Iranian cyber operations targeting U.S. water and wastewater systems followed drone strikes on Gulf desalination plants. Washington responded with sanctions, indictments, and new authorizations for offensive cyber operations against Tehran’s actors.
The Iran Cyber Strategy directed at water and wastewater systems across the United States represents a deliberate expansion of Tehran’s coercive reach beyond the Persian Gulf. Where Iranian missiles cannot strike American territory, cyber intrusions allow the Islamic Republic to target infrastructure essential for public health and economic stability. The attacks on remote-control capabilities and water-pressure systems in as many as 12 states illustrate a methodical effort to impose costs on Washington while avoiding conventional military retaliation.
This approach mirrors Iran’s conventional targeting of desalination plants in Bahrain and Kuwait, but extends the threat to civilian populations far beyond the conflict zone. Washington has responded with Operation Economic Outcast, sanctioning nearly 60 entities and individuals tied to Iranian intelligence and hacking networks. Yet sanctions and indictments address only the aftermath of intrusion. They do not prevent the next breach or force Tehran to recalculate its operational logic.
The Iran Cyber Strategy thus exposes a structural vulnerability in American infrastructure security, where fragmented ownership, aging technology, and limited cyber workforces create openings for state-directed sabotage. The strategic challenge is no longer attribution but deterrence. Without credible offensive options or resilient defenses, Washington remains in a reactive posture against an adversary that has integrated cyber coercion into its broader warfighting doctrine.
Why Iran Cyber Strategy Escalates
Iran is trying to turn off the water taps across the Persian Gulf region and in the United States. Washington is determined to stop the sabotage, partly through sanctions. The US Treasury launched Operation Economic Outcast to isolate the Islamic Republic of Iran’s economy with sanctions on nearly 60 entities, individuals, and vessels. The targets included five members of a group directed by Iran’s Ministry of Intelligence that “is responsible for extensive compromises of US critical infrastructure and financially motivated cyber theft.”

Sanctions Alone Fall Short
The announcement came roughly a month after Iranian hackers reportedly carried out cyberattacks on water and wastewater systems across as many as 12 states, disrupting remote-control capabilities and water-pressure systems. US government agencies had warned in April of an “urgent and ongoing” threat from an Iran-affiliated campaign targeting American infrastructure, including water facilities.
In the current conflict with the United States, Tehran has tried to bring maximum pressure to bear on Washington in both the cyber and kinetic realms. Cyber operations are part of Tehran’s playbook, and Washington needs ways to impose costs on the actors ordering and carrying them out beyond sanctions and prosecutions.
Distance changes Tehran’s weapons, not its target set. Cyber operations let Iran reach American critical infrastructure that lies beyond the range of its missiles and drones, unlike US allies in the Persian Gulf who are reachable by kinetic means.
Desalination Plants Become Targets
The Islamic Republic has targeted civilian infrastructure across the Persian Gulf from the first day of the war, turning to critical infrastructure that is essential for life in the region. An Iranian drone attack damaged a water desalination plant on March 8, according to Bahrain’s Ministry of Interior. Iranian Foreign Minister Abbas Araghchi accused the United States of attacking Iranian desalination first. However, there is limited independent verification, and a US Central Command spokesperson responded to Araghchi’s allegations with “US forces do not target civilians—period.”
The Islamic Republic also struck a desalination plant in Kuwait in April and again in July and threatened water infrastructure across the region. In August, the regime renewed its threats to attack critical water infrastructure, among other sectors, if the United States resumed attacks.
Nearly all Gulf countries rely on desalination for more than 80 percent of water needs. The Islamic Republic is betting that fear of a humanitarian crisis will push Gulf countries to pressure the United States to end the war.
The reach of its conventional weapons does not constrain Tehran’s attacks on critical infrastructure. Cyberattacks enable Iran to threaten the West as it does the Middle East.

A Decade of Iranian Hacking
The recent campaign against American water systems builds on more than a decade of efforts. In 2013, an Islamic Revolutionary Guard Corps-affiliated hacker gained access to a New York dam and could have manipulated a sluice gate controlling water levels and flow rates. The gate was disconnected for maintenance, preventing remote operation, while the intrusion still cost more than $30,000 to remediate. In 2020, Iranian hackers targeted Israeli water facilities to manipulate chlorine levels. Three years later, the IRGC hackers compromised US water systems, prompting the US Treasury to sanction six officials from the Guards’ Cyber-Electronic Command.
Fragile Water Systems at Risk
The United States is crisscrossed with nearly 170,000 water and wastewater systems. Many rely on aging technology, and even minor disruptions can create immediate physical and public-health consequences. Cybersecurity workforce and funding gaps make the problem more acute.
The United States isn’t the only Western country on Iran’s target list. As the American water systems were being attacked, Tehran’s hackers took a UK power plant offline for about four days. British officials would not name the plant, but said it was small and did not affect the United Kingdom’s broader power capacity. It was the first reported instance of a cyberattack knocking a British power plant offline.

Iran Cyber Strategy Faces Pushback
To fight back, the Department of Justice unsealed the indictment on August 18 against 17 members of the Mabna Institute, an Iranian hacking company. Mabna stole data from more than 380 universities, companies, and government agencies worldwide—about half in the United States—since 2013 on behalf of various regime entities including the IRGC. But these measures by themselves leave Washington reacting to attacks rather than disrupting them.
The Trump administration has launched a new offensive by authorizing vetted US companies, under federal direction, to conduct cyber operations against foreign “Cyber-Enabled Transnational Criminal Organizations.”
The August 12 memorandum does not mention foreign governments or adversaries, but it creates a pathway to turn US private-sector capabilities against some of the cyber actors Tehran employs.

