Between July 26 and 31, 2026, hackers took manual control away from water and wastewater utilities across U.S. states, Minnesota, Michigan, New Jersey, Georgia, and South Dakota among them, with more than 30 community systems hit in Minnesota alone. According to news, cyberattacks on U.S. water systems are suspected to be linked to Iran-backed hackers. Operators in Georgia's Clayton County Water Authority, serving 300,000 people near Atlanta, watched pressure drop and had to issue a boil-water advisory before service was restored within hours. In several cases, the hackers gained remote access to pumps, valves, and water pressure, though the cyberattacks have had no impact on drinking water, which has remained safe.
A hacking front calling itself CyberAv3ngers, an Iranian Revolutionary Guard Corps-linked group sanctioned by the US Treasury Department in February 2024, has since claimed the operation on Telegram, framing it as a warning rather than an attack: "our intention in attacking Minnesota was only to warn" of its abilities and its intention to retaliate against any country that poses a threat to Iran. That framing matters as it leaves us questioning whether an “actual” attack can take place.
Nothing about late July changes the war’s trajectory. No ransom was demanded, no contamination occurred, and outages were resolved within hours to days by reverting to manual operations. That’s precisely why the incident shouldn’t be read as an escalation in the conventional sense. It was enough to generate headlines and force emergency declarations in towns like Maple Plain, Minnesota, not enough to trigger the kind of infrastructure failure that would draw a proportionate U.S. military response. This is thus signaling while not war-fighting.
Formal attribution remains open, investigators are still collecting evidence, and the U.S. administration has publicly disputed Iranian involvement, with U.S. President Donald Trump initially blaming Minnesota state authorities directly rather than Tehran. But the pattern argument is strong enough to build an analysis on. Iranian-linked hackers have gone after U.S. power and water before. For example, in 2023, an Iranian-linked hacktivist group broke into and defaced industrial machines at a water facility in Aliquippa, Pennsylvania, manipulating components made in Israel to display anti-Israel messages during the Israel-Hamas war. Iranian cyber meddling against U.S. water infrastructure actually dates back to 2013, when Iranian hackers infiltrated the control systems of the Bowman Avenue Dam in Rye, New York, resulting in the indictment of seven Iranian nationals. The exploited pathway in July was the same one CyberAv3ngers used in 2023, third-party industrial controllers, often internet-connected for remote servicing, that broaden a single vulnerability into an attack surface spanning many municipalities using the same equipment. A group claiming credit, a documented decade-long lineage against the same sector, and tradecraft consistent with a known state-linked actor is not proof, but it’s a pattern.
The ceiling isn’t only set by what Iran can do, it’s set by how exposed the U.S. water sector already is. First, geographic reach. The jump from prior isolated incidents to a dozen states in under a week wasn’t a capability leap so much as a target-rich environment finally being tested at scale. The U.S. has roughly 150,000 to 170,000 water systems, the vast majority small, locally operated, and lacking dedicated IT staff, the exact profile CyberAv3ngers has systematically targeted since 2023. A 2024 U.S. Environmental Protection Authority (EPA) Inspector General report found critical or high-severity vulnerabilities across 97 systems serving roughly 26.6 million people, and the Government Accountability Office found EPA has struggled to identify the legal authority needed to mandate cyber risk management in the sector. A volunteer defense program built to help has reportedly reached only a fraction of the unprotected utilities. Structurally, there is no reason this stays at twelve states. It stayed at twelve because that’s as far as the operation was designed to go, not because thirteen was out of reach.
Second, sectoral reach. Water is a soft target because it’s a lightly regulated one. Power, by contrast, sits under mandator North American Electric Reliability Corporation (NERC) reliability standards with real enforcement teeth, a regulatory asymmetry that itself shapes where an adversary probes first. That’s a meaningful distinction because Iran testing water infrastructure isn’t necessarily evidence it can’t reach the grid, but it is evidence that water was the rational first move given the disparity in defensive maturity. The next logical test, if this campaign continues, is whichever critical-infrastructure subsector combines internet-connected legacy controllers with weak mandatory standards, ports, smaller electric cooperatives, and wastewater treatment are the likeliest candidates.
Third, state involvement. This is arguably already answered rather than hypothetical. CyberAv3ngers isn’t an independent hacktivist collective coincidentally aligned with Tehran’s interests, it’s IRGC-linked and Treasury-sanctioned, with tradecraft tracked by researchers across four escalating phases of activity since 2020. The “hacktivist front” model is precisely how states run deniable operations in the cyber domain as it is close enough to direct the target selection and timing, distant enough to avoid the attribution certainty that would force a response. The open question isn’t whether the state is involved, it’s whether Tehran chooses to formally own an operation like this in the future, which would itself be an escalation signal worth watching for.
Fourth, cyber as a missile substitute. Iran cannot put ordnance on U.S. soil without inviting a war. It can put a hacker inside a Minnesota water pump. As one former White House cyber official put it, this looks like a shot across the bow, and the framing is apt because a shot across the bow, by definition, is a demonstration of reach without commitment to impact. Cyber gives Tehran exactly what conventional force can’t, plausible deniability, reversible effects, minimal cost, and the ability to reach the continental U.S. directly.
Water was not picked because it is the best target. It was picked because it is the easiest one. So the real question is: what’s next on that list, and how bad would it be if they got there.
The power grid. This is the big one, and it’s not new. Back in 2013-2014, Iranian hackers broke into a U.S. power company called Calpine, which runs power plants in 18 states. They stole passwords and detailed engineering drawings of dozens of power plants, plans so detailed that experts said skilled hackers could have used them, along with other tools, to cut power to millions of homes. They never pulled that trigger. But the access was real, and it shows Iran has tried this before, not just water. Right now, a U.S. government warning (CISA) about this exact hacking group says plainly that they are going after several U.S. sectors at the same time, and the list includes the Energy Sector, not just water. So this isn’t a maybe. It’s already happening quietly, in the background, while water gets the headlines.
If Iran ever did manage to cause a real blackout, the consequences would be much bigger than anything water hacks have caused so far. A well-known study by Lloyd’s of London and Cambridge University looked at a scenario where malware knocks out a big piece of the East Coast power grid. Their estimate: a cyberattack causing outages and damage to power infrastructure could cost the U.S. economy up to $1 trillion in the worst case. Even in a more likely, smaller version of that scenario, a targeted attack could leave 15 states and 93 million people from New York City to Washington DC without power, with total economic damage between $243 billion and $1 trillion. And it’s not just about money going dark. The same report warns that in this kind of scenario, health and safety systems could start to fail, trade could slow as ports shut down, water supplies could be disrupted because electric pumps stop working, and transport could fall into chaos. To be fair, nobody thinks Iran is close to pulling this off today. Experts who study the U.S. grid say a full “Business Blackout”-style attack this large is still a scenario, not something that would be easy to make happen, and would take months of planning and specific technical access most groups don’t have. The Calpine case in 2013 is really the clearest proof point we have, and even then, Iran had the map but never used it. That gap between “got the access” and “actually did it” has lasted over ten years. That’s the important detail, not that they can’t reach the grid, but that so far they have chosen not to go all the way.
Pipelines and fuel supply. This is a softer target than the grid because a lot of pipeline equipment is old. About half of U.S. oil and gas pipelines are more than 50 years old, and roughly 75% of transmission lines are more than 25 years old, meaning they were built long before anyone thought about cybersecurity, and many still run on outdated software. Nobody has publicly tied Iran to a pipeline attack in the U.S. yet. But the type of weakness they’ve already shown they know how to exploit in water (old, simple systems connected to the internet) is exactly the type of weakness these pipelines have too.
Other possible targets. Iran has already shown, outside the U.S., that it’s willing to cause real, deliberate destruction when it decides to escalate, in 2012 it wiped 35,000 computers at Saudi Arabia’s state oil company in an attack called Shamoon. That tells us the mindset exists. Inside the U.S., Iran-linked hackers have also poked at banks and the stock exchange in the past, though without lasting damage. Ports and shipping are a newer worry, they run on the same kind of old, internet-connected control systems as water and pipelines, and a serious disruption there would slow down trade the same way the Lloyd’s study describes.
Accordingly, the takeaway is that Iran has already reached toward the power grid once, in a serious way, and current U.S. government warnings say they’re actively probing energy systems right now, in parallel with the water attacks. If they ever went further and caused a real blackout, the damage would be measured in hundreds of billions of dollars and would ripple into water, transport, and health systems too, a much bigger deal than anything seen so far. But the fact that Iran had real access to the grid over a decade ago and still hasn’t used it to cause a blackout says something important, this could be about Iran choosing not to cross that line yet than about Iran being unable to.
Cybersecurity and Infrastructure Security Agency (CISA). “IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities.” CISA.gov. 2023. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a.
Cybersecurity and Infrastructure Security Agency (CISA). “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.” CISA.gov. 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a.
Council on Foreign Relations. “A Cyberattack on the U.S. Power Grid.” CFR.org. Accessed August 18, 2026. https://www.cfr.org/reports/cyberattack-us-power-grid.
Cybersecurity Dive. “CISA, FBI Warn That Iran-Linked Hackers Are Expanding Target Set for Water, Energy.” CybersecurityDive.com. 2026. https://www.cybersecuritydive.com/news/cisa-fbi-iran-hackers-target-water-energy/826025/.
Environmental Protection Agency (EPA). “EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks.” EPA.gov. April 7, 2026. https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian.
TIME. “What to Know About the U.S. Water Systems Cyberattacks.” Time.com. August 2, 2026. https://time.com/article/2026/08/02/what-to-know-about-the-u-s-water-systems-cyberattacks/.
Tripwire. “Cyber Attack on the U.S. Power Grid Could Cost Economy More Than $1 Trillion, Report Says.” Tripwire.com. Accessed August 18, 2026. https://www.tripwire.com/state-of-security/cyber-attack-on-the-u-s-power-grid-could-cost-economy-more-than-1-trillion-report-says.
Comments