The Central Arizona Project (CAP), designed to bring 1.5 million acre-feet of Colorado River water per year to Pima, Pinal and Maricopa counties. (Photo: Manuela Durson/Shutterstock)
Suspected Iranian Hackers Target Water Systems In At Least 12 States After Iran-Linked Arizona Election Portal Attack
Officials have reported no contamination or other effect on the safety of drinking water
By Megan Barth, August 7, 2026 10:06 am
Federal investigators are examining a wave of cyberattacks that disrupted municipal water operations across at least 12 states, weeks after an Iran-linked group claimed it breached systems associated with a major California water utility and more than a year after an Iranian-affiliated threat actor targeted the backend of the Arizona Secretary of State’s candidate portal.
The latest attacks affected water and wastewater systems in Michigan, Minnesota, Georgia, New Jersey and South Dakota, according to CBS News. The remaining affected states have not been publicly identified.
More than 30 community water systems were affected in Minnesota alone. Some utilities lost remote access to pumps, valves and water-pressure controls, forcing employees to operate the equipment manually.
The Clayton County Water Authority in Georgia, which serves approximately 300,000 customers in the Atlanta area, reported that cyber activity caused a drop in water pressure and prompted a boil-water advisory. Service was restored within several hours.
Officials have reported no contamination or other effect on the safety of drinking water.
The FBI and Environmental Protection Agency warned on July 30 that water utilities in at least seven states had reported attacks beginning July 27.
The attackers gained remote access to internet-connected programmable logic controllers manufactured by Rockwell Automation and Allen-Bradley. The controllers are used to monitor and operate equipment within water and wastewater facilities.
According to the FBI, the attackers changed the internet addresses and passwords assigned to the controllers, causing utility employees to lose monitoring and control capabilities. Some affected facilities experienced water-pressure losses and flooding.
“Pressure loss in water systems could potentially allow untreated ground water to seep into pipes,” the FBI warned.
Federal officials advised utilities to disconnect the controllers from direct internet access, place them behind secure gateways and firewalls, use strong and unique passwords, restrict network access and preserve the ability to operate facilities manually.
Federal investigators suspect Iran-backed hackers may be responsible, according to CBS News, The Hill and the BBC. The government has not formally attributed the attacks to Iran or any specific hacking organization.
Investigators are also considering whether another actor attempted to make the attacks appear Iranian amid the continuing conflict between the United States and Iran.
Federal agencies had previously warned that Iranian-affiliated actors were targeting internet-connected programmable logic controllers used across American critical infrastructure.
The methods also resemble a 2023 campaign attributed to CyberAv3ngers, a hacking persona affiliated with Iran’s Islamic Revolutionary Guard Corps.
During that campaign, the FBI, Cybersecurity and Infrastructure Security Agency, EPA and other federal agencies said IRGC-affiliated hackers targeted internet-connected programmable logic controllers used by water and wastewater facilities. The attackers primarily pursued Israeli-made equipment that remained accessible through default passwords.
The latest attacks follow a confirmed 2025 intrusion by an Iranian-affiliated threat actor targeting the backend of the Arizona Secretary of State’s candidate portal.
The attackers uploaded malicious code and replaced photographs of political candidates from previous elections with an image of Ayatollah Ruhollah Khomeini. The altered images directed visitors to a Telegram account carrying a message warning that its “erosion revenge” had begun following American strikes against Iranian nuclear facilities.
Arizona officials said they had moderate confidence that the Iranian government or an affiliated actor was responsible.
The Secretary of State’s Office temporarily took the candidate portal offline and isolated the affected system. The office later said no sensitive information was accessed and that Arizona’s statewide voter-registration database and Address Confidentiality Program operated on separate networks and were unaffected.
The handling of the attack prompted scrutiny from Republican lawmakers.
Arizona State Sen. Jake Hoffman, (R-LD15), accused Democratic Secretary of State Adrian Fontes of withholding information after lawmakers reportedly received separate briefings about the incident.
Fontes responded that his office had publicly acknowledged malicious activity on July 1 and had protected the state’s critical election systems.
Arizona State Rep. Nick Kupper, (R-LD25), later requested a briefing open to the full Legislature, including information about how the attackers gained access, which systems may have been exposed and what protections were implemented afterward.
“Arizona’s election systems should never be this easy a target for foreign adversaries,” Kupper said. “This wasn’t a prank — it was a politically motivated act of cyberwarfare, and we deserve answers.”
Arizona House Republicans also publicized Kupper’s request, calling for additional disclosure about the state’s response to the intrusion.
The Arizona Secretary of State’s Office subsequently confirmed that federal agencies had been notified and described the attempted intrusion as the work of an Iranian-affiliated threat actor.
The office did not publicly attribute the attack directly to the IRGC. The Justice Department has separately charged IRGC-linked hackers with targeting American political campaigns and attempting to influence U.S. elections.
The current water-system investigation also follows a separate June incident involving California Water Service, an investor-owned utility that supplies water to approximately two million Californians across more than 100 communities.
An Iran-linked hacking group known as Handala claimed it breached systems associated with the utility and obtained information connected to operations in Bakersfield, Visalia and Chico.
The group released approximately five gigabytes of purportedly stolen data and claimed it possessed the ability to interfere with water service.
Cal Water said an investigation conducted with Google-owned cybersecurity firm Mandiant found no evidence that the hackers entered the utility’s internal information-technology network or operational-technology systems.
“Based on its investigation, Mandiant has confirmed that the threat actor activity was limited to unauthorized access to a small number of specific user accounts within two third-party service provider platforms,” Cal Water said, according to SecurityWeek.
The investigation found that an attacker accessed one active customer’s online account using stolen credentials. The account did not provide access to Cal Water’s billing system, and no payment information was compromised.
The attacker also accessed a third-party website used for correcting GPS location data. Cal Water said the website contained no confidential or sensitive information.
California State Sen. Melissa Hurtado, (D-LD16), subsequently asked the Cybersecurity and Infrastructure Security Agency to examine the incident and determine whether infrastructure or leak-detection information had been accessed or altered.
“The reported threat against Bakersfield and other Central Valley water systems must be taken seriously,” Hurtado said in a June 19 statement. “When a foreign-linked hacker group claims it could have cut off water to American cities, it is not just a local concern — it is a national security warning.”
The incidents have renewed scrutiny of Iranian-linked cyber operations targeting American government systems, election-related infrastructure and operational technology used by public utilities. Federal investigators have not formally attributed the latest water-system attacks.
The FBI and EPA urged utilities to remove programmable logic controllers from direct internet exposure, place remote connections behind secure gateways and firewalls, use strong passwords, maintain the ability to operate systems manually and report suspicious activity to the FBI or CISA.
- Nevada Doctor Charged in $95 Million Medicare Wound Care Fraud Scheme - August 7, 2026
- Suspected Iranian Hackers Target Water Systems In At Least 12 States After Iran-Linked Arizona Election Portal Attack - August 7, 2026
- White House Declassifies 2020 Maricopa County Voter Data Breach - August 6, 2026





They did us a favor.
“California State Sen. Melissa Hurtado, (D-LD16), subsequently asked the Cybersecurity and Infrastructure Security Agency to examine the incident and determine whether infrastructure or leak-detection information had been accessed or altered.”
IOW, The Golden “State of No” will find a way to sluff it off to a multi-million dollar NGO who will create a staff and Hoover up the money ending with a 10,000 word report saying “Our amateur coders left a lot of doors open”.
Why not hire Microsoft or someone who knows what they are doing when secure code is important.
Next time we may not be able to brag about “saving the day”.