Did Iran hack water systems in seven US states?
Getty ImagesMany were surprised last week when the US state of Minnesota reported that more than 30 of its state water systems had faced a "co-ordinated cyber-attack".
Days later the FBI warned cyber-attacks had been reported in seven states and "some of that activity degraded water operations".
The US Cybersecurity and Infrastructure Security Agency (Cisa) is reportedly probing a possible Iranian connection to the Minnesota attacks, according to US media. Cisa would not comment.
Although US President Donald Trump has not blamed Iran, cyber-experts tell the BBC it's likely the attack was directed by Tehran.
Here's what you need to know.
Is Iran behind these attacks?
Morgan Wright, a former US state department anti-terror adviser, told the BBC that these kinds of attacks are usually attributed to North Korea or Iran.
"And who are we in conflict with right now? Well, it's Iran. So they become, they go to the top of the listed terms of nations capable, and also having a desire to do something like this," he said.
US investigators are also looking into whether the hackers could have posed as Iran-based as a ruse to sow further discord amid the US war with Iran, according to the BBC's US partner CBS.
Jake Braun, former acting White House Deputy National Cyber Director, told the BBC that the Trump administration is involved in its own information war and therefore it might be unlikely to admit that Iran did infiltrate US water infrastructure, even if it was confirmed.
At a cabinet meeting last Friday, Trump, a Republican, blamed "grossly incompetent" Minnesota officials, including Governor Tim Walz, for the water hack.
Walz, a Democrat, responded: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too."
Iran has yet to comment on these incidents, but Tehran has repeatedly denied involvement in other cyber-attacks over the years, which include water systems, presidential campaigns, hospitals and a casino company in Las Vegas in 2014.
After a 2016 accusation linked to the targeting of banks and a dam outside New York City, Iran's foreign ministry spokesman said the US should prove such accusations.
Iran has "never had on its agenda any dangerous measures in cyberspace and does not support such moves", spokesman Hossein Jaberi Ansari said on state TV at the time.
Does this fit a pattern for Iran?
Iran has a documented history of this kind of activity, experts told the BBC.
They noted that groups supportive of Iran, but located outside the country could be responsible.
"It makes it harder to assign attribution because if all of your attacks and groups are coming out of Iran, you can pretty much link it to Iran," Wright said.
He noted that such a tactic offers bad actors plausible deniability.
"They do it so that their fingerprints aren't directly on it," he said.
Most of the Iranian cyber-attacks against the US and Israel this year have been carried out by a group called Handala, BBC Verify has found.
The US justice department has linked the group to Iran, saying they have been working on behalf of the the Islamic Republic of Iran's Ministry of Intelligence and Security (MOIS).
Handala previously was accused of accessing some personal details and emails by FBI Director Kash Patel in the early days of the Iran war.
The last cyber-attack in the US claimed by Handala was in mid-June, BBC Verify found. The hackers claimed to have breached a water facility in California in response to a US attack on Iranian water infrastructure.
Here are some of the other notable hacking operations that have been linked to Iran:
- 2026: The justice department disrupted a hacking operation by Handala that targeted a medical technologies firm. The operation also released sensitive information about members of the Israeli government and military
- 2024: Iran was accused of hacking into US presidential campaigns to "stoke discord, erode confidence in the US electoral process, and unlawfully acquire information" about officials to help Iran.
- 2023: US water and wastewater systems were hacked by a group accused of being affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) both in 2023 and later in 2024, according to Cisa. Equipment regulating water pressure in two Pennsylvania towns was temporarily closed due to the incident
- 2020: Two Iranian nationals were indicted on charges of attempting to meddle in the presidential election by obtaining confidential US voter information and sending threatening messages for people to vote for Trump
- 2017: Iran-based hackers were also accused of a years-long ransomware effort targeting local governments, schools, healthcare and financial institutions, though Cisa noted that the group's activities were "likely not sanctioned" by Iran's government.
Could it endanger water supplies?
Experts told the BBC that the biggest threat of the hacks was not to the water supply itself, but in degrading public confidence in the security of their water.
"They're attacking our trust in our government to be able to deliver basic services in a time when, you know, you've got a deeply divided country over the war," Braun said.
It also cannot be ruled out that Iranian hackers might one day succeed in endangering US water supplies, experts added.
Malicious efforts could cause a harmful distribution of chemicals, shut off water, or damage equipment, Wright suggested.
Cisa and the US Environmental Protection Agency have jointly said that cyber-attacks pose "a serious concern" for water utilities.
The US has 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities.
"Look, if you want to bring a nation to its knees, you go after two things, you go after power and water," Wright said.
How could this be prevented?
A lot of devices used in the water and wastewater processes are vulnerable to attack, because either there is old infrastructure or technology is older, Wright said.
Experts who spoke to the BBC warned that without upgrading the security of these systems, the US would continue to face this national security threat.
The vast majority of water utilities in the US are publicly run, unlike most other critical infrastructure.
So it is up to the government to do something, experts said.
Cisa has recommended a variety of upgrades to governments across the US in hopes of minimising this threat.
To immediately hinder hacking attempts, the agency recommended that water systems should be immediately removed from the internet as soon as possible and reset passwords.
Shayan Sardarizadeh with BBC Verify contributed to this report
