Iranian Hackers Target U.S. Water Systems, Exploiting Default Passwords
Hackers, suspected to be aligned with Iran, attempted to breach at least 30 municipal water systems in Minnesota on July 26-27, 2026. Similar cyberattacks have been reported in Michigan, New Jersey, and other states. The attackers targeted small computers controlling equipment like pumps and valves, crucial for delivering drinking water. Utilities responded by shutting down control computers and manually operating equipment, ensuring water safety. The U.S. government has not officially attributed the attacks to any group, but the methods align with typical international cyberattacks. The incidents highlight vulnerabilities in the U.S. water infrastructure, particularly the use of default passwords in internet-connected systems.