Cyberattacks targeting water and wastewater utilities have been reported across at least 12 US states, with Iran identified as the prime suspect. No widespread disruptions to water supplies or treatment have occurred so far.
Intelligence sources indicate a coordinated campaign against critical water infrastructure across multiple states. The attacks represent a significant security concern given the essential nature of water utilities to public health and safety.
Federal authorities are investigating the scope and sophistication of the intrusions. The targeting of water systems is particularly alarming as such infrastructure is classified as critical national security infrastructure.
While attackers have gained access to some systems, officials report that operational disruptions remain limited at this time. Water treatment and supply to customers have not been substantially impacted.
The incident underscores ongoing vulnerabilities in critical infrastructure cybersecurity. Authorities are working with affected utilities to assess the breach extent and implement defensive measures. Officials have not yet provided specific details about which states were targeted or the methods used in the attacks.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.
Healthcare software company Unlimited Technology Systems disclosed a data breach affecting 3.8 million individuals. The breach occurred in October 2025.