Key facts:
- Cyberattacks hit water and wastewater utility systems in at least 7 US states starting around July 27, 2026
- More than 30 municipal water systems in Minnesota were affected, the largest concentration so far
- Michigan later confirmed hackers targeted 9 of its water systems
- US investigators are examining whether Iran-linked actors are behind the activity, though attribution hasn’t been confirmed
- No utility has reported unsafe drinking water, several switched to manual operations as a precaution
- The FBI, CISA, and EPA issued a joint advisory warning utilities nationwide to secure their operational technology
What actually happened
Starting in late July 2026, water and wastewater utilities across at least seven US states reported unauthorized access attempts to their operational technology, the industrial control systems that manage pumps, valves, and treatment processes rather than the office networks people usually think of when they hear “cyberattack.” In Minnesota, more than 30 municipal water systems were affected, prompting some utilities to switch to manual operations while investigators worked to confirm the intruders no longer had access. Michigan reported a similar pattern days later, with nine water systems affected, though officials there said all systems continued operating safely throughout.
How the attackers got in
According to federal investigators, the pattern across affected utilities involved hackers remotely accessing internet-facing devices tied to operational technology, then changing IP addresses and passwords in a way that locked normal operators out of monitoring and control systems. This is a known weak point across the water sector nationally: much of the equipment running smaller municipal utilities was built before internet connectivity was a serious design consideration, and remote-access features added later for convenience often ship with weak or default credentials that are easy to find and exploit. Our broader cybersecurity coverage tracks this kind of critical-infrastructure targeting as it develops.
Why attribution is still unconfirmed
US officials say the intrusion has characteristics consistent with previous Iran-linked activity against water infrastructure, including a 2016 case where Justice Department charges were filed over an attack on a small dam near New York. That said, investigators have been explicit that attribution isn’t finalized, and they’re also examining the possibility that whoever carried this out deliberately left signs pointing toward Iran to escalate tension around the broader US-Iran relationship. Attribution in cases like this typically takes weeks, sometimes longer, since it requires tracing infrastructure and techniques back to a specific group with confidence, not just noticing a familiar pattern.
What federal agencies are telling utilities to do
The FBI, CISA, and EPA issued a joint advisory directing water and wastewater utilities nationwide to review their exposure, with the central recommendation being to disconnect programmable logic controllers, the devices directly controlling physical equipment, from open internet access entirely. Where remote access is genuinely necessary for smaller utilities with limited staff, agencies recommended routing it through a VPN or a dedicated secure gateway rather than leaving a device reachable directly from the open internet, which is the exposure pattern investigators say was exploited here.
The bigger pattern this fits into
Water utilities have become a recurring target in this kind of critical-infrastructure activity for a structural reason, not a coincidental one: the sector is large, mostly locally run, and chronically underfunded relative to the systems it protects. A major metro utility might have a dedicated security team, but a lot of the roughly 50,000 community water systems in the US are run by small municipal staffs without a full-time cybersecurity role at all. That gap is exactly what federal advisories like this one are aimed at closing, treating basic technical hygiene, no PLCs facing the open internet, no default passwords, as a baseline rather than an upgrade. For more on how this fits into the broader technology landscape, our Technology section covers related developments as they happen.
FAQ
Has anyone’s drinking water actually been contaminated or made unsafe?
No utility has reported unsafe drinking water as a result of these incidents. Officials in Minnesota and Michigan both said systems continued operating safely, with some switched to manual control as a precaution while investigators worked.
Is it confirmed that Iran was behind the attack?
No. US officials say the activity has characteristics consistent with prior Iran-linked incidents, but attribution has not been finalized, and investigators are also considering whether the actor deliberately mimicked Iranian tactics.
Which states were affected besides Minnesota and Michigan?
The FBI’s advisory referenced incidents in at least seven states without naming all of them publicly. Minnesota and Michigan are the two states that have been officially confirmed and named so far.
What should smaller water utilities do right now?
Federal agencies recommend disconnecting programmable logic controllers from direct internet access, using a VPN or secure gateway for any necessary remote access, and changing default credentials on internet-facing operational technology.
