Source: Shutterstock
Products are selected by our editors, we may earn commission from links on this page.
Hackers did not just look around inside America’s water systems. In several cases, they actually took the wheel, remotely controlling real pumps and valves. Officials say cyberattacks possibly linked to Iran-backed hackers have now hit water systems in at least a dozen states. So far, drinking water has stayed safe. The fact that outside hackers reached the controls at all is exactly what has officials worried.
A dozen states is a wide footprint for any single wave of cyberattacks. Sources familiar with the matter told CBS News that at least 12 states have reported incidents possibly tied to Iran-backed hackers. Confirmed states so far include Michigan, Minnesota, Georgia, New Jersey and South Dakota. That spread suggests this was not one isolated break-in, but a broader pattern of attempts across multiple utility systems.
Minnesota alone accounts for a striking share of the reported activity. More than 30 separate community water systems across the state were impacted, according to earlier CBS News reporting. That number represents dozens of individual utilities, each responsible for delivering safe water to its own local community, all showing signs of the same kind of unauthorized cyber activity within a similar window of time.
Georgia offers the clearest real-world example of what these attacks can actually do. The Clayton County Water Authority, which serves 300,000 customers in the Atlanta area, experienced cyber activity last month that caused a real drop in water pressure. Officials had to issue a boil water advisory as a precaution. Service was restored within hours, but the incident showed these intrusions can trigger genuine operational consequences.
Losing remote control of a water system forces operators back into an older, slower way of working. Some utilities lost their critical remote control capabilities entirely, requiring staff to switch over to manual operation just to keep things running. In several cases, hackers gained direct remote access to pumps, valves and water pressure settings, the exact controls operators normally rely on to manage a system safely.
Federal agencies issued a formal warning once the pattern became clear across multiple states. On July 30, the FBI, Environmental Protection Agency and Cybersecurity and Infrastructure Security Agency jointly warned that cyber threat actors had remotely accessed online infrastructure for water and wastewater systems in at least seven states. According to the advisory, the intrusions were “resulting in a loss of monitoring and control functionality” at affected facilities.
That same federal warning came with specific advice for water agencies trying to protect themselves. Officials recommended disconnecting operating programs from the internet entirely, along with strengthening password protections and firewalls across affected systems. Those steps sound basic, but for utilities that had left certain controls internet accessible, closing that gap quickly became an urgent, hands-on priority rather than a routine maintenance item.
Despite everything hackers managed to access, one crucial fact has not changed throughout this entire situation. According to officials, the cyberattacks have had no impact on drinking water itself, which has remained safe for residents in every affected area. Pressure drops and lost remote controls created real operational headaches, but the actual water reaching people’s taps was never contaminated or made unsafe to drink.
Investigators have a working theory about who is behind these attacks, though nothing has been officially confirmed yet. Federal investigators suspect Iran-backed hackers are responsible, based on the pattern and tactics observed across the affected states. However, they have not made any formal attribution at this point. Cybersecurity investigations involving foreign actors often take considerable time before officials are willing to name a specific group publicly.
This is not the first time this exact kind of attack has targeted American water infrastructure. The tactics closely resemble a 2023 campaign by CyberAv3ngers, a group linked to the Iranian Revolutionary Guard, which broke into water system controllers by simply using default passwords nobody had bothered to change. Years later, the same basic vulnerability appears to be opening the door for hackers all over again.
Source: Shutterstock Jennifer Lawrence has officially entered the Instagram era, but she came with terms…
Source: Commons Wikimedia WalletHub's 2026 Happiest States in America ranking evaluated all 50 states across…
Source: Shutterstock Ralph Lauren, 86, staged the unofficial opening show of New York's fashion season,…
Source: Commons Wikimedia T.J. Maxx is closing several locations across the U.S. in 2026, including…
Source: Shutterstock Sequins. Feathers. Rhinestones. Sometimes, even a curtain rod. Bob Mackie never seemed interested…
Source: Shutterstock For decades, chemical relaxers promised straighter hair. Now L’Oréal is facing a very…