A municipal water utility in Minnesota, an outdated computer connected to the internet for remote control, and a group of hackers thousands of miles away. This is, in its simplest form, the geography of the new confrontation between Tehran and Washington .
Iranian hackers have targeted not only American water networks , but also telecommunications , the energy sector, and other critical US facilities in recent weeks.
According to NBC, which brought the matter to light, the attempts focused on automated systems connected to the internet and have not been successful so far. However, they demonstrate Tehran’s readiness to respond dynamically far beyond the geographical boundaries of the Middle East.
The context is familiar. Since the war broke out last February , US and Israeli forces have carried out repeated airstrikes on Iranian bridges, fuel tanks and other infrastructure. At the same time, the pressures are multiplying as the aging US electrical grid is already being tested by unpredictable fluctuations in demand, which have caused sudden power outages in major cities such as Los Angeles .
On Sunday, a channel on the Telegram platform that acts as a conduit for Iranian cyber operations openly declared that it would target the energy, water and telecommunications sectors in the US, claiming that previous warnings to Washington had been ignored. “Soon, the United States will witness unexpected and critical events in the energy, water and telecommunications industries,” the APT IRAN group said.
The channel did not show evidence of successful infiltration, but the message was nonetheless recorded with caution. Before the July attacks, pro-Iranian networks used to exaggerate , claiming successes against Western targets, with most of these accounts now suspended.
The new warning, however, came at an extremely heated moment. It coincided with the US military’s announcement that it had struck Iranian rocket launchers on the strategic island of Larak , where, according to the Pentagon , naval mines were being laid in the Strait of Hormuz. The climate of silence that followed is characteristic. The US Cybersecurity and Infrastructure Security Agency ( CISA ) did not respond to a request for comment, the White House referred the matter to the FBI, which also did not respond, while the CIA declined to comment.
Cyberwarfare analysts tell NBC that the threat from Iranian espionage and sabotage operations is steadily growing. In July , while American water systems were under attack, a cyberattack knocked out a British power plant for four days . A Western official with knowledge of the matter said Iran is suspected of being behind the sabotage.
In the US, the FBI confirmed last month that it was investigating a barrage of cyberattacks on municipal water facilities in at least seven states . The attacks did not cause widespread water supply disruptions or contamination, but are likely to be attributed to Iranian hackers. In Minnesota alone, more than 30 municipal facilities were targeted.
Days earlier, CISA and federal officials had warned that Iranian-linked actors were attempting to hack into infrastructure management devices. In July, systems at more than 100 water and wastewater facilities were targeted, primarily through automations connected directly to cellular modems. On August 21 , CISA issued a new directive calling on all critical infrastructure organizations to fortify their remote access programs.
The pressure coincides with internal turmoil in Washington. The Trump administration has drastically reduced the size of CISA, laying off about a third of its staff. Democratic lawmakers and experts warn that the cuts are leaving critical infrastructure vulnerable. Water utilities in the U.S. are fragmented , with small units in rural areas lacking resources and specialized technicians. Many are now turning to volunteers, small cybersecurity firms and even an artificial intelligence program developed by Vanderbilt University .
While the known Iranian attempts are technically simple , the risk remains real. Many facilities rely on outdated computers, which are connected to the internet to allow remote control during understaffed shifts. This practice opens the door wide to would-be attackers.
The situation is being rapidly complicated by the spread of artificial intelligence . As one source explains, AI has drastically lowered the difficulty level, helping even inexperienced hackers identify targets and break through defenses. According to a CISA warning on August 19 , the use of AI to create exploit code is a quantum leap for adversaries, as it minimizes the technical expertise and time required to build malicious tools against industrial control systems. Attackers are mining public data for vulnerabilities, identifying exposed programmable logic controllers, and implementing automated attack scripts.
Herein lies the real concern. It’s not that Iranian teams have exceptional skills. It’s that, with fewer personnel on defense, outdated systems on the field, and artificial intelligence tools in the hands of the attacker, the need for exceptional skills is continually diminishing.