Cyberattacks targeting water and wastewater facilities have spread across at least seven US states, raising urgent concerns about the security of essential public infrastructure. The incidents reportedly interfered with equipment used to monitor and control water operations, producing effects that included reduced water pressure, flooding, loss of remote access, and temporary reliance on manual controls.
The attacks demonstrate how a relatively simple intrusion into internet-connected industrial equipment can create physical consequences for communities. Although authorities have not reported widespread contamination or a prolonged national water outage, the campaign has prompted federal agencies to warn utilities that poorly protected operational technology may remain exposed to further attacks.
FBI Confirms Incidents Across at Least Seven States
The Federal Bureau of Investigation confirmed that water and wastewater utilities in at least seven states had reported cyber incidents beginning on July 27, 2026. Federal authorities have not publicly released a complete list of the affected states, which means the geographical scope remains only partially known.
According to the official FBI cybersecurity alert, attackers targeted operational technology devices, particularly Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers. These devices are commonly used to monitor equipment and automate processes within industrial facilities.
After gaining remote access, the attackers reportedly changed device passwords and internet protocol addresses. These changes prevented some operators from viewing or controlling connected equipment through their usual digital interfaces. At least one affected organization also discovered unexpected changes in programmable logic controller project files.
The FBI said the consequences depended on how each compromised controller was configured. A controller used only for monitoring could leave operators without visibility, while a controller connected directly to pumps, valves, pressure equipment, or other machinery could interfere with physical operations.
Minnesota Water Systems Experienced Coordinated Attacks
Minnesota has emerged as the most clearly documented center of the campaign. More than 30 community water systems in the state were reportedly targeted during coordinated attacks on July 26 and July 27.
Several Minnesota communities disclosed temporary operational problems. In Braham, attackers reportedly shut down controls for a well and water treatment plant, leaving the city temporarily dependent on water stored in its tower. Residents were asked to reduce water use while operators worked to restore the system.
Plymouth also experienced a disruption involving communications with its water infrastructure. Crews continued operating the system while communications were restored, and city officials reported no effect on water levels or water quality.
An Associated Press report on the Minnesota attacks noted that being classified as an affected system did not necessarily mean that every community lost water service. In some locations, investigators found malicious activity in the operational technology without a major interruption to residents.
The similarities in timing, equipment, and network configuration have led investigators to examine whether the incidents were connected. However, authorities have not confirmed that a single group was responsible for every attack.
Attacks Caused Pressure Loss and Flooding
The most concerning part of the federal warning is that some incidents moved beyond unauthorized access and caused physical operational effects.
Victims reported water pressure loss and flooding following the attacks. A reduction in pressure can interrupt normal water delivery and may create additional safety concerns because low pressure can allow untreated groundwater or other contaminants to enter damaged or vulnerable pipes.
Some operators were locked out after attackers activated or changed passwords on exposed controllers. Other facilities reportedly disconnected equipment, issued boil-water notices, or maintained operations manually while compromised devices were inspected and restored.
According to Reuters coverage of the federal warning, the attacks led federal cybersecurity officials to urge operators to remove exposed control technology from the public internet as quickly as possible.
No broad failure of the national water system has been reported. Nevertheless, the operational consequences show that cyberattacks against industrial controllers can affect pumps, pressure, storage, treatment processes, and communications rather than remaining limited to stolen information.
Why Programmable Logic Controllers Were Targeted
Programmable logic controllers, commonly called PLCs, serve as the connection between software instructions and physical machinery. They can control pumps, valves, motors, treatment equipment, pressure systems, chemical processes, alarms, and other essential functions.
Remote access allows engineers and contractors to monitor these systems without being physically present at every facility. That convenience becomes a vulnerability when a controller is directly exposed to the internet, protected by a weak password, or connected through an inadequately secured modem.
Older equipment can create additional risk. Some water systems continue operating controllers that have reached the end of their manufacturer-supported life. Once support ends, the device may stop receiving security patches even though it remains responsible for an important physical process.
Shared network configurations can also expand the scale of an attack. The FBI warned that similar setups provided by third-party contractors may allow attackers to repeat the same technique across multiple customers. A weakness found in one standard configuration could therefore expose several facilities using the same hardware and remote-access arrangement.
Possible Iranian Connection Remains Unconfirmed
US officials and cybersecurity specialists are investigating whether Iranian-affiliated attackers were involved. The latest incidents resemble earlier campaigns in which Iranian-linked groups targeted internet-facing industrial controllers used by water utilities and other critical infrastructure organizations.
In April 2026, the Environmental Protection Agency, FBI, Cybersecurity and Infrastructure Security Agency, and National Security Agency issued a joint warning about an ongoing Iranian-affiliated threat to operational technology. That campaign involved the disruption of human-machine interfaces, manipulation of mechanical sensors, erased configurations, operational interruptions, and financial losses.
The EPA’s joint cybersecurity advisory warned that attacks against drinking-water and wastewater systems could disrupt treatment, damage equipment, create contamination risks, and weaken public confidence in essential services.
A separate federal advisory stated that Iranian-affiliated actors had targeted internet-exposed PLCs across water, energy, government, and facility-management environments. Some victims experienced operational disruption after attackers accessed controllers and manipulated files or information displayed through industrial monitoring systems.
Despite those similarities, the FBI has not publicly attributed the seven-state campaign to a specific government, organization, or hacking group. Any direct attribution to Iran therefore remains an assessment rather than a confirmed conclusion.
Smaller Water Utilities Face Greater Cybersecurity Pressure
The attacks highlight a long-standing challenge within the US water sector. Many community systems operate with limited budgets, small technical teams, aging equipment, and a mixture of modern and legacy technology.
A large organization may employ dedicated cybersecurity staff who continuously monitor networks and manage incident response. A small municipal water utility may depend on a few employees, outside contractors, and remote access to keep facilities operating across several locations.
This resource gap can delay software updates, equipment replacement, network segmentation, security testing, and detailed asset management. It can also make older controllers attractive targets because attackers may discover them through automated internet scans before the utility realizes the device is publicly accessible.
Water systems are particularly sensitive because they cannot simply shut down operations for an extended period while a cyber investigation takes place. Communities, hospitals, emergency services, businesses, and households depend on continuous water delivery and wastewater treatment.
Federal Agencies Call for Immediate Security Changes
The FBI and EPA have advised utilities to remove PLCs from direct public internet exposure and place remote connections behind secure gateways and firewalls. Controllers should use strong, unique passwords, while network access rules should permit communication only from approved devices and locations.
Operators are also being advised to inspect controller project files for unauthorized changes, review logs from modems and connected workstations, verify clean backups, and check whether attackers moved from one device to another.
Manual operating capability remains especially important. A facility that can safely control pumps and other equipment without its normal digital interface may continue delivering essential services while compromised technology is isolated.
The federal alert also encourages utilities to identify end-of-life equipment and establish replacement plans. Where immediate replacement is not possible, vulnerable devices may need to be isolated and protected through additional security controls.
Water Infrastructure Has Become a Cybersecurity Priority
The attacks across seven states show that water security now depends on both physical maintenance and digital protection. A properly maintained pump can still become unavailable when the controller operating it is exposed to unauthorized access.
The campaign did not create a nationwide water emergency, but it revealed how local vulnerabilities can be exploited across multiple communities in a short period. It also demonstrated that cyber incidents can produce real-world effects such as pressure loss, flooding, temporary outages, and manual operations.
As investigations continue, the focus will remain on identifying the responsible actors, determining the full number of affected facilities, and reducing exposure before another campaign causes more serious damage. For water utilities, cybersecurity is no longer limited to protecting office computers or customer information. It has become an essential part of protecting treatment systems, equipment, public health, and the continuous delivery of one of society’s most important services.