"Invisible War" Targeting Water Infrastructure: The Shock of Cyber Attacks Spreading Across 7 U.S. States - Is Iran Behind It?

"Invisible War" Targeting Water Infrastructure: The Shock of Cyber Attacks Spreading Across 7 U.S. States - Is Iran Behind It?

Turning on the tap brings water. For many residents in the United States, this was an unquestionable part of daily life.

However, at the end of July 2026, it was revealed that the computers of water facilities, which support this everyday convenience, were simultaneously targeted from outside.

The first publicized center of the attack was Minnesota. According to state authorities, malicious access was confirmed in water systems of over 30 areas between July 26 and 27. Subsequently, it was found that nine water systems in Michigan were also affected. It is reported that the damage and related suspicious activities have spread to at least seven states.

At present, there is no evidence that harmful substances were mixed into the water or that residents drank dangerous water. Most of the affected facilities continued safe operations.

Nevertheless, the shock this incident has given to American society is significant.

The target was not just customer information or employee emails. It was the "operational technology" that operates pumps, adjusts water pressure, and monitors equipment used for water treatment.


More than 30 water systems were simultaneously targeted

Minnesota's IT department describes the incident as a "coordinated cyberattack."

Not all of the affected water systems experienced water outages or quality issues. The term "affected" means that unauthorized access or traces of malicious operations were confirmed against the operational technology of the facilities.

However, in some municipalities, actual operations were disrupted.

In Braham, Minnesota, with a population of about 1,700, the control functions of the water facility stopped, and wells and water treatment facilities temporarily could not operate. The city requested residents to refrain from using water. Until the equipment was restored, they maintained supply using the water remaining in the water tower.

In Plymouth, near Minneapolis, communication equipment related to water facilities experienced failures. On-site staff responded with manual operations and later restored communication functions.

In Michigan, after a federal warning about attacks on water facilities, similar suspicious activities were reported by municipalities within the state. State authorities stated that the nine affected systems were operating safely and that no public health issues were confirmed.

In other words, while this incident did not lead to large-scale water contamination or prolonged water outages, it showed the possibility that attackers could contact control systems supporting civic life.


What the attackers targeted: "Operational Technology"

Water facilities have systems for operating physical machinery, separate from the PCs and business networks used in general companies.

These systems handle starting and stopping pumps, adjusting water pressure, monitoring storage levels, managing chemical input, and opening and closing valves. Such mechanisms are called OT, or operational technology.

One of the central devices is a small control unit called a PLC. It receives information from sensors and issues instructions to machines according to pre-set programs.

They are used in various places in modern society, such as factories, water facilities, power plants, and transportation equipment.

If attackers infiltrate PLCs or surrounding remote management systems, they might not only steal data from screens but also change the operation of the equipment itself.

They could stop pumps, destabilize water pressure, disable alarms, disrupt processing steps, and rewrite operation histories to delay the discovery of abnormalities.

The extent of operations carried out will need to await future investigations. However, it is clear that attacks on water facilities are a threat of a different nature from usual information leaks.

Anomalies on computers can lead to real-world water outages, equipment damage, and public health hazards.


Why are local water facilities targeted?

The U.S. water infrastructure is not managed nationwide by a single large organization. Numerous organizations, such as cities, counties, small municipalities, and regional operators, each operate their own facilities.

Among them, there are many small facilities supporting areas with populations of just a few thousand.

In such facilities, it is difficult to employ cybersecurity professionals full-time. Limited budgets are prioritized for replacing aging water pipes, repairing pumps, managing water quality, and securing personnel.

As a result, cases arise where old control devices are used for long periods, initial passwords are not changed, or remote management functions are directly connected to the internet.

There are also circumstances where equipment cannot be stopped.

For a typical PC, restarting for updates is not difficult. However, in facilities supplying water 24/7, operations cannot be easily stopped for software updates or equipment replacement.

Adding new security features may also result in losing compatibility with older equipment.

For attackers, it can sometimes be easier to target remote control devices of small public facilities than highly defended networks of global companies.

Moreover, attacks on water systems can instill strong fear in citizens, even if the actual damage is limited.

Just spreading anxiety about whether the water is safe to drink or if there will be sudden outages can shake trust in society and government. This psychological effect is considered one reason why critical infrastructure is targeted.


Possible Iranian involvement, but no formal conclusion yet

Regarding this attack, U.S. authorities and experts are investigating the possibility of involvement by attackers related to Iran.

One reason is that groups believed to be Iranian have previously targeted U.S. water facilities and industrial control equipment.

In April 2026, U.S. government agencies issued a warning that attackers related to Iran were targeting internet-connected PLCs. In July, the warning was updated to indicate that the range of targeted equipment manufacturers and attack methods had expanded.

The targeted equipment, intrusion methods, and timing of this attack are also pointed out to have common characteristics with past Iran-related activities.

The absence of confirmed monetary demands also distinguishes this from typical ransomware crimes. If the attackers are not motivated by ransom, political intimidation, retaliation, information gathering, or inducing social chaos could be the motives.

Meanwhile, agencies including the FBI have not publicly identified the perpetrators.

In cyberattacks, it is possible to route through third-party devices or mimic the methods of other groups. It is difficult to immediately identify the state or organization behind an attack based solely on the programs used or communication destinations.

While there are reasonable grounds to suspect a connection with Iran, at this stage, it should not be treated as a confirmed fact that "Iran executed it."

This caution is not just a matter of words. Determining national attribution can lead to diplomacy, sanctions, retaliatory measures, and, in some cases, military action.


Political issue sparked by President Trump's remarks

While technical investigations continue, the incident rapidly transformed into a political issue.

When asked by reporters about Iran's involvement, President Trump denied that view and suggested that Minnesota was responsible. He criticized the state's response capabilities and Governor Tim Walz but did not provide evidence to support his claims.

In response, Governor Walz posted on X, arguing that the President knows who is responsible for the attack and should be aware that other states were also affected. He claimed, "This is the face of modern warfare," and criticized the administration for weakening the federal government's cyber defense system.

Under normal circumstances, blocking attack routes, restoring affected facilities, and sharing information with water operators nationwide should be the top priorities.

However, the focus of the debate began to shift not only to "who attacked" but also to "who bears political responsibility" due to the attention drawn by the conflict between the President and the state governor.

In responding to cyberattacks, blaming the organization that disclosed the damage could lead to new dangers.

If the atmosphere spreads that reporting damage results in political attacks, municipalities and companies may start hiding intrusions. If information sharing is delayed, attacks using the same methods could expand to other facilities.

The information from Minnesota, which first detected and disclosed the anomaly, may have led to inspections and damage discovery by other states.


Three reactions spread on social media

 

The incident was widely shared on X, Bluesky, Facebook, Reddit, and other platforms. However, posts on social media do not represent the entire public opinion and should be viewed as trends observable from individual public posts.

The first noticeable reaction was anxiety about targeting living infrastructure.

The term "attack on water facilities" led to a series of posts worrying about water contamination or poison mixing. On the other hand, there were voices cautioning against excessive fear and the spread of unverified information, stating that "system intrusion" is not the same as "drinking water contamination."

At present, there is no evidence indicating that water has become dangerous, and each municipality is issuing information to residents as needed. In emergencies, it is important to check official announcements from municipalities and water operators rather than speculations on social media.

The second reaction was calls for investment in critical infrastructure.

Posts from security and congressional personnel positioned the attack as a "wake-up call," suggesting that restrictions on remote connections, the introduction of multi-factor authentication, changes to initial passwords, network separation, and staff training should be urgently advanced.

Some experts pointed out that instead of focusing only on specific manufacturers' devices, the operation itself of leaving control devices exposed on the internet or unused remote connections should be improved.

The third reaction was intense political confrontation over President Trump's remarks.

From the side criticizing the administration, voices were raised that it is inappropriate to blame the affected state while federal agencies are investigating the possibility of foreign forces.

Meanwhile, from those supporting the administration, opinions were seen that municipalities should have thoroughly ensured equipment safety management before foreign attacks.

Some posts called for a cautious stance regarding Governor Walz's strong claims, stating that there is insufficient evidence to determine attribution.

On social media, discussions tend to become a binary choice between "Iran's attack" or "state's management failure." However, in reality, the possibility of foreign attacks and facility vulnerabilities can coexist.

The fact that the intruding side has primary responsibility and the need to improve defense posture are not contradictory.


The biggest issue is not "a single attack"

It is important that no significant issues arose regarding the safety of water this time. However, this alone does not allow the incident to be evaluated as small-scale.

It is not yet known whether the attackers failed to achieve their goals, aimed for limited chaos from the start, or if it was reconnaissance in preparation for a larger attack.

In intrusions into control systems, attackers do not necessarily stop equipment immediately. They may investigate internal structures, collect authentication information, and leave connection routes for future use.

A tactic of securing intrusion routes during peacetime and using them all at once when international tensions rise is also conceivable.

The issue is not just with water.

Similar remote control devices are used in power, oil, gas, transportation, manufacturing, food, and medical facilities. Attack methods effective in one industry could be adapted to another.

The important thing is not just to pursue the nationality of the attackers but to create a system that can maintain citizen services even if intrusions occur.

Disconnect remote control devices from external networks. Introduce strong authentication. Switch to manual operation in case of abnormalities. Share threat information among facilities. Provide technicians and funds to small municipalities.

Furthermore, it is necessary to understand which equipment is connected to which networks and who can access them. Surprisingly, it is not uncommon for organizations themselves to be unable to grasp the full picture of connected devices.


Protecting water is protecting trust in society

This attack shows that cyber warfare is no longer just a problem for the military or intelligence agencies.

The entry point for the attack was not a massive military facility. It was the control devices of small municipalities delivering water to local residents daily.

Without destroying advanced weapons, instilling fear in essential services can shake trust in the state and administration.

Fortunately, there is currently no information indicating widespread danger to U.S. drinking water. On-site staff manually operated equipment, restored communications, and maintained water supply.

However, there is no guarantee that the next attack will have the same outcome.

Identifying the attackers and holding them accountable is necessary. At the same time, water operators must be prepared to minimize damage, assuming they will be attacked.

Safe water supports not only hygiene and health but also trust in cities, industries, healthcare, firefighting, and society as a whole.

The incident highlighted is not a simple computer problem.

It is a national-scale challenge of how to continue protecting the everyday reality of "safe water from the tap" in the digital age.


Source URL

The New York Times: Key information about the attack spreading to at least seven states, possible Iranian involvement, and President Trump's remarks
https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-systems.html

Minnesota IT Services: Primary information from the state government announcing that over 30 regional water systems were targeted on July 26-27
https://mn.gov/mnit/media/blog/?id=38-761869

AP News: Reports on the situation in nine systems in Michigan, Braham, and Plymouth, FBI investigations, and safe operations of each facility
https://apnews.com/article/cyberattack-minnesota-water-systems-77d52a1d7356e608500a1ddb0ec373a6

Reuters: Reports on the timing of the attack in Minnesota, the absence of a formal attribution decision, and attacks targeting PLCs and federal warnings
##HTML_TAG