Iran-linked hackers probe US drinking-water systems in multi-state wave
Force in PlayMichigan and Minnesota lead a string of states reporting intrusions into internet-connected water controls during the 2026 US-Iran conflict
5 days ago: Count reaches at least 12 statesNew here? Follow stories to track developments over time. Create a free account to get updates when stories you care about change.
Overview
The tap water still runs clean in Lansing, Michigan. But the machines that keep it that way were being poked at by hackers. On August 1, Michigan officials said nine municipal water systems, including the Lansing Board of Water and Light, had been targeted in coordinated cyberattacks that US intelligence ties to Iran.
The Michigan disclosure came a day after Minnesota reported more than 30 similar intrusions. Within a week the count grew to at least a dozen states. Attackers went after the internet-connected controllers that run pumps, valves, and water pressure. No one has been sickened and no service has stopped, but the FBI now treats the campaign as state-linked pressure on US infrastructure during an active conflict with Iran.
Why it matters
If a foreign government can reach the controls behind your tap, the line between a distant war and your kitchen sink gets thin.
Questions about this story
No questions yet — be the first to ask.
Key Indicators
Voices
Curated perspectives — historical figures and your fellow readers.
Play
Exploring all sides of a story is often best achieved with Play.
Higher or Lower
A number from this story, against one from elsewhere in the news — guess which is bigger, then keep the chain going. 5 rounds, 3 strikes; a miss costs a strike and resets your streak.
Keyboard: ↓/L lower · ↑/H higher
0 points — sign up to put that on the leaderboard.
Timeline
Order five events from this story, oldest at top. Each in the right slot scores 1 — neighbours within one slot count too. Your previous result — green ✓ for exact slots, yellow ~ for off by one. Cards now in true chronological order.
Sign up to save your score and track a streak across stories.
Connections
Sixteen names from the news. Find the four hidden groups of four. Four mistakes max.
Sign up to keep a daily streak — a new puzzle lands every day.
Exit debate?
Your progress in this debate will be lost.
- 1 Two AI personas square off on this story.
- 2 You predict who'll win each round — correct picks earn XP.
- 3 One crossfire question is yours to fire. Pick it carefully.
Couldn't generate a topic
Select Your Champions
Choose one persona for each side of the debate
DEBATE TOPIC
Choose personas with different perspectives for a more dynamic debate.
Select debater for this side:
No debate personas available right now.
Select debater for this side:
No debate personas available right now.
Who's Got This Round?
Make your prediction before the referee scores
The referee scores both sides on
Round Results
Set the Crossfire
Pick the question both personas must answer in the final round
Debate Oracle! You called every round!
Sharp Instincts! You know your debaters!
The Coin Flip Strategist! Perfectly balanced!
The Contrarian! Bold predictions!
Inverse Genius! Try betting the opposite next time!
XP Breakdown
Prediction History
People Involved
Organizations Involved
An Iran-linked hacking persona that specializes in breaking into the industrial controllers behind water and energy systems.
The FBI is coordinating the multi-state investigation into who breached the water controllers and why.
CISA is the federal agency that warns critical-infrastructure operators about active cyber threats and how to blunt them.
A publicly owned Michigan utility named among the nine systems targeted in the state.
Timeline
April 2026 August 2026
-
Count reaches at least 12 states
Latest InvestigationThe FBI is now probing suspected Iran-linked water intrusions across at least a dozen states, including New Jersey and South Dakota.
-
Georgia and others join the list
IncidentGeorgia and additional states report intrusions, with some activity degrading water operations and forcing manual control.
-
Michigan reports nine systems hit
IncidentMichigan discloses nine targeted water systems, including the Lansing Board of Water and Light. The FBI says at least seven states were probed.
-
Investigators point to Iran
InvestigationA preliminary US assessment concludes Iranian hackers were probably behind the Minnesota intrusions. The FBI warns utilities nationwide.
-
Minnesota water systems breached
IncidentMore than 30 Minnesota municipal water systems are hit in a coordinated intrusion targeting remote monitoring and control devices.
-
Advisory widened to more hardware
WarningCISA updates AA26-097A, expanding the named targets from Rockwell Automation to Schneider Electric and Siemens controllers.
-
CISA warns of Iranian controller attacks
WarningCISA publishes advisory AA26-097A on Iranian-affiliated actors exploiting internet-connected controllers across US critical infrastructure.
Historical Context
3 moments from history that rhyme with this story — and how they unfolded.
Aliquippa water authority hack (2023)
The CyberAv3ngers group breached Israeli-made Unitronics controllers at the Municipal Water Authority of Aliquippa, Pennsylvania, and other US sites. The screens showed an anti-Israel message. Operators switched a booster station to manual control while they responded.
No water quality was affected, but the breach prompted federal warnings to hundreds of utilities using the same devices.
It established water controllers as a favored target for Iran-linked hackers and set the template for the 2026 wave.
The same group and the same class of exposed controllers are at the center of the 2026 campaign, now on a far larger scale.
Oldsmar water plant intrusion (2021)
An intruder gained remote access to a water treatment plant in Oldsmar, Florida, and briefly raised the setting for sodium hydroxide to a dangerous level. A plant operator watching the screen reversed it within minutes.
No contaminated water reached the public, and the case became a national example of how thin the safety margin can be.
It drove new federal attention to remote-access security at small water utilities that often lack dedicated cyber staff.
It shows the worst-case path the 2026 intrusions have not taken: a hacker reaching the chemistry that keeps water safe.
Ukraine power grid attack (2015)
Hackers linked to Russia cut power to roughly 230,000 people in western Ukraine by seizing control of grid operators' systems. Operators watched cursors move on their own screens and had to restore power by hand.
Electricity returned within hours, but it was the first confirmed cyberattack to take down a power grid.
It proved a state could use code to cause physical infrastructure failure, reshaping how governments defend utilities.
It is the benchmark for what state-linked intruders can do once they move from probing controls to operating them.
