HackMyIP
← Back to News
2026-08-10 SecurityWeek

Iranian Hackers Hit 12 US States in Water Utility Cyberattack Campaign

APTIncident ResponseThreat Intel

New Jersey and Alabama have joined the growing list of US states confirming that their water and wastewater facilities were targeted in a coordinated hacking campaign that began in late July 2024. At least 12 states have reportedly been affected, with Minnesota being the first to disclose that over 30 water systems had their operational technology (OT) environments targeted. Michigan, South Dakota, and Georgia soon followed with their own confirmations, and the latest additions — New Jersey and Alabama — bring the scope of the campaign into sharper focus.

In New Jersey, the Cape May and Woodbine water systems were hit on July 27. Officials reported that only phone systems were disrupted, with no impact on water treatment operations. On the same day in Alabama, the Childersburg Water, Sewer and Gas system was attacked, with hackers targeting industrial control systems (ICS) but failing to disrupt water services. Despite the breadth of the campaign, none of the affected utilities have reported significant operational damage, and all have assured citizens that drinking water remains safe. Wisconsin, Pennsylvania, and Washington have issued advisories to local water utilities but have not confirmed direct attacks, while New York has allocated more than $9 million in grants to strengthen cybersecurity across the sector.

The FBI confirmed publicly on July 30 that at least seven states had been targeted, but neither the bureau nor CISA has issued a formal update since. The attacks have been attributed to Iranian-linked threat actors exploiting vulnerabilities in ICS devices manufactured by Rockwell Automation and potentially other major vendors. CISA has urged water sector operators to harden their OT environments immediately. Security teams responsible for critical infrastructure can audit their exposure using a port scanner to identify open services on control networks, and operators managing remote access infrastructure should verify configurations with a SSL/TLS checker to ensure encrypted channels are properly implemented across SCADA and management interfaces.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →