
Iranian-linked cyberattacks on US water systems expand to 12 states

A suspected Iranian-linked cyber campaign targeting US water and wastewater systems has expanded this week, with incidents reported across at least 12 states, including Minnesota, Michigan, Georgia, New Jersey and South Dakota. The attacks have targeted operational technology (OT), including programmable logic controllers (PLCs) used to monitor and control treatment and distribution processes.
In Minnesota, more than 30 community water systems were affected, with some operators losing remote access and reverting to manual operations; in Georgia, a utility briefly lost water pressure and issued a precautionary boil-water notice before restoring service. US authorities have not formally attributed the wider campaign to Iran, but the activity follows a 2023 campaign by the Iranian-linked group CyberAv3ngers, which compromised an internet-connected PLC at a Pennsylvania water authority.
At the time, CISA noted that the NCSC had separately observed related PLC targeting activity within the UK itself. The current campaign therefore highlights a recurring OT vulnerability with direct relevance to UK water-sector resilience.