Federal Investigators Probe Expanding Critical Infrastructure Attack as Utilities Switch to Manual Operations
A sweeping cyber campaign targeting America’s drinking water infrastructure has spread across at least 12 U.S. states, triggering emergency responses from federal cybersecurity agencies and raising new concerns about the vulnerability of critical infrastructure to suspected state-backed hackers.
Although officials emphasize that drinking water remains safe, investigators say the attacks disrupted operational technology, disabled remote monitoring systems, and forced multiple utilities to operate manually after attackers gained unauthorized access to pumps, valves, and pressure-control equipment. Federal investigators are examining evidence pointing toward hackers linked to Iran, though no official public attribution has yet been announced.
America’s Water Infrastructure Under Digital Siege
What initially appeared to be isolated cybersecurity incidents has rapidly evolved into one of the broadest cyber campaigns ever directed against U.S. municipal water systems.
According to multiple officials familiar with the investigation, incidents have now been reported at least:
- Minnesota
- Michigan
- Georgia
- New Jersey
- South Dakota
- and several additional states still under investigation.
Federal agencies believe the campaign is coordinated rather than random, reflecting tactics previously associated with Iranian cyber operators targeting industrial control systems.
Minnesota Emerges as the Largest Target
Minnesota has become the epicenter of the campaign.
State officials confirmed that more than 30 community water systems experienced coordinated cyber intrusions during a concentrated wave of attacks.
Hackers reportedly compromised operational technology responsible for controlling:
- water pumps
- treatment facilities
- storage towers
- wastewater lift stations
- monitoring equipment
Several municipalities temporarily lost remote visibility into their systems before switching to manual operations.
Authorities stressed that no contamination of drinking water occurred and normal service was restored after emergency intervention.
Georgia Utility Forced to Issue Boil Water Advisory
One of the most visible consequences occurred in Georgia.
The Clayton County Water Authority, serving approximately 300,000 customers south of Atlanta, reported cyber activity that temporarily reduced water pressure throughout portions of its network.
The disruption prompted officials to issue a precautionary boil-water advisory while engineers restored system stability.
Water pressure recovered within hours, and testing later confirmed the drinking water remained safe.
How the Hackers Broke In
Investigators say the attackers focused on industrial control systems (ICS) rather than traditional IT networks.
Their objective was not stealing customer information, but manipulating operational technology that physically controls water infrastructure.
According to federal cybersecurity advisories, attackers:
- accessed internet-connected programmable logic controllers (PLCs)
- altered passwords
- disabled remote monitoring
- interrupted supervisory control systems
- forced utilities into manual control
In some cases, operators temporarily lost visibility over:
- pumps
- valves
- water pressure
- treatment processes
Fortunately, backup safety systems prevented widespread service failures.
Federal Agencies Launch Nationwide Response
The growing campaign prompted an unusually coordinated response from several U.S. agencies, including:
- FBI
- Cybersecurity and Infrastructure Security Agency (CISA)
- Environmental Protection Agency (EPA)
Their joint advisory warned utilities that threat actors had already remotely accessed operational technology in multiple states, resulting in a loss of monitoring and control capabilities.
Utilities were instructed too immediately:
- disconnect operational technology from the public internet where possible,
- implement stronger firewall protections,
- replace default passwords,
- enforce multi-factor authentication,
- review remote-access configurations,
- continuously monitor industrial control systems for abnormal activity.
Why Investigators Suspect Iran
Although the U.S. government has not formally attributed the attacks, investigators say the methods strongly resemble operations previously linked to the CyberAv3ngers, a hacking group associated with Iran’s Islamic Revolutionary Guard Corps (IRGC).
Security researchers note striking similarities, including:
- exploitation of internet-exposed PLCs,
- use of default credentials,
- targeting municipal utilities,
- disruption rather than destruction,
- focus on critical infrastructure.
Federal agencies have warned since early 2026 that Iranian-affiliated hackers have increasingly targeted U.S. water, wastewater, energy, and government infrastructure using these same techniques.
Long-Standing Warnings Become Reality
Cybersecurity experts say the attacks expose a structural weakness that has existed for years.
Many municipal water systems operate with:
- aging industrial equipment,
- limited cybersecurity budgets,
- small IT staffs,
- internet-connected legacy control systems.
Experts have repeatedly warned that even modestly skilled attackers can compromise these systems when remote-access services remain publicly exposed or protected by weak credentials.
No Evidence of Water Contamination
Despite the alarming nature of the attacks, officials emphasize an important distinction:
There is no evidence that drinking water quality has been compromised.
The cyber campaign primarily disrupted monitoring and operational control, not water treatment itself.
Safety mechanisms, manual oversight, and redundancy prevented attackers from altering chemical treatment or contaminating public supplies.
Growing Geopolitical Dimension
The incidents arrive amid heightened geopolitical tensions involving Iran and renewed warnings from U.S. intelligence agencies that cyber operations may increasingly serve as an asymmetric tool against Western infrastructure.
Earlier federal advisories warned that Iranian-affiliated actors were actively targeting operational technology across water, wastewater, energy, and government sectors to create disruptive effects inside the United States.
Critical Infrastructure Faces a New Era of Cyber Warfare
The attacks highlight an uncomfortable reality: modern infrastructure no longer requires physical sabotage to disrupt essential public services.
Water systems, electric grids, pipelines, transportation networks, and industrial facilities increasingly rely on interconnected digital control systems that, if poorly secured, can become attractive targets for state-backed cyber actors.
While this latest campaign caused limited operational disruption and no confirmed public health impacts, cybersecurity officials warn it may represent another chapter in the evolution of cyber conflict, where critical civilian infrastructure becomes a frontline target without a single missile being launched.





