Seven States' Water Systems Hit by Cyberattacks Likely Tied to Iran — Scope Expands Beyond Minnesota
The water-sector campaign just got bigger. WIRED reports systems in seven US states hit by attacks likely tied to Iran — beyond the 30-plus Minnesota systems first disclosed. What every water utility should verify now, and what's still unnamed.
The water-sector story that started in Minnesota is now a seven-state one. On August 1, WIRED reported that water systems in seven US states have been hit by cyberattacks likely tied to Iran — a scope that runs well past the roughly 30 Minnesota community water systems that dominated the coverage a few days earlier.
That single number, one state to seven, changes how operators everywhere should read this week. What looked like a regional incident is now a pattern spread across the country, and the defensive work no longer belongs only to utilities near the Twin Cities. The attribution language matters too: reporting says likely tied to Iran, not confirmed as Iran's work, and that gap is doing real work in how officials are talking about the campaign.
What WIRED Reported
WIRED's account puts water and wastewater systems in seven US states in scope, with the activity likely tied to Iran. The FBI said utilities in at least seven states reported incidents involving programmable logic controllers — the small industrial computers that open valves, run pumps, and hold treatment set points. That framing lines up with the earlier CISA operational guidance, which described intruders modifying passwords to lock operators out of their own equipment and disconnecting PLCs by changing their IP addresses. The visible result on the ground: boil-water notices and utilities dropping back to manual operation.
One detail from the federal advisory stands out. Investigators flagged the incidents as unusual because no ransom was demanded. That is not how financially motivated crews behave. It fits disruption for its own sake, which is part of why the assessment points where it does — while stopping short of a firm call.
How a Minnesota Incident Became a National One in a Week
Follow the thread and the escalation is stark. It opened with more than 30 Minnesota community water systems reported hit, with the Iran-linked CyberAv3ngers named as a suspect. Then a leaked WaterISAC memo, first reported by WIRED, tied the activity to Iran and lined it up with CISA advisory AA26-097A. CISA followed with its blunt instruction to pull exposed PLCs off the public internet. Now the same reporting outlet says the footprint reaches seven states.
The specific seven states have not all been publicly named. Some individual reports have surfaced a couple of them — Minnesota, plus references to Michigan — but a full, confirmed list of all seven attributed to this campaign has not been published, and it is not clear that every affected utility has disclosed. Treat the count as reported and the roster as incomplete.
● HOW THE SCOPE GREW A Minnesota incident became a multi-state one over a single week. |
BASELINE — MINNESOTA 30+ Minnesota community water systems reported hit; CISA issued operational guidance to pull exposed PLCs offline. |
| ↓ |
NOW — SEVEN STATES WIRED reports water systems in seven US states hit by attacks likely tied to Iran — the specific states not all publicly named. |
Source: WIRED; CISA; prior CyberSignal reporting. |
What Every Water Utility Should Verify Now
Here is the useful part, and it is the same whether or not the attribution ever firms up. The reported tradecraft — exposed controllers, changed passwords, changed IP addresses — is common to small municipal systems everywhere, not just the ones already hit. If you run water or wastewater operations, this is the checklist to work through this week.
- Audit for internet-exposed PLCs and OT. Do an external-exposure review the way an outside observer would — the kind of look a Shodan or Censys search gives an attacker. Anything answering from a public IP is the first thing to pull back behind a firewall.
- Disable or segment remote-management interfaces. Web admin panels, vendor remote-support tools, and any management port reachable from the internet should be off or tightly segmented. If a controller does not need to be reachable remotely, it should not be.
- Rotate credentials on internet-facing OT. The reported activity involved changing passwords to lock operators out. Rotate now, store recovery credentials offline, and make sure a lockout does not also lock you out of recovery.
- Hunt for undocumented cellular modems and links. CISA flagged unexpected cellular connectivity. Physically walk the equipment and inventory every modem, radio, and out-of-band link against what should be there.
- Rehearse the manual-operations fallback. Boil-water notices and manual operation were the real-world outcome in Minnesota. Confirm staff can run treatment by hand, that the procedure is written down, and that someone has actually practiced it recently.
- Follow CISA's operational guidance. The advisory tied to this campaign is AA26-097A, and the CISA directive to disconnect exposed PLCs is the baseline. None of this waits on attribution.
My read: the smartest move a small utility can make today is the exposure review. Every other step depends on knowing what an outsider can already reach. If you do only one thing this week, make it that.
The Coordination Question
A seven-state footprint pulls in more players than a single-state one — the FBI and EPA on the federal side, state emergency managers, and dozens of individual utilities that may not know they share an adversary. The reporting does not spell out how that coordination is running, whether affected states are sharing indicators in near-real time, or where the seams are. For operators, the practical takeaway is not to wait for a tidy federal picture. Work your own checklist and share what you find through your existing channels, WaterISAC included.
Sitting over all of this is an unresolved public split on who is responsible. President Trump has publicly blamed Minnesota, while his own intelligence agencies assessed Iran as the likely actor — a disagreement we mapped earlier this week. It is not clear that split applies evenly across all seven states, or how it shapes the federal response. What is clear is that the defensive work does not depend on it resolving.
What's Still Unnamed
Three things are worth holding loosely. First, the full list of seven states has not been publicly confirmed, and it is unclear whether every affected utility has disclosed. Second, it is not established that CISA's public alert itself references the multi-state scope — the seven-state count comes through FBI statements and WIRED's reporting, and the campaign should not be treated as one tidy, officially bundled event. Third, the attribution remains likely tied to Iran, not confirmed, and reporting notes investigators are still weighing whether someone tried to look Iranian to stir tension.
The CyberSignal's assessment: the count matters less than the pattern. Seven states, one week, the same OT tradecraft, no ransom — that shape is the story, and it is enough to justify the exposure review on its own. We will update this piece as the states are named and as the attribution firms up or shifts.
Primary Documents
- WIRED: Security News This Week — 7 States' Water Systems Hit by Cyberattacks Likely Tied to Iran
- CISA Advisory AA26-097A (industrial control system / water-sector operational guidance)