Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

Is it AI or human? Ottawa wants your ideas on how to boost transparency

July 31, 2026

Here’s the problem with putting an AI image generator in Google Earth

July 31, 2026

Next Point LLC Releases The Physician’s Exit Plan for Medical Practice Owners Considering Their Next Chapter

July 31, 2026

MAX Power Announces Closing of Sale of Arizona Lithium Asset

July 31, 2026

Chicano Hollywood Film Festival Returns to Pomona with Packed 5-Day Program

July 31, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Cyberattacks on water systems are growing in the U.S. — is Iran involved?
Health

Cyberattacks on water systems are growing in the U.S. — is Iran involved?

By News RoomJuly 31, 20265 Mins Read
Cyberattacks on water systems are growing in the U.S. — is Iran involved?
Share
Facebook Twitter LinkedIn Pinterest Email

Federal and state officials in the U.S. are investigating a series of cyberattacks on water and wastewater systems in at least seven states this week, with multiple media reports linking the attacks to Iran.

The FBI said Thursday that “some of that activity has degraded water operations,” which the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said has led to communities issuing boil water notices and switching to manual operations.

Those agencies and others are warning water facilities to disconnect vulnerable equipment from the internet — particularly programmable logic controllers (PLCs) — to prevent further attacks.

“These threat actors are targeting water entities of all sizes,” CISA said in an advisory Thursday.

“Even water organizations with mature cybersecurity processes should validate their external connections.”

The attacks come days after CISA updated and recirculated an advisory last week warning “Iranian-affiliated cyber actors” were exploiting PLCs across U.S. critical infrastructure, including water systems.

Warnings about Iranian cyber threats have increased since the U.S. and Israel launched the war on Iran in late February.

However, officials have not yet publicly linked this week’s water system attacks to a specific threat actor, and U.S. President Trump dismissed the possibility of Iranian involvement on Friday while disparaging leaders in Minnesota, one of the affected states.

Here’s what to know about what’s going on.

PLCs are internet-connected computer devices used to remotely control and monitor industrial operations.

The devices allow for geographically dispersed systems to be controlled from a central office, which can be particularly useful for large urban communities. For water systems, PLCs can be integrated into dams, pumping stations, treatment facilities and other infrastructure.

A November report from the Canadian Centre for Cyber Security on the threat to water systems notes, however, that “the more internet-connected assets an organization has, the larger the threat surface” that can be exploited by criminal hackers.

CISA’s July 22 advisory says Iranian-affiliated cyber actors have been using third-party programming software to gain remote access to specific PLCs, extract program data, and manipulate it to allow water systems to “enter unsafe conditions” without notifying operators, bypassing critical shutdown and alarm procedures.

The attacks appear to have begun in Minnesota on Sunday and Monday, according to a statement from the state’s IT services department (MNIT) on Tuesday.

The agency said in an update Thursday that more than 30 community water systems across Minnesota were targeted, but there have not been any requests from affected communities for residents to modify their drinking water use.

Receive the latest medical news and health information delivered to you every Sunday.

Get weekly health news

Receive the latest medical news and health information delivered to you every Sunday.

“In this situation, ‘impacted’ means investigators confirmed malicious activity involving a system’s technology,” the statement said. “It does not mean every affected community experienced a disruption to water service.”

CNN, citing a memo it obtained from Wisconsin’s Department of Natural Resources, reported officials in that state warned they had detected malicious cyber activity at their water facilities on Monday.

The FBI advisory did not name the seven states it says have reported cyberattacks since Monday.

It said the attacks involved changing IP addresses and passwords for water systems’ PLCs, “resulting in a loss of monitoring and control functionality.”

“Operational effects reported to the FBI have included loss of pressure and flooding,” the advisory says. “Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”

Thursday’s MNIT statement said Minnesota “has not attributed the activity to a specific actor,” noting investigators have yet to confirm every incident is connected but have identified “similarities.”

“We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor,” John Israel, Minnesota’s chief information security officer, said in the statement.

Multiple U.S. news outlets, including the New York Times, CNN and CBS News, citing federal and state sources familiar with the investigation, reported Thursday and Friday that Iran is believed to be involved.

The Water Information Sharing and Analysis Center (WaterISAC), which co-ordinates cybersecurity information for the U.S. water utility industry, confirmed Thursday the existence of a memo leaked to Wired that linked the Minnesota attacks to “Iran-affiliated” hackers.

That memo, according to Wired, cited information from the Minnesota Fusion Center, a state intelligence-sharing agency, saying the attacks were “aligned” with methods outlined in the CISA advisory first published in April and updated this month.

Asked about the Wired report during a cabinet meeting Friday, Trump pinned the blame for the cyberattack on Minnesota’s government, which the U.S. president has repeatedly attacked for its response to fraud allegations against immigrant communities accessing state funds.

“You know who’s behind it? Minnesota, because they’re grossly incompetent,” Trump told reporters. “I think the governor’s behind it. I don’t think there was an Iranian cyberattack. I think that Minnesota ought to get its act together.

“They like to say, ‘Oh, it was Iran,’” Trump continued. “Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

After Trump spoke, Minnesota Gov. Tim Walz posted on X that “Trump knows exactly who is responsible for this attack, and knows that other states were hit too.”

“This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran,” he wrote.

Walz further alleged that federal funding cuts to CISA have “left the U.S. exposed to cyber attacks,” while his state’s authorities were able to mitigate the water system attacks.

The FBI and CISA are urging all organizations that use PLCs to disconnect them from the public-facing internet and ensure remote modems connected to the systems are secured.

Passwords should be changed and strengthened, with additional access safeguards, such as firewalls, installed.

The agencies say manual overrides should also be maintained and practiced in the event of an incident.

The Canadian Cyber Centre report also contains several mitigation measures that organizations can take to secure their own PLC systems.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Are you underestimating mold-related illness? What U.S. study says

Health Canada granted injunction over unauthorized peptide retailer sales

4 out of 5 American toddler foods are ultra-processed, research says

Dr. Anthony Fauci invokes Fifth Amendment in U.S. Senate pandemic hearing

E-scooters driving ‘huge’ number of child injuries, doctors say: ‘Not toys’

Some psychiatric patients wait days in ER for hospital admission: data

Canadian emergency doctors leaving ‘broken’ industry, citing burnout: CMAJ

Cases of cyclosporiasis deserve attention but shouldn’t alarm, says Quebec doctor

2026 U.S. measles cases have passed record-breaking tally for all of 2025

Editors Picks

Here’s the problem with putting an AI image generator in Google Earth

July 31, 2026

Next Point LLC Releases The Physician’s Exit Plan for Medical Practice Owners Considering Their Next Chapter

July 31, 2026

MAX Power Announces Closing of Sale of Arizona Lithium Asset

July 31, 2026

Chicano Hollywood Film Festival Returns to Pomona with Packed 5-Day Program

July 31, 2026

Latest News

Pure Flix Familia To Sponsor Second Annual Chicano Hollywood Film Festival

July 31, 2026

Winnipeg mosque was likely shot at with pellet-style gun, police say

July 31, 2026

Cyberattacks on water systems are growing in the U.S. — is Iran involved?

July 31, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version