U.S. Warns Water Utilities to Strengthen Cyber Defenses After Coordinated Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that cyberattacks targeting water and wastewater systems are increasing, urging utilities to immediately remove internet-exposed operational technology from public access to reduce the risk of disruption.

The warning follows coordinated cyber incidents that targeted more than 30 community water systems in Minnesota during July 26–27. While officials said the attacks did not compromise drinking water quality, several facilities experienced operational disruptions that required manual intervention.

The incidents have renewed concerns about the vulnerability of critical infrastructure as governments confront increasingly sophisticated cyber threats believed to originate from nation-state actors.


Quick Facts

  • CISA reported a significant rise in cyberattacks targeting water and wastewater infrastructure.
  • More than 30 Minnesota community water systems were targeted during coordinated attacks on July 26–27.
  • Drinking water safety was not compromised, according to state officials.
  • The FBI said utilities in at least seven U.S. states have reported related cyber incidents.
  • Authorities are investigating whether the attacks can be formally linked to an Iran-affiliated threat actor.

What Happened in Minnesota?

Minnesota's state information technology agency said attackers targeted dozens of community water systems over a two-day period.

Although the attacks did not contaminate drinking water, some affected utilities temporarily took critical systems offline while operators restored services manually.

Most confirmed incidents involved industrial control technologies, including programmable logic controllers (PLCs) and operator interface systems used to monitor and manage water infrastructure.

According to CISA, attackers in several cases changed system passwords, preventing operators from accessing essential equipment and forcing some devices to disconnect from operational networks.

The agency also said similar attacks have, in some instances, resulted in boil water notices and required utilities to operate systems manually until access could be restored.


How Widespread Are the Cyber Incidents?

The FBI said water and wastewater utilities in at least seven U.S. states have reported related cyber incidents.

According to federal investigators, some attacks disrupted normal water operations, causing operational problems such as reduced water pressure and localized flooding at certain facilities.

Investigations remain ongoing to determine whether the incidents share a common origin or represent multiple coordinated campaigns.

Minnesota officials continue to assess the extent of the attacks alongside federal cybersecurity agencies.


What Systems Were Targeted?

Direct Answer

The attacks primarily targeted operational technology (OT) used to control water infrastructure, including programmable logic controllers (PLCs) and industrial control systems that manage pumps, valves, monitoring equipment, and other essential operations.

Unlike traditional office computer networks, operational technology directly controls physical infrastructure. Disrupting these systems can affect the delivery of essential public services even if customer data remains untouched.

CISA has therefore urged utilities to disconnect internet-facing operational systems whenever possible and strengthen network protections around critical infrastructure.


Who Is Suspected of Carrying Out the Attacks?

Reuters reported that U.S. officials and investigators reviewing the incidents believe Iran-linked hackers are the most likely suspects, citing information also reported by The New York Times.

However, federal authorities have not formally attributed the attacks to Iran.

The FBI has not publicly confirmed Iranian involvement, and Iranian officials had not responded to requests for comment at the time of reporting.

Because cyber attribution often requires extensive forensic analysis, governments typically avoid making formal accusations until investigations are complete.

 


Why Governments Are Increasingly Focused on Critical Infrastructure Cybersecurity

The attacks highlight a broader challenge facing governments worldwide: protecting essential public services from increasingly sophisticated cyber threats.

Critical infrastructure—including water systems, energy grids, hospitals, transportation networks, and communications services—has become an attractive target for cyber actors because disruptions can affect large populations and create significant economic consequences.

In April, CISA, the FBI, the National Security Agency (NSA), and other federal agencies jointly warned that Iranian-affiliated groups had been targeting industrial control systems across multiple sectors.

That advisory was updated on July 22 to include additional targeted devices and newly observed attack techniques, reflecting the evolving nature of these cyber campaigns.

Governments are responding by expanding information sharing between federal agencies and local utilities, encouraging stronger cybersecurity standards, reducing internet exposure for operational systems, and improving incident response capabilities.


Experts Say the Incidents May Represent an Escalation

Former senior FBI cybersecurity official Cynthia Kaiser said the Minnesota attacks closely resemble previously documented campaigns attributed to Iranian-affiliated cyber groups.

Cybersecurity specialists also noted that the temporary shutdown of operational systems represents a potentially more disruptive approach than earlier attacks that primarily focused on gaining unauthorized access without affecting day-to-day operations.

If confirmed, the incidents could signal a shift toward cyber operations capable of creating immediate operational consequences for critical infrastructure providers.

 


What Happens Next?

Federal and state authorities continue investigating the Minnesota incidents to determine who was responsible and whether additional utilities were affected.

CISA and the FBI are also evaluating evidence to establish whether the attacks can be formally attributed to a specific threat actor.

In the meantime, federal agencies are urging water utilities across the country to review cybersecurity practices, secure industrial control systems, and minimize internet exposure for operational technology.


Why It Matters

The recent cyberattacks underscore how digital threats have become a national security concern rather than solely an information technology issue. Water systems, power grids, transportation networks, and healthcare facilities increasingly rely on connected operational technology that can become a target for sophisticated cyber campaigns.

As governments strengthen cybersecurity strategies to protect critical infrastructure, organizations responsible for essential services are being encouraged to improve network resilience, limit internet exposure of industrial systems, and prepare for faster incident response. The outcome of the ongoing investigations may also shape future cybersecurity policies aimed at defending critical infrastructure against nation-state threats.