Iranian Hackers Hit Water Systems in at Least 12 US States
New Jersey and Alabama are the latest to confirm attacks on water infrastructure. So far, no taps have run dry and no water has been contaminated, but the campaign is still expanding.

Key points
- At least 12 US states have had water or wastewater facilities targeted in a hacking campaign that began in late July 2025.
- The FBI confirmed at least seven affected states as of July 30, 2025.
- Attacks are linked to Iranian hackers and focus on industrial control systems made by Rockwell Automation.
- No state has reported contaminated water or prolonged disruption to water services.
- New York has not confirmed any attack but announced more than $9 million in grants to strengthen water-sector cybersecurity.
Somebody is working through America's water utilities one state at a time. New Jersey and Alabama have now joined Minnesota, Michigan, South Dakota, Georgia and others in confirming that hackers targeted their water infrastructure in a campaign that kicked off in late July.
The full count sits at twelve states, though not all have been named publicly. SecurityWeek first tallied the scope of the campaign.
What exactly did the hackers do?
They went after industrial control systems, the computerised equipment that tells pumps and treatment processes what to do. In New Jersey, Cape May and Woodbine water systems were hit on July 27. Officials said only phone systems were knocked offline. Alabama's Childersburg water system was attacked the same day; hackers reached the industrial controls but water kept flowing normally.
Minnesota was the first state to go public, reporting that more than 30 water systems had their operational technology (OT), meaning the hardware and software running physical plant equipment, targeted. Wisconsin, Pennsylvania and Washington have warned their water utilities without confirming attacks.
Should people worry about their tap water?
Not right now. Every utility that has come forward says drinking water is safe. Some operators shut down affected systems as a precaution, but disruptions were limited and brief.
As of July 30 the FBI had confirmed at least seven targeted states, and neither it nor CISA, the federal body responsible for protecting critical infrastructure, has issued a public update since. CISA has urged water operators to lock down their OT systems.
Who is behind this?
US officials and security researchers have linked the campaign to Iranian state-sponsored hackers. Threat Vectr has followed the Iranian targeting of industrial systems since our 23 July story on the federal advisory that named specific techniques used against programmable logic controllers, and our 3 August report confirmed that Minnesota bore the first confirmed wave.
The attackers have focused on devices made by Rockwell Automation, one of the biggest suppliers of industrial control hardware, and possibly equipment from other major vendors. Rockwell makes the programmable controllers that smaller utilities often use to run treatment plants remotely. Hitting internet-exposed industrial devices isn't novel tradecraft. It's the same class of attack researchers have documented for over a decade, just aimed at a sector that's been slow to apply basic security hardening. The more unsettling detail, as our 4 August story laid out, is that attackers may have left with the only complete copy of control logic some operators ever had.
| State | Systems confirmed affected | Date |
|---|---|---|
| Minnesota | 30+ water systems | Late July 2025 |
| Michigan | Confirmed, count not disclosed | Late July 2025 |
| South Dakota | Confirmed, count not disclosed | Late July 2025 |
| Georgia | Confirmed, count not disclosed | Late July 2025 |
| New Jersey | Cape May, Woodbine | July 27, 2025 |
| Alabama | Childersburg water system | July 27, 2025 |
If you're a customer of a small or mid-sized water utility, watch for boil-water advisories from your provider. None have been issued in connection with these attacks, but that's the official channel utilities use when water safety is genuinely at risk.



