Pull to refresh
Logo
Iran-linked hackers probe US drinking-water systems in multi-state wave

Iran-linked hackers probe US drinking-water systems in multi-state wave

Force in Play

Michigan and Minnesota lead a string of states reporting intrusions into internet-connected water controls during the 2026 US-Iran conflict

5 days ago: Count reaches at least 12 states

Overview

The tap water still runs clean in Lansing, Michigan. But the machines that keep it that way were being poked at by hackers. On August 1, Michigan officials said nine municipal water systems, including the Lansing Board of Water and Light, had been targeted in coordinated cyberattacks that US intelligence ties to Iran.

The Michigan disclosure came a day after Minnesota reported more than 30 similar intrusions. Within a week the count grew to at least a dozen states. Attackers went after the internet-connected controllers that run pumps, valves, and water pressure. No one has been sickened and no service has stopped, but the FBI now treats the campaign as state-linked pressure on US infrastructure during an active conflict with Iran.

Why it matters

If a foreign government can reach the controls behind your tap, the line between a distant war and your kitchen sink gets thin.

Questions about this story

No questions yet — be the first to ask.

Key Indicators

9
Michigan water systems targeted
Includes the Lansing Board of Water and Light, disclosed August 1.
30+
Minnesota systems hit days earlier
Cities including Plymouth, South St. Paul, Maple Plain, and Braham confirmed intrusions.
12
States reporting attacks
By early August the FBI was probing incidents across at least a dozen states.
0
Confirmed drinking-water impacts
Officials say water has stayed safe, though some utilities lost remote monitoring.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 4 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

April 2026 August 2026

7 events Latest: 5 days ago
Tap a bar to jump to that date
  1. Georgia and others join the list

    Incident

    Georgia and additional states report intrusions, with some activity degrading water operations and forcing manual control.

  2. Michigan reports nine systems hit

    Incident

    Michigan discloses nine targeted water systems, including the Lansing Board of Water and Light. The FBI says at least seven states were probed.

  3. Minnesota water systems breached

    Incident

    More than 30 Minnesota municipal water systems are hit in a coordinated intrusion targeting remote monitoring and control devices.

  4. Advisory widened to more hardware

    Warning

    CISA updates AA26-097A, expanding the named targets from Rockwell Automation to Schneider Electric and Siemens controllers.

  5. CISA warns of Iranian controller attacks

    Warning

    CISA publishes advisory AA26-097A on Iranian-affiliated actors exploiting internet-connected controllers across US critical infrastructure.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

November 2023

Aliquippa water authority hack (2023)

The CyberAv3ngers group breached Israeli-made Unitronics controllers at the Municipal Water Authority of Aliquippa, Pennsylvania, and other US sites. The screens showed an anti-Israel message. Operators switched a booster station to manual control while they responded.

Then

No water quality was affected, but the breach prompted federal warnings to hundreds of utilities using the same devices.

Now

It established water controllers as a favored target for Iran-linked hackers and set the template for the 2026 wave.

Why this matters now

The same group and the same class of exposed controllers are at the center of the 2026 campaign, now on a far larger scale.

February 2021

Oldsmar water plant intrusion (2021)

An intruder gained remote access to a water treatment plant in Oldsmar, Florida, and briefly raised the setting for sodium hydroxide to a dangerous level. A plant operator watching the screen reversed it within minutes.

Then

No contaminated water reached the public, and the case became a national example of how thin the safety margin can be.

Now

It drove new federal attention to remote-access security at small water utilities that often lack dedicated cyber staff.

Why this matters now

It shows the worst-case path the 2026 intrusions have not taken: a hacker reaching the chemistry that keeps water safe.

December 2015

Ukraine power grid attack (2015)

Hackers linked to Russia cut power to roughly 230,000 people in western Ukraine by seizing control of grid operators' systems. Operators watched cursors move on their own screens and had to restore power by hand.

Then

Electricity returned within hours, but it was the first confirmed cyberattack to take down a power grid.

Now

It proved a state could use code to cause physical infrastructure failure, reshaping how governments defend utilities.

Why this matters now

It is the benchmark for what state-linked intruders can do once they move from probing controls to operating them.

Sources

(8)