Last week, a sudden coordinated cyberattack targeting more than 30 public water systems in the U.S. state of Minnesota sent shockwaves across national cybersecurity circles, catching many officials and analysts by surprise. Within days, the Federal Bureau of Investigation confirmed that similar malicious cyber activity had been detected across seven U.S. states, with some of these intrusions successfully disrupting core water treatment and distribution operations.
According to anonymous U.S. media sources, the Cybersecurity and Infrastructure Security Agency (CISA) has launched an investigation into a potential link between the Minnesota breaches and Iranian actors, though CISA has declined to issue any public comment on the ongoing probe. While former President Donald Trump has not publicly placed blame on Iran for the attacks, multiple cybersecurity experts interviewed by the BBC have assessed that Tehran is the most likely sponsor of the operation.
Morgan Wright, a former U.S. State Department counterterrorism advisor, told the BBC that cyber intrusions of this nature targeting U.S. critical infrastructure are most commonly traced to either North Korean or Iranian actors. “Given our current ongoing geopolitical conflict with Iran, they immediately rise to the top of the list: they have both the capability to carry out this attack and a clear motive to do so,” Wright explained.
However, the BBC’s U.S. partner CBS has noted that investigators are also exploring an alternative theory: that hackers may have intentionally masked their origins to appear Iranian, a deliberate ruse designed to exacerbate existing geopolitical tensions between the U.S. and Iran amid the ongoing conflict. Jake Braun, former acting White House Deputy National Cyber Director, pointed out that the Trump administration has been waging its own information campaign amid heightened tensions, meaning it may be unwilling to publicly confirm Iranian involvement even if evidence of such a link is solidified.
The breach has already sparked heated partisan friction in the U.S. Speaking at a cabinet meeting last Friday, Trump, a Republican, blamed the attack on what he called “grossly incompetent” Minnesota state leadership, including Democratic Governor Tim Walz. Walz pushed back swiftly, saying “Trump knows full well who is responsible for this attack, and he is aware that multiple other states across the country have also been targeted.”
To date, Iran has not issued any formal response to the recent allegations, a pattern consistent with its past stance on similar accusations. Tehran has repeatedly denied involvement in a string of cyberattacks targeting U.S. entities over the past decade, ranging from previous water system intrusions and presidential campaign hacks to breaches at U.S. hospitals and a 2014 attack on a Las Vegas casino corporation. After 2016 accusations that Iran targeted a New York-area dam and multiple U.S. banks, then-foreign ministry spokesman Hossein Jaberi Ansari told state TV that “Iran has never included any malicious cyber activities on its agenda, nor does it support such actions,” and called on the U.S. to provide concrete proof for its claims.
Cybersecurity experts confirm that Iran has a well-documented history of conducting cyber operations against Western targets, and note that many attacks linked to Tehran are carried out by Iran-aligned groups based outside the country, a tactic that creates plausible deniability for the Iranian government. “This makes attribution far more difficult, because even if all the infrastructure and actors trace back to Iran, the regime can always deny any official connection,” Wright explained. “They structure operations this way specifically to avoid leaving direct fingerprints on the activity.”
BBC Verify’s analysis has found that the majority of Iranian-linked cyberattacks targeting the U.S. and Israel this year have been carried out by a hacking collective called Handala. The U.S. Department of Justice has formally tied Handala to Iran’s Ministry of Intelligence and Security (MOIS), confirming the group operates on behalf of the Islamic Republic. In the early days of the U.S.-Iran conflict, FBI Director Kash Patel publicly accused Handala of stealing personal information and accessing private emails from U.S. targets. The most recent publicly claimed breach by Handala occurred in mid-June, when the group said it hacked a California water facility in retaliation for a U.S. military strike on Iranian water infrastructure.
Handala has been linked to a string of high-profile breaches in recent years: just this year, the Department of Justice disrupted a Handala operation that targeted a U.S. medical technology firm and leaked sensitive personal data belonging to Israeli government and military officials. In 2024, Iran was accused of hacking U.S. presidential campaign networks to stoke political division, undermine public trust in the U.S. electoral system, and steal sensitive information on government officials. Both 2023 and 2024 saw Cisa confirm that Iranian Revolutionary Guard Corps (IRGC)-affiliated hackers targeted U.S. water and wastewater systems, forcing temporary shutdowns of water pressure regulation equipment in two Pennsylvania towns. In 2020, two Iranian nationals were indicted for attempting to interfere in the U.S. presidential election by stealing confidential voter data and sending threatening messages designed to coerce voters into supporting Trump. As early as 2017, Iranian-based hackers were linked to a multi-year ransomware campaign targeting local governments, K-12 schools, healthcare providers, and financial institutions, though Cisa noted at the time that the group’s activities were likely not officially sanctioned by the Iranian government.
Cybersecurity experts emphasize that the most immediate harm from the recent water system breaches is not physical disruption to drinking water supplies, but the erosion of public trust in the government’s ability to secure critical basic services at a time of deep national division over the ongoing Iran conflict. “They are attacking our confidence in public institutions,” Braun explained. That said, experts warn that the risk of future attacks that do endanger public water safety cannot be ignored: malicious actors could manipulate chemical dosages to create harmful drinking water, shut off water service entirely to entire communities, or cause permanent damage to treatment infrastructure, Wright noted.
Cisa and the U.S. Environmental Protection Agency have repeatedly warned that cyber intrusions represent a serious and growing threat to the nation’s water utilities. The U.S. is home to more than 152,000 public drinking water systems and over 16,000 wastewater treatment facilities, making the attack surface extremely broad. “If you want to cripple a nation, you target two core systems: power and water,” Wright said. He added that a large share of the equipment used in water and wastewater operations remains vulnerable to intrusion, due to decades-old legacy infrastructure and outdated technology that lacks modern security protections.
Unlike most other U.S. critical infrastructure, the vast majority of the nation’s water utilities are publicly operated, meaning securing these systems falls to federal, state, and local governments. Experts warn that without systematic upgrades to cybersecurity defenses across the sector, the U.S. will continue to face this persistent national security threat. Cisa has already issued a series of recommended security upgrades to state and local governments across the country to reduce risk: as an immediate mitigation step, the agency has advised water systems to take public-facing control devices offline as quickly as possible and reset all default or compromised passwords.
