Why Critical Infrastructure Keeps Getting Hacked
Water, power, hospitals, and ports are the new targets for cyber attackers
Last month, public works crews in Braham, MN, noticed that the well feeding their water tower was malfunctioning. It was suspected to be the work of Iranian hackers, who investigators believe broke into the town’s automated water controls along with dozens of other systems statewide.
The investigators don’t believe the intrusion was designed to poison anyone or shut off a city’s water supply — the taps kept running because operators caught the anomaly and switched to manual controls before the malfunction could cause real damage. It was something investigators believe was meant to be quieter and more unsettling: a reminder that a foreign government may already be inside the systems Americans rely on every day. A town told to boil its water learns, immediately, that something it took for granted is not guaranteed.
By the time the FBI and the Environmental Protection Agency issued a joint advisory, at least seven states had reported related incidents, and utilities from Michigan to South Dakota were switching to manual operations to keep water flowing.
The statement explained that hackers are remotely accessing internet-connected controls, changing administrator passwords, and “causing operational disruption” like flooding and pressure loss, which “could potentially allow untreated ground water to seep into pipes.”
The Cybersecurity and Infrastructure Security Agency (CISA) attributed the hack to a group called CyberAv3ngers, which is affiliated with the Islamic Revolutionary Guard Corps. It said the hackers weren’t picking favorites — they were “targeting water entities of all sizes.” Gus Serino, a veteran water-sector cybersecurity specialist, put it plainly: “The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented.”
For years, Americans pictured cyberwar as hackers stealing credit card numbers or breaking into government servers. That picture is outdated. Today’s targets are the systems that make ordinary life possible — water, electricity, pipelines, hospitals, ports, communications.
Water seems like an unglamorous target, but that’s exactly why it’s attractive. Most municipal utilities are small operations running old control equipment, managed by a handful of staff who also fix water mains and read meters. Of the roughly 151,000 public water systems in the country, only a few hundred participate in the industry’s main cyber-threat-sharing group.
That’s partly because many of these systems were built to run in isolation, decades before anyone thought about hacking, and got connected to the internet only later. Federal inspectors have found that most of the drinking water systems they’ve reviewed fail to meet basic cybersecurity standards — problems as simple as factory-default passwords that were never changed. None of that requires a sophisticated attacker to exploit.
Beyond the tap
Water is the clearest example of this sort of vulnerability, but it isn’t the only one. The electric grid has many of the same problems — aging equipment, thin cybersecurity staffing, and thousands of separate operators with no uniform standard. US officials have believed for years that Chinese state-linked hackers have already installed themselves inside American power systems. The grid has also seen a rise in physical attacks — vandalism and in one case a foiled drone plot against a Tennessee substation — a reminder that the threat to critical infrastructure isn’t purely digital.
Pipelines, hospitals, and ports have similar exposure. The 2021 ransomware attack on Colonial Pipeline, blamed on DarkSide, a Russian-speaking criminal group, never touched the pipeline’s operating systems — only its billing software. Yet it was enough to shut down fuel deliveries across the East Coast for days.
Hospitals have become one of the FBI’s most frequently targeted sectors for ransomware. Like water utilities and pipelines, they depend on aging systems, limited cybersecurity resources, and uninterrupted operations — making them attractive targets for criminals and nation-states alike. A hospital that loses water pressure is rendered unable to sterilize medical equipment within hours.
Different actors, and strategies
Iran is one of three countries that dominate the cyber threat to US infrastructure, and experts believe each is playing a different game.
Iran operates like an opportunist. Investigators of the Minnesota attacks believe the hackers weren’t hunting for one high-value target; they were scanning the internet for any water system running an exposed, vulnerable device and hitting whichever ones they found. When the goal is to undermine confidence, the target chosen is not especially important.
One aspect of this strategy’s success is visible in the US political fight over the attacks. President Trump dismissed the theory that Iran was responsible, blaming Minnesota’s Democratic state government instead. “Iran should be so lucky,” he said. Minnesota Governor Tim Walz responded that “this is what modern warfare looks like.”
Iranian-linked hackers have used that same scattershot approach against US water and energy systems since at least 2013, when they accessed the control system of a small dam outside New York City — a low-value target, but one that made the point that they could get in.
Russia, meanwhile, fuses cyber operations into a single, coordinated campaign against one target, timed to work alongside physical strikes. Over more than a decade of conflict with Ukraine, Russian military hackers have treated cyber as a companion to battlefield weapons — knocking out sections of Ukraine’s power grid in the same window as missile attacks, and in 2022 launching wiper (or data-destroying) malware against Ukrainian government systems hours before tanks crossed the border. NotPetya, a form of malware those same Russian hackers built to hit Ukraine in 2017, was aimed narrowly at Ukrainian networks but spread far beyond its intended targets, costing companies worldwide billions of dollars — proof of how easily a state-built cyberweapon can slip its creators’ control.
Russian-affiliated hackers have also opportunistically joined in the Iran war, backing Tehran-aligned targeting of US networks.
China, by contrast, isn’t after disruption today — it’s after position for the long term. The group known as Volt Typhoon has spent years embedded inside US water, energy, and transportation networks, avoiding detection by using legitimate administrative tools rather than malware. The goal, officials believe, is to retain the ability to disrupt American infrastructure during some future crisis, most plausibly one involving Taiwan. CrowdStrike, a leading cybersecurity firm, found that China-linked activity rose 38% in 2025 — evidence of a well-funded, patient operation, not a one-time strike.
The adversary goes quiet
Attackers are also getting harder to spot. CrowdStrike calls 2025 the year of “the evasive adversary” — not because hackers have gotten more sophisticated, but because they’ve largely stopped using malware, the thing security tools are built to catch. CrowdStrike found that 82% of the intrusions it detected in 2025 were malware-free, up from 51% five years earlier, and that the average time an attacker took to move deep into a network was just 29 minutes.
For a water utility running with a small IT staff that doesn’t work around the clock, that leaves almost no window to catch an intrusion before it’s already inside the systems that matter. Artificial intelligence is accelerating all of this — not replacing hackers, but making each one faster. The result: fewer obvious break-ins, more legitimate-looking log-ins, and far less warning before something goes wrong.
Protecting the grid
The picture isn’t uniformly bleak. Since the Colonial Pipeline attack, Washington has built out real defenses: agency-led coordination, mandatory incident reporting, and stricter rules requiring systems to verify every user and device. The EPA says it has worked directly with hundreds of water systems in the past two years to close known vulnerabilities, and Congress is advancing legislation that would, for the first time, write cybersecurity requirements and funding directly into federal water infrastructure programs.
But the gains are running against a rising tide. The barrier to mounting a serious intrusion keeps falling, blurring the line between state-directed operations and freelance hacktivists — a blur already visible in Iranian-linked activity carried out by proxy groups whose ties to Tehran are deliberately murky. Meanwhile, the agencies charged with coordinating America’s defense have absorbed real cuts to staff and budget, even as officials call infrastructure security a top priority.
The bottom line
Most Americans will never notice the intrusions that are detected and quietly stopped every day. That’s the good news. The harder truth is that deterrence in cyberspace doesn’t look like deterrence during the Cold War. There are no missile silos to photograph, no troop movements to track. Adversaries map networks, test defenses, and wait — sometimes for years — for the moment access becomes leverage.
If the suspected Iranian intrusion into Minnesota’s water systems proves anything, it’s that the front line isn’t somewhere else anymore. It runs beneath American streets, through American substations, into the systems people rely on without a second thought. The next geopolitical crisis may begin thousands of miles away. Its first effects, increasingly, could be felt the moment someone turns on the faucet.








