Water utilities in 45 US municipalities have been hit by cyberattacks that are suspected to have originated from Iran, according to a report from Tom's Hardware.
The targets were mostly small towns. According to Tom's Hardware, several US towns have said their water utilities suffered attacks, and while the systems remain running, a number of utilities have fallen back on manual control to protect their water supply.
That detail — switching to manual — is the clearest signal of how seriously the operators are treating this. Modern water systems are run largely by remote industrial controls: software that opens valves, runs pumps, and doses treatment chemicals without a person standing at the equipment. Pulling the plug on that automation and having staff operate things by hand is slow and labor-intensive, but it takes the compromised or suspect digital layer out of the loop entirely.
Small towns are a soft spot in American infrastructure. A municipal water system serving a few thousand residents typically has no dedicated security staff and a budget that leaves little room for the monitoring and hardening that a large city utility can afford. The equipment is often the same industrial control gear used everywhere else, which means one known weakness can be reused against many separate operators.
The suspicion of Iranian involvement has not, in the source material available, been accompanied by confirmed attribution or technical detail, and no disruption to drinking water itself has been reported. What's described so far is intrusion and precaution rather than damage.
It matters because drinking water is the most basic public service there is, and this suggests the systems delivering it in dozens of American communities are reachable by adversaries who are willing to try.