The attacks on U.S. water systems have caused no known contamination, but they may be Iran's latest attempt to bring the war inside the American homeland.

 

Protest against the war in Iran, near the White House, 3/7/26. (Photo: Victoria Pickering)

The first thing Americans should know about the recent attacks on municipal water systems is that no one has been poisoned. There is no evidence that hackers successfully altered chemical-treatment levels or rendered drinking water unsafe.

The second thing Americans should know is that this was not merely another data breach.

Hackers penetrated computers connected to the machinery that monitors and controls water pressure, pumps and other physical operations. Some communities lost automated control, issued boil-water notices or had to keep their systems running manually. Since July 27, utilities in at least seven states have reported incidents to the FBI, and some of the intrusions degraded water operations.

That is a meaningful escalation. It is one thing to steal passwords, freeze office computers or deface a government website. It is another to reach into the industrial systems that keep water flowing through American cities.

Federal officials have not formally attributed the latest campaign to Iran. Cyber investigations are difficult, evidence can be concealed and one country’s methods can be copied by criminals or rival intelligence services. President Donald Trump is therefore within reason to demand stronger evidence before publicly accusing Tehran.

But Iran is not being treated as the leading suspect without cause.

In April, the FBI warned that Iranian-affiliated hackers were targeting internet-connected programmable logic controllers used throughout American critical infrastructure. The bureau assessed that the attackers intended to cause disruption by altering project files, manipulating data and interfering with the displays operators use to monitor industrial processes. Officials said Iranian cyber activity had escalated in response to hostilities with the United States and Israel.

The government renewed that warning in July, telling American organizations that Iran-affiliated groups were continuing to target operational technology — the computers that control machinery rather than merely storing information.

There is precedent as well. In 2023, the IRGC-affiliated CyberAv3ngers group compromised internet-connected controllers at several American water facilities. One attack forced a Pennsylvania water authority to disconnect automated equipment and operate a pressure station manually. The attackers did not demonstrate some revolutionary new weapon. They often exploited exposed devices protected by default or easily guessed passwords.

Iranian hackers had displayed an interest in American water infrastructure even earlier. In 2013, an Iranian intruder accessed the control system of the Bowman Avenue Dam in New York and obtained information about its operations. The hacker might have been able to operate a sluice gate had it not been physically disconnected for maintenance.

What appears different now is the scale. The current activity has reportedly spread across numerous municipalities and at least seven states. Rather than targeting one symbolic facility, the hackers appear to be scanning widely for vulnerable industrial equipment and exploiting whatever they can reach.

This may be less a carefully planned effort to poison a particular city than an attempt to try every unlocked door in America. That should not be reassuring. A burglar who enters the wrong house is still a burglar, and a hostile government testing thousands of doors may be looking for the ones it will need during a larger confrontation.

Iran’s suspected objective may not be mass casualties — at least not yet. Cyber operations offer Tehran several cheaper and less risky benefits. They can frighten the public, force municipalities to spend scarce resources on emergency security, identify weak systems and demonstrate that a war conducted thousands of miles away can still reach American homes.

Most importantly, Iran can operate in the space between peace and open attack. A missile carries an unmistakable return address. A cyberattack can be routed through compromised computers, criminal intermediaries and foreign servers, giving Tehran time to deny responsibility while investigators assemble the evidence.

That ambiguity is part of the weapon.

The water intrusions should also be viewed alongside Iran’s willingness to conduct other operations inside the United States. In 2024, the Justice Department charged alleged IRGC asset Farhad Shakeri with participating in a plot to kill Trump. According to prosecutors, Shakeri told investigators that the IRGC had instructed him to produce an assassination plan.

In a separate case, a federal jury convicted Asif Merchant in March 2026 of murder-for-hire and attempting an act of transnational terrorism. Merchant admitted that the IRGC sent him to the United States to arrange political assassinations. He tried to recruit killers, paid what he believed was a $5,000 advance and researched American political events before his arrest. Trump was among the intended targets identified by the government.

Those cases do not prove that Iran conducted the latest water attacks. They do, however, establish willingness and motive. Tehran has shown that it is prepared to use hackers, intelligence operatives and criminal proxies against targets inside the United States.

America should respond without panic and without complacency. The good news is that many of these attacks can be prevented. Industrial controllers should not be exposed unnecessarily to the public internet. Default passwords should be changed. Remote access should be limited. Systems should be segmented so that penetrating one device does not grant control over an entire facility.

The bad news is that America has known this for years. Small municipalities frequently rely on aging equipment, outside contractors and tiny technology budgets. Many do not employ a full-time cybersecurity specialist. Iran does not need to defeat the most sophisticated systems in the country when hundreds of poorly defended ones remain available.

So, is Iran targeting U.S. infrastructure? The latest incidents have not yet been conclusively attributed, but the broader answer is already yes. Iranian-affiliated hackers have targeted American infrastructure before, federal agencies say they are doing so now, and Tehran has repeatedly demonstrated its appetite for operations on American soil.

The water is safe today. The warning should not be wasted.

(Contributing writer, Brooke Bell)