Iranian Hackers Hit Water Systems in at Least 12 US States

New Jersey and Alabama are the latest to confirm attacks on water infrastructure. So far, no taps have run dry and no water has been contaminated, but the campaign is still expanding.

ThreatVectr Newsdesk· 3 min read
Aerial 16:9 view of a vast server room with long rows of illuminated blue and amber rack lights stretching to a vanishing point, emergency backup lighting casti
Share

Key points

  • At least 12 US states have had water or wastewater facilities targeted in a hacking campaign that began in late July 2025.
  • The FBI confirmed at least seven affected states as of July 30, 2025.
  • Attacks are linked to Iranian hackers and focus on industrial control systems made by Rockwell Automation.
  • No state has reported contaminated water or prolonged disruption to water services.
  • New York has not confirmed any attack but announced more than $9 million in grants to strengthen water-sector cybersecurity.

Somebody is working through America's water utilities one state at a time. New Jersey and Alabama have now joined Minnesota, Michigan, South Dakota, and Georgia in confirming that hackers targeted their water infrastructure in a campaign that kicked off in late July.

The full count sits at twelve states, though not all have been named publicly. SecurityWeek first tallied the scope of the campaign.

What exactly did the hackers do?

They went after industrial control systems, the computerised equipment that tells pumps, valves, and treatment processes what to do. In New Jersey, Cape May and Woodbine water systems were hit on July 27. Officials there said only phone systems were knocked offline. In Alabama, the Childersburg Water, Sewer and Gas system was attacked on the same day; hackers reached the industrial controls but water kept flowing normally.

Minnesota was the first state to go public, reporting that more than 30 water systems had their operational technology (OT), meaning the hardware and software that runs physical plant equipment, targeted. Wisconsin, Pennsylvania, and Washington have warned their water utilities without confirming confirmed attacks.

Should people worry about their tap water?

Not right now. Every utility that has come forward says drinking water is safe. Some operators shut down affected systems as a precaution, but disruptions were limited and brief.

The FBI confirmed at least seven targeted states as of July 30 and has not issued a public update since. The Cybersecurity and Infrastructure Security Agency (CISA), the federal body responsible for protecting critical infrastructure, has urged water operators to lock down their OT systems.

Who is behind this?

US officials and security researchers have linked the campaign to Iranian state-sponsored hackers. The attackers have focused on devices made by Rockwell Automation, one of the biggest suppliers of industrial control hardware, and possibly equipment from other major vendors.

Rockwell Automation makes the programmable controllers and monitoring software that smaller utilities often use to run treatment plants remotely. Hitting that equipment is not novel tradecraft. It is, at its core, the same kind of internet-exposed industrial device attack that researchers have documented for over a decade, just aimed squarely at a sector that has been slow to apply basic security hardening.

State Systems confirmed affected Date
Minnesota 30+ water systems Late July 2025
Michigan Confirmed, count not disclosed Late July 2025
South Dakota Confirmed, count not disclosed Late July 2025
Georgia Confirmed, count not disclosed Late July 2025
New Jersey Cape May, Woodbine July 27, 2025
Alabama Childersburg Water, Sewer and Gas July 27, 2025

If you are a customer of any small or mid-sized water utility, the practical advice is simple: watch for any notice from your provider about boil-water advisories. None have been issued in connection with these attacks, but that is the official channel utilities use when water safety is genuinely at risk.

© 2026 Threat Vectr