Suspected Iranian hackers targeted water and wastewater utility companies across seven U.S. states starting July 27, 2026 [1], [2].

These attacks represent a direct threat to critical infrastructure, as the breaches degraded essential water operations and exposed vulnerabilities in public utility security [1], [2].

Federal authorities are investigating the incidents, which have affected seven utility companies [1]. The attacks began on July 27, 2026 [1], and continued through the past week [1], [2]. The breaches targeted both water and wastewater systems, creating operational disruptions across multiple jurisdictions [1], [2].

Investigators said the actors are linked to Iranian hacking threats [1], [2]. The nature of the attacks suggests a coordinated effort to penetrate critical infrastructure systems that provide essential services to the public, a tactic often associated with state-sponsored actors [2].

While the full extent of the operational degradation is still being assessed, the scope of the attacks across seven different states indicates a wide-reaching campaign [1]. Officials said they continue to monitor the systems to ensure water safety and restore full functionality to the affected facilities [2].

Suspected Iranian hackers targeted water and wastewater utility companies across seven U.S. states.

The targeting of water and wastewater systems signals a shift toward attacking the physical necessities of daily life. By degrading utility operations, these actors demonstrate the ability to disrupt essential services, highlighting a critical need for enhanced cybersecurity protocols within municipal infrastructure to prevent potential public health crises.