Hackers likely linked to Iran have targeted public drinking-water and wastewater-treatment systems across the U.S. [1, 2].

These attacks highlight critical vulnerabilities in the nation's essential infrastructure, where lax security could potentially allow foreign actors to disrupt basic utility services.

Authorities said the wave of cyberattacks has persisted since the beginning of summer 2024 [1]. The breaches have been reported in 12 states [3]. Officials said Iranian actors are the likely culprits behind the intrusions [1, 2].

The scale of the potential target pool is vast. There are 152,000 public drinking-water systems in the U.S. [1]. Additionally, the country operates 16,000 wastewater-treatment facilities [1].

Investigators said the success of these attacks is rooted in years of under-investment in critical infrastructure [1, 2]. Many of these systems rely on outdated technology and lack the robust security protocols necessary to repel sophisticated foreign state actors [1, 2].

While the attacks have been widespread, authorities have focused on the systemic weakness of these utilities. The reliance on legacy systems creates entry points that hackers can exploit to gain access to control systems [2]. This vulnerability persists across both small municipal plants, and larger regional facilities [1].

Hackers likely linked to Iran have targeted public drinking-water and wastewater-treatment systems.

The targeting of water utilities represents a shift toward attacking 'soft' critical infrastructure that often lacks the cybersecurity budgets of the energy or financial sectors. Because these systems are decentralized and frequently managed by local governments with limited resources, they provide a low-risk, high-impact vector for foreign adversaries to signal capability or cause localized chaos.