
The failure mode is familiar to anyone who has watched a healthcare or energy-sector postmortem. Legacy equipment, thin security budgets, a small IT team managing everything at once. Default passwords never changed, remote-access portals left open, patches applied months late, if at all.
Iran-linked groups have targeted industrial control systems before. On 23 July, a federal advisory we covered named the specific techniques used to break into programmable logic controllers, the small computers that directly operate physical machinery such as chemical pumps. Those controllers showed up in water facilities.
Should residents be worried?
Right now, no confirmed water-quality failures have been tied to these intrusions. That matters. Getting into a system and actually causing harm to water treatment are two very different steps.
The breadth of the targeting is the story. Seven states is not opportunistic scanning. This looks like a deliberate, sustained effort against infrastructure the US government classifies as critical, where disruption has direct consequences for public health.
Residents in the named states don't need to boil water or stockpile bottles based on current public information. If your local utility issues any advisory, follow it. Sign up for your water provider's alert system if one exists.
What does this mean for water utilities?
The operational takeaway is blunt: if your programmable logic controller or human-machine interface (the screen operators use to control equipment) is reachable from the open internet without multi-factor authentication, a login step requiring two separate forms of verification, you're a soft target.
Patch cycles that work for office software don't map onto industrial systems, and that gap is where these intrusions live. Any water utility still running internet-exposed control interfaces without multi-factor authentication should treat that as an active emergency, not a roadmap item.



