Iranian hackers have targeted US water systems telecommunications energy and critical infrastructure in recent weeks with an Iranian hacking group warning unexpected and critical events would soon target America.
By NBC | Imran Malik | US News & Security Desk | NJNewsline.com | MediaBites.com.pk
The US-Iran war has a front that no missile can target, and no aircraft carrier can defend. And Iran is fighting it aggressively.
Iranian state-linked hackers have expanded their cyberattack campaign against the United States beyond water systems to include telecommunications, energy, and other critical infrastructure, according to sources with access to government and industry information on cyberthreats, as reported by NBC News. The attacks so far have been unsuccessful in causing catastrophic damage, but an Iranian hacking group has warned that “unexpected and critical events” would soon target American infrastructure.
The warning is not theoretical. The capability is real. And America’s defenses are being tested in ways the public is only partially aware of.
What Iran Has Already Done — The Water Attack That Shocked America
Iranian cyber actors attacked water facilities simultaneously across at least 12 US states in the most expansive Iranian cyber campaign against American infrastructure on record. Among the most severe consequences was in Georgia, where hackers shut down a pump station, causing water pressure to drop.
According to the FBI, hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disable processes that handled critical shutdowns and alarms, allowing systems to enter unsafe conditions without notifying operators of the anomalies.
Between July 26 and July 28, several local authorities in Minnesota reported problems at community water plants, with officials in Maple Plain declaring a brief state of emergency.
“It appears this is a shot across the bow from Iran,” said Jake Braun, former White House acting principal deputy national cyber director.
Beyond Water — The Expanded Campaign
The NBC News report confirmed what security analysts had been warning for months. Iran’s cyber campaign is not limited to water systems. It has expanded to telecommunications, energy networks, and broader critical infrastructure — the interconnected systems that power American life.
Since at least March 2026, FBI-identified Iranian-affiliated advanced persistent threat actors have disrupted the function of industrial control systems at multiple US critical infrastructure organizations, targeting internet-exposed programmable logic controllers with the intent to cause disruptions, including manipulating data displayed on control systems.
The scope has expanded beyond initial targets to include Rockwell Automation, Schneider Electric, Siemens, and potentially other branded PLCs, with agencies emphasizing the importance of restricting direct internet access.
Stryker, FBI Emails and the Scale of Iranian Hacking
Among the more notable incidents was a hack on US medical technology giant Stryker, which allowed the Iranian hacking group Handala to remotely wipe tens of thousands of employee devices.
The same period saw Iranian hackers leak the contents of FBI Director Kash Patel’s personal email account, demonstrating the breadth of Iranian cyber operations that extend well beyond infrastructure disruption into intelligence gathering and embarrassment operations against senior American officials.
Why Military Ceasefires Do Not Stop Cyberattacks
Experts warn that military ceasefires do not always translate to cyberspace, with federal officials warning that state-sponsored malicious hackers are increasingly targeting US critical infrastructure, posing significant business risk given the reliance of commercial systems on critical infrastructure, from financial institutions to telecommunications systems.
US authorities have specifically warned about Iranian-affiliated actors targeting internet-connected programmable logic controllers, with agencies identifying activity across water, energy, and government services, including attempts that have resulted in operational disruption.
The 60-day ceasefire framework between Washington and Tehran has expired without a replacement agreement. The military conflict continues. And in cyberspace, the conflict has never paused.
America’s Infrastructure Vulnerability — The Uncomfortable Truth
Iran’s cyber activity during this conflict has been much broader than just disruption and can be categorized into opportunistic disruption by Iranian state or state-linked actors on US and regional targets, cyber espionage to assess battle damage or inform kinetic activity, and intelligence gathering to inform targeting.
The threat to US critical infrastructure goes far beyond Iran, with the US government struggling to boot persistent Chinese cyber actors such as Salt Typhoon from US telecommunications networks despite them having been present since at least 2021 and 2022.
The Trump administration’s proposed FY2027 budget would shrink CISA’s front-line cyber support at a time when national cyber threats are escalating — a contradiction that cybersecurity professionals have described as deeply concerning.
What Pakistani Americans and New Jersey Residents Should Know
For New Jersey’s significant Pakistani-American community and its broader population, Iran’s cyberattacks on American infrastructure are not an abstract national security concern.
New Jersey’s water systems, energy grid, and telecommunications networks are all part of the interconnected American infrastructure that Iranian hackers are targeting. The state’s dense population, proximity to New York City, and concentration of critical facilities make it among the most significant targets in any infrastructure disruption campaign.
The warning from the Iranian hacking group about “unexpected and critical events” targeting American infrastructure deserves to be taken seriously. The FBI, NSA, Department of Energy, and CISA have all issued advisories. The threat is real. The defenses need to be stronger than the proposed budget cuts would allow.
— Imran Malik | US News and Security Desk | NJNewsline.com | MediaBites.com.pk | Southera.com Sources: NBC News, CISA, TechCrunch, NPR, Al Jazeera, CSIS, FDD

