Iranian hackers are believed to be responsible for a growing cyberattack campaign targeting U.S. Water systems across at least seven states, with more than 30 systems affected in Minnesota alone, according to cybersecurity experts.

Annie Fixler, director of the cyber and technology innovation center at Foundation for Defense of Democracies, told JNS that "the working assumption is that it is Iranian threat actors" Based on the patterns observed. "The kind of behavior matches what we've seen out of Iran. The kind of targets and the systems that we're talking about match," She said.

No actor has publicly claimed responsibility for the attacks, which Fixler described as somewhat unusual. "What we don't have is anyone claiming responsibility, which is a little surprising," She explained. "Iranian hackers tend to claim responsibility for stuff because of that 'perception-hacking' component, because they want to let everyone know they did it and that they're really scary and big and bad."

Minnesota officials confirmed on Tuesday that more than 30 community water systems in the state were targeted in coordinated attacks on July 26 and 27. The FBI reported Thursday that water utilities in at least seven states experienced similar incidents, though the other affected states remain unidentified publicly. Fixler doubts that number will be final, noting "it's certainly an evolving situation" And that the incidents likely extend beyond the initial reports.

The attackers gained unauthorized access to water system controls, altered passwords and caused disruptions including water pressure losses and flooding. Fixler explained that the hackers targeted programmable logic controllers that manage industrial equipment like pumps and valves, allowing them to affect physical operations directly without navigating multiple network layers.

President Trump disputed the Iranian attribution on Friday, instead blaming Minnesota's governor, stating "I think I blame it on Minnesota, because they're grossly incompetent" And suggesting "Iran should be so lucky."

Federal agencies warned in April that Iranian hackers were targeting energy networks, government facilities and critical infrastructure beyond just water systems. Fixler indicated the current attacks may be connected to that broader spring activity.

Fixler noted officials have historically underestimated such threats and urged caution in public messaging. While current attacks do not appear to pose direct public danger, she warned that exaggerating the threat could serve Iran's intimidation goals by inflating perceptions of its capabilities.