If you fire missiles at me, I’ll cut off your water supply: The cyberattacks attributed to Iran that showed the US is vulnerable
The acts of sabotage that targeted water infrastructure in 12 states this summer are believed to have been carried out by Iranian hackers, who have been very active since the start of the war


Water service failed in at least 300,000 Atlanta households on July 27. Taps ran, but only a trickle came out. After receiving several consumer alerts, the water company found that a pumping station had stopped functioning, affecting that city and others in the state. The loss of pressure led authorities to advise boiling water before drinking it to reduce the risk of contamination, sparking some panic among the population. It was not a technical fault: everything points to it having been orchestrated from a computer almost 7,000 miles away, in Iran.
A few days later, authorities in another state, Minnesota, revealed that hackers had attacked more than 30 water-treatment facilities. By August 1 the cyberattacks had spread to seven states; by August 6 at least 12 states were affected, including Oregon, Michigan, New Jersey, South Dakota and Alabama. According to The New York Times, up to 100 facilities across the country were hit. The large number of incidents put city and county officials nationwide on alert, fearing further problems with that resource.
President Donald Trump, who has on several occasions declared the war with Iran over and won since it began, and who last week threatened to annihilate the country in his speech to the United Nations General Assembly, initially denied Tehran was behind the campaign. Other agencies were less certain. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) confirmed the systems had been hacked, although they did not name suspects. In cyberspace, attribution is extremely difficult, but, as of today, the main theory is that this summer’s U.S. water-supply crisis was cooked up in Iran. That is the view of the water industry group WaterISAC, according to a communication obtained by Wired, and other official sources cited by outlets such as CBS. The incidents caused no health problems or widespread chaos, but the scale of the cyberattack sent a message: the critical infrastructure of a superpower like the United States is vulnerable.
There are several indications pointing to Iran. One of the clues that typically guides forensic analyses of cyberattacks is the reuse of known code snippets by analysts, or even the language in which that code is written. There is another strong reason to suspect Tehran: attacking water infrastructure has become a specialty of groups linked to Iran. They did so in 2013 in New York, in 2023 in Pennsylvania and in 2020 and 2023 in Israel, where they tried to poison water by raising chlorine levels and to sabotage agricultural irrigation pipelines.
The 2023 campaign was carried out by the group CyberAv3ngers, which is believed to be linked to the Islamic Revolutionary Guard Corps. The message they left on compromised systems looked like the work of hacktivists — independent hackers who organize online to pursue a specific task: “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is CyberAv3ngers legal target.” However, official investigations soon determined the group was taking orders from Tehran.

That is not a minor detail. At the base of the cyberthreat pyramid are people tinkering at home, usually young IT enthusiasts testing themselves online. Above them are professional cybercriminals, and above those, cybercriminal organizations that can operate like companies. The next level would be hacker groups allegedly sponsored by states but without official ties. At the top sit the agencies of major powers: the U.S. NSA, the various Russian GRU agencies, Britain’s MI6, or the intelligence services of Israel or China.
Iran war shakes cyberspace
The penultimate level, that of large organized groups financed unofficially by governments — known in the sector as advanced persistent threats (APTs) — is where CyberAv3ngers would fit. Several other groups have been very active since March, when the war began: Imperial Kitten, Hydro Kitten, Charming Kitten, MuddyWater and OilRig are some examples. Each has its own structure and financial resources, allowing them to mount complex, coordinated and fast attacks, but they tend to specialize in different attack vectors.
All metrics show incidents have surged since March. Distributed denial-of-service attacks (DDoS, which overwhelm a server or website by sending a massive number of requests) rose 168% in the first quarter of this year compared with the same period in 2025, according to a CyberProof report. That analysis identified more than 70 hacktivist groups linked to Tehran. Europol, the U.S. Department of Homeland Security and the cybersecurity agencies of Canada and the UK also recorded excessive digital activity, according to a recent Palo Alto Networks report. CloudSek, for its part, has documented the use of AI tools in attack preparation.
The hacktivist group Handala knocked out systems at U.S. medical-technology company Stryker on March 11, barely two weeks after the start of the armed conflict, erasing data from more than 200,000 devices and deleting 50 terabytes of “critical information.” The same group also managed to compromise the personal email account of FBI director Kash Patel.
Why water?
Water supply and treatment infrastructure is an especially attractive target for cyberattacks because it is often poorly protected and any system failure has a direct effect on the public and on government credibility.
“During periods of heightened geopolitical tension, these environments acquire special sensitivity because any disruption can have consequences that go beyond the digital realm and directly affect essential services and physical processes,” says Hervé Lambert, global consumer operations director at Panda Security.
For this expert, the important question in this case is not who launched the attack, but why it was possible. “A system capable of controlling an essential physical process should not be directly exposed to the internet without appropriate protections,” he says. “To cause a significant impact it is not always necessary to develop an extremely sophisticated attack. An internet-accessible PLC [computers commonly used in industrial automation], weak or reused credentials, inadequately protected remote access or poor segmentation between corporate IT networks and industrial systems can open entry points with serious operational consequences. Operators of essential services must raise their level of vigilance in this context.”
But Iran has also taken hits in the cyberwar. On February 28, the same day the first missiles were launched at Tehran, Israel carried out what is considered one of the largest cyber operations ever against a nation’s digital infrastructure. Internet connectivity was virtually knocked out — to less than 4% of normal performance, according to a CloudSek report. News agencies and several official bodies were disconnected, and a widely used prayer-call app in the country, BadeSaba, with about five million users, was hacked and used to send messages urging Iranian soldiers to lay down their arms.
Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition







































