July 31, 2026

Cyberattacks Threaten Municipal Water Systems Across Seven States

Cyberattacks aimed at municipal water systems have been reported in seven states recently. The FBI and the Environmental Protection Agency have warned utilities nationwide about hackers trying to disrupt crucial water infrastructure.

In a public announcement, these agencies stated that water and wastewater utilities have contacted the FBI due to some malicious activities impacting water operations. While specific states were not named, the warning followed hackers targeting over 30 municipal water facilities in Minnesota. This attack showed signs of Iranian interference, as noted by a law enforcement official, and is under investigation.

A spokesperson from Minnesota’s information technology services agency confirmed through email that the breaches did not contaminate any municipal water supplies.

The federal advisory highlighted that malevolent cyber actors targeted particular brands of control systems within municipal water utilities. Nevertheless, the FBI and EPA urged operators of various systems to exercise caution. The warning underscores the vulnerability of certain U.S. infrastructure systems to interference by adversaries. This concern arises amid escalating military conflict involving Iran and challenges faced by the U.S. and Israel.

During the recent cyberattack, state officials reported that more than 30 water systems in Minnesota, including Plymouth’s, were affected. Hackers remotely accessed internet-connected devices, altered IP addresses and passwords, and disrupted monitoring and control capabilities for the utilities.

The federal advisory recommends removing programmable logical controllers (PLCs) from direct internet exposure. Systems should be placed behind secure gateways and firewalls. Strong passwords should be used, and communications should be limited to authorized control system devices via access control lists.

While the agencies have not identified those responsible for the breaches, U.S. government and state officials have also abstained from publicly attributing the malicious activity in Minnesota to any specific actor.

Emily Zimmer, a spokesperson for Minnesota’s information technology agency, stated that identifying the perpetrators requires a thorough analysis of technical evidence along with broader threats at the national and international levels.

The Minnesota breach occurred shortly after U.S. officials warned of Iran-backed hackers targeting critical infrastructure. In a July 22 advisory, the Cybersecurity and Infrastructure Security Agency, alongside the FBI and federal agencies, encouraged businesses to bolster defenses against Tehran-linked hackers who are attempting to breach online automated devices managing infrastructure systems.

U.S. intelligence agencies have issued warnings about Iran’s growing capability and willingness to execute aggressive cyber operations, including targeting water systems in 2023.

In May 2024, the EPA warned about the increasing frequency and severity of cyberattacks on water utilities. During inspections over the past year, federal officials found that approximately 70% of utilities had violated standards designed to prevent such breaches.

TAGS: