Cyberattacks targeting water systems in dozens of municipalities across at least seven US states have highlighted a growing vulnerability in American critical infrastructure and the expanding use of cyber operations by Iran as a tool of asymmetric pressure.
The attacks, reported in late July, involved malicious activity at multiple water systems in Minnesota, primarily affecting technology used to remotely monitor or control equipment known as programmable logic controllers (PLCs). Although the incidents did not compromise drinking water quality or cause prolonged service disruptions, they demonstrated how hostile actors can exploit weaknesses in decentralised infrastructure to create operational disruption, generate public anxiety and test the capabilities of US defences.
US intelligence agencies have assessed that Iranian cyber actors were likely responsible. The Soufan Center, which analysed the incidents, described them as the latest suspected Iranian cyber operations against US critical infrastructure and placed them within Tehran’s broader use of cyber operations as asymmetric leverage.
The incidents also illustrate a broader problem: Iran has repeatedly demonstrated an ability to exploit vulnerabilities in systems connected to the internet without possessing the conventional military capabilities of the United States. For Tehran, cyber operations provide a means of imposing costs on adversaries while avoiding the threshold that would normally trigger a direct military confrontation.
Iranian activity against American infrastructure is not new. In 2023, Iranian and Iran-backed actors remotely infiltrated a water provider in Aliquippa, Pennsylvania, by exploiting software-defined systems. During the Iran War, Iranian threat actor Handala launched a major cyberattack that crippled internal devices at US medical technology company Stryker.
Iranian cyber activity against the United States dates back more than a decade. In 2013, Iranian hackers infiltrated the control systems of the Bowman Avenue Dam in Rye, New York. Seven Iranian nationals were subsequently indicted by the US Department of Justice on a range of cybercrime charges. Iranian hackers have also, at various points, been accused of attempting to target the systems of the New York Stock Exchange, NASDAQ, Bank of America, J.P. Morgan Chase and AT&T.
The Soufan Center has argued that the logic behind Iran’s cyber operations resembles the use of its proxy network: both allow Tehran to project influence beyond its immediate geographical reach while seeking to restore a degree of deterrence. The significance of attacks on water systems, therefore, extends beyond the immediate disruption they cause.
The concern is that relatively simple weaknesses in industrial control systems could provide access to sensitive infrastructure and potentially allow hostile actors to demonstrate capabilities that might later be applied against more complex targets. The attacks can also create uncertainty among US residents and policymakers over the extent to which Iranian actors may already have access to critical networks.
The United States has long been warned about such vulnerabilities. A decade ago, two Soufan Center analysts, then working at the RAND Corporation, wrote in Defense One that Washington needed to establish clearer cyberspace rules of engagement, strengthen government-industry partnerships and improve oversight and regulation of cyber-enabled technologies. They warned that Iran was developing cyber capabilities to compensate for its conventional military disadvantages.
“With its nuclear program on hold, Iran is trying to bridge the conventional military gap between the country and its competitors by shifting some resources to develop cyber capabilities,” Serena and Clarke wrote. They warned that Iranian hackers had moved beyond website defacement and network disruption and were capable of probing vulnerabilities, injecting malware and gaining control of adversary systems.
A decade later, Tehran has continued investing in these capabilities despite US and Israeli efforts to counter them.
The water sector is particularly exposed because much of its operational technology is ageing. Municipalities have increasingly adopted remote monitoring systems and internet-enabled management tools such as PLCs, potentially expanding the number of pathways through which attackers can reach operational systems. Some systems are exposed directly to the public internet and protected by default or shared credentials, meaning that malicious actors can sometimes obtain access through relatively straightforward techniques rather than sophisticated malware.
Federal agencies including the Environmental Protection Agency and the Cyber Security and Infrastructure Security Agency have previously warned about these vulnerabilities and advised utilities to eliminate unnecessary exposure. Implementation, however, has remained limited. The situation has generated additional concern following staffing and funding cuts to CISA during US President Donald Trump’s second term, after controversy between Trump and the former CISA director over the security of the 2020 US presidential election.
The latest attacks come as Iran employs a broader range of grey-zone tactics against Western countries. According to The Soufan Center, Tehran has increasingly combined cyber operations with influence campaigns on social media, proxy organisations and the recruitment of petty criminals to conduct attacks or vandalism.
An example cited by the centre is Harakat Ashab al-Yamin al-Islamia (HAYI), an Iranian front group that has recruited and paid individuals across Europe to target Jewish and Israeli-linked targets.
Cyber operations therefore form part of a wider strategy in which Iran seeks to exert pressure without necessarily provoking a conventional military response. In the case of US water infrastructure, the immediate objective is unlikely to be prolonged disruption, given America’s ability to restore affected systems.
Instead, the attacks serve a broader strategic purpose: demonstrating that even a major power remains vulnerable to an adversary capable of exploiting weaknesses in its critical networks.
For the United States, the incidents expose the enduring challenge of protecting highly decentralised infrastructure whose technological systems have become increasingly connected while remaining unevenly protected. For Iran, the same vulnerabilities offer an opportunity to demonstrate reach, impose limited costs and reinforce a message that conventional military superiority does not eliminate exposure in cyberspace.

