Federal investigators are sounding the alarm after a wave of cyberattacks that hit water and wastewater systems in at least seven states, with some operations knocked offline or forced into manual mode.
The FBI and Environmental Protection Agency issued a joint public service announcement on July 30 confirming that utility companies have been reporting incidents since July 27. In several cases the attacks degraded actual water operations: loss of pressure, flooding, and disruptions that in some instances prompted boil-water notices.
According to assessments shared with U.S. and state officials, Iranian-affiliated actors are the leading working theory behind the activity.
Investigators treat that assessment as fluid and remain alert to possible false flags amid broader geopolitical tensions.
More than 30 community water systems in Minnesota were targeted in a coordinated wave over the July 26–27 weekend.
Hackers locked operators out after changing passwords and IP addresses on internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers, the small industrial computers that run pumps, valves, and pressure monitors.
Once those settings were altered, some plants lost all remote visibility and control and had to fall back to manual operation.
Minnesota officials said there was no indication of contamination or compromised water quality, and no widespread boil-water notices specific to Minnesota supplies from these incidents.
Officials have not publicly named the other six states, and the exact number of systems affected outside Minnesota has not been released. CISA described the activity as a “significant escalation.” The attackers target devices left sitting on the public internet, alter configurations, and move on.
The real risk is contamination. When system pressure drops, untreated groundwater can be pulled into the pipes, the scenario utility managers fear most.
So far no confirmed cases of actual water contamination have been reported, but the pathway is real and the margin for error is thin.
Many smaller utilities still run older controllers that are vulnerable and were never meant to be left constantly reachable from the internet.
Weak or default passwords, direct internet connections, and a lack of basic network barriers turn ordinary equipment into easy targets. Larger, better-protected systems avoided lasting disruption, while those that left their controllers open to the internet were forced into prolonged manual operations. This readiness gap between well-resourced utilities and smaller community systems is now impossible to ignore.
The solution, according to the agencies, is straightforward.
Water utilities have been instructed to remove the controllers from the public internet, place them behind firewalls and secure gateways, use strong unique passwords, lock access with control lists, and leave the physical mode switches set to “Run.”
They are also being told to maintain the ability to run everything manually and to check project files for signs of tampering. Older hardware that is no longer supported by the manufacturer needs a replacement plan sooner rather than later.
This is not the first time water systems have been targeted. Iranian-linked groups have previously compromised municipal systems, most notably the 2023 intrusion at the Municipal Water Authority of Aliquippa in Pennsylvania and a June 2026 incident involving California Water Service. The geographic reach and real operational damage in the current wave, however, put it among the more serious episodes in recent years.
The response remains focused on containing the damage with simple, essential safeguards, mainly getting the devices offline and behind basic protections.
Water is still flowing in the affected communities, and crews have kept the systems running the hard way whenever the screens went dark. The message from the FBI and EPA is unambiguous: these devices should never be left reachable from the open internet, and the window to fix that is closing fast.
The Trump Administration will meet this threat with steady resolve, focused on both resolving the vulnerabilities and holding those responsible to account.