INTELBRIEF

August 7, 2026

Suspected Iranian Hack of U.S. Water Systems Sign of Grey Zone Capabilities

(AP Photo/Ellen Schmidt)

Bottom Line Up Front 

  • The cyberattacks targeting water systems in dozens of municipalities across at least seven states represent the latest string of suspected Iranian cyber operations against U.S. critical infrastructure.
  • The United States is ill-prepared to deal with the improving cyber capabilities of some of its chief adversaries, even though this outcome seemed inevitable.
  • Past cases of cyberattacks demonstrate that Iran relies on exploitable weaknesses to impose a cost on the United States and other adversaries without crossing the threshold that would normally prompt a direct kinetic confrontation.
  • Iran understands that the U.S. has the ability to quickly recover from such attacks, but Tehran’s goal most likely is to remind the U.S. that its great-power status does not make it invulnerable to Tehran.

The cyberattacks targeting water systems in dozens of municipalities across at least seven states represent the latest string of suspected Iranian cyber operations against U.S. critical infrastructure. Although the attacks did not compromise drinking water quality or result in prolonged service disruptions, they demonstrate how hostile actors can exploit vulnerabilities in decentralized infrastructure to create operational disruption, generate public anxiety, and test U.S. defense capabilities. U.S. intelligence agencies have assessed that attacks were likely carried out by Iranian cyber actors, marking the latest in Tehran’s use of cyber operations as asymmetric leverage, part of a broader grey zone portfolio. The attacks were reported in late July when operators at multiple water systems across Minnesota reported malicious activity predominantly surrounding technology used to remotely control or monitor equipment, known as programmable logic controllers (PLCs).

Iran and Iran-backed actors hacking into U.S. water systems and utilities is not a novel phenomenon. Iran, a middle power aspiring to regional hegemony, has, through the exploitation of software-defined systems, been able to remotely infiltrate a water provider in Aliquippa, Pennsylvania, in 2023, for example. Earlier during the Iran War, Iranian threat actor Handala launched a massive cyberattack that led to the crippling of internal devices at U.S. medical technology company Stryker. Iranian cyber meddling dates back well over a decade. In 2013, Iranian hackers infiltrated the control systems of the Bowman Avenue Dam in Rye, New York. As a result, seven Iranian nationals were indicted by the U.S. Department of Justice, charged with a range of cybercrimes. This is the profound asymmetry issue presented by the cyber domain: even significantly less capable military powers can find significant operational success, and at a distance, with minimal fear for secondary effects. At various points, Iranian hackers have been accused of attempting to hack the systems of the New York Stock Exchange, NASDAQ, Bank of America, J.P. Morgan Chase, and AT&T.

A report by The Soufan Center published earlier this year on software understanding compares the logic of Iranian cyber operations to the use of its proxy network: tools to conduct operations beyond its immediate vicinity, and at times an attempt to restore a modicum of deterrence. While targeting water systems or public/private utility infrastructure may seem like an odd target, the concerning part is the impunity with which Iranian hackers can breach sensitive systems, likely with an eye toward replicating similar actions on more complex targets. Past cases demonstrate that Iran relies on exploitable weaknesses, including industrial control systems (ICS), to signal presence and capabilities, and to seek to impose a cost on the United States and other adversaries without crossing the threshold that would normally prompt a direct kinetic confrontation. A secondary consequence is the psychological impact this has on the United States, its residents, and its decisionmakers, on the extent of Iran’s prepositioning in the country’s critical networks.

The United States is ill-prepared to deal with the improving cyber capabilities of some of its chief adversaries, even though this outcome seemed inevitable. Ten years ago, two Soufan Center analysts (both then at the RAND Corporation) wrote in Defense One about the consequences of the U.S. failing to establish cyberspace rules of engagement, improve and increase government-industry partnerships, and strengthen oversight and regulation of cyber-enabled technologies. Serena and Clarke argued: “With its nuclear program on hold, Iran is trying to bridge the conventional military gap between the country and its competitors by shifting some resources to develop cyber capabilities. Iranian hackers have progressed far beyond defacing websites and disrupting network services. They can now develop and use sophisticated software to probe for vulnerabilities, inject malware, and gain control of adversary systems.” Over the course of the past decade, despite American and Israeli efforts to counter Iranian cyber capabilities, Tehran has continued to invest resources in this capability.

The water sector presents an especially attractive target because of its antiquated operational technology. As municipalities have adopted remote monitoring tools and internet-enabled management systems, like PLCs, they have unintentionally increased their exposure to attacks. In many cases, these systems are exposed to the public internet and are protected by default or shared credentials, allowing malicious cyber actors to gain access through relatively simple techniques rather than relying on sophisticated malware or advanced cyber capabilities. Federal agencies like the Environmental Protection Agency (EPA) and the Cyber Security and Infrastructure Security Agency (CISA) have warned of these vulnerabilities in the past and advised utilities to strengthen their abilities to eliminate exposure to these types of attacks. Yet implementation has remained limited, especially considering the staffing and funding cuts to CISA in U.S. President Donald Trump’s second term following controversy between Trump and the former CISA director over the security of the 2020 U.S. presidential election. The recent string of attacks prompted renewed concerns among federal officials as Iran continues to employ its approach of asymmetric warfare as the war between the U.S. and Iran continues to evolve.

Cyber-attacks are one part of a larger hybrid strategy that Iran utilizes against its adversaries. In the past few months, Iran has adopted a range of grey zone strategies to target Western countries, seemingly taking a page out of the Russian playbook — Iran’s close partner. Tehran’s use of proxy organizations pairs well with its other asymmetric tools: influence campaigns on social media and the recruitment of petty criminals to carry out attacks or vandalism. The Iranian front group Harakat Ashab al-Yamin al-Islamia (HAYI), for instance, has recruited and paid locals across Europe to strike Jewish and Israeli-linked targets. In targeting U.S. water supply, the goal is not necessarily to cause mass disruption to critical infrastructure — Iran understands that the U.S. has the ability to quickly recover from such attacks. Most likely the goal is to remind the U.S., and the American public, that its great-power status does not make it invulnerable to Iran. This is a common thread across its foreign policy; in closing the Strait of Hormuz and holding the global economy hostage and in backing its Axis of Resistance, it attempts to advance the same narrative: that the U.S. and its partners are paper tigers.

SUBSCRIBE TO INTELBRIEFS