Cyberattacks disrupt water facilities across seven US states
Cyberattacks disrupted water facilities across seven US states, prompting fresh FBI and EPA warnings over critical infrastructure security.
US authorities have issued an urgent warning after a series of cyberattacks targeted water and wastewater facilities across seven states, disrupting operations and raising concerns about the security of critical infrastructure.
Table Of Content
According to a joint public service announcement from the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA), at least seven utility providers have experienced cyber incidents since 27 July. The attacks have affected water operations, with officials warning that the consequences could extend beyond temporary service disruption if systems remain vulnerable.
Authorities warn of growing threat to water infrastructure
The FBI said cybercriminals are targeting Programmable Logic Controllers (PLCs), which are used to monitor and control industrial equipment in water and wastewater facilities. Investigators found that attackers were remotely accessing internet-facing devices before changing internet protocol (IP) addresses and passwords, effectively locking operators out of critical systems.
By taking control of these devices, the attackers prevented utility staff from monitoring and managing essential processes. Officials said this has already resulted in operational problems at several affected facilities, demonstrating how cyber intrusions can quickly translate into real-world disruptions.
The FBI reported receiving information about incidents that caused water pressure to drop and, in some cases, flooding. While low water pressure alone can inconvenience customers, authorities stressed that the wider implications could be far more serious. Reduced pressure may allow untreated groundwater to enter water distribution pipes, posing potential public health risks and significantly increasing operational impacts on affected utilities.
In response, federal agencies have urged water providers to strengthen their cyber defences immediately. Recommended measures include placing industrial control systems behind secure gateways and firewalls to reduce direct exposure to the internet. Utilities have also been advised to implement stronger password policies and configure access control lists to permit only authorised devices and communications within operational networks.
Officials believe these measures could reduce the likelihood of unauthorised access and make it more difficult for attackers to compromise critical systems.
Minnesota attacks add to concerns over wider campaign
The latest warning follows another wave of cyber incidents involving municipal water facilities in Minnesota. More than 30 facilities in the state were reportedly infiltrated during the previous week, prompting further concern among federal and state authorities.
According to NBC News, the attacks in Minnesota displayed characteristics commonly associated with Iranian cyber operations. However, investigators have not formally attributed responsibility, and law enforcement agencies continue to examine the evidence before reaching any conclusions.
A separate report by Wired said it had reviewed an internal memorandum linking the Minnesota incidents to Iran. The document was reportedly distributed to members of the Water Information Sharing and Analysis Centre (WaterISAC), an industry organisation that shares cybersecurity information with water utilities across the United States.
The memorandum stated that the Minnesota Fusion Centre, a state-level intelligence-sharing organisation, had warned that the “ongoing malicious cyber activity impacting public drinking water systems across Minnesota” matched a hacking campaign previously identified by the US Cybersecurity and Infrastructure Security Agency (CISA).
Although the investigation remains active, the similarities between the recent attacks and previously documented campaigns have heightened concern among security professionals responsible for protecting critical infrastructure.
Cybersecurity agencies urge stronger protections
The recent incidents reinforce warnings issued earlier this year by CISA regarding cyber threats to essential infrastructure. In April, the agency alerted organisations that “Iran-affiliated” hackers were targeting sectors including water infrastructure as part of broader malicious cyber activity.
Water treatment facilities have increasingly become attractive targets because many rely on industrial control systems that were designed primarily for operational efficiency rather than modern cybersecurity. In some cases, internet-connected equipment can provide attackers with a pathway into systems that manage essential public services.
Security experts have repeatedly warned that cyberattacks on critical infrastructure are becoming more frequent and more sophisticated. Rather than focusing solely on stealing data, attackers are increasingly attempting to disrupt physical operations, posing risks that can directly affect communities.
The FBI and EPA are encouraging utilities to review their cybersecurity practices, restrict remote access wherever possible, and ensure industrial systems are not unnecessarily exposed to the public internet. Strong authentication, regular password updates and carefully managed network access are among the key steps authorities recommend to reduce risk.
While investigators continue working to identify those responsible for the latest attacks, the incidents highlight the growing importance of protecting critical infrastructure from evolving cyber threats. As water utilities continue modernising their operations, federal agencies are urging organisations to treat cybersecurity as a core part of maintaining safe and reliable public services.





