FBI and CISA Warn of Cyberattacks on Water Systems Across Seven States
Federal agencies are investigating a coordinated campaign targeting internet-facing controllers in municipal water facilities.
The FBI, EPA, and CISA have issued an urgent warning after a series of cyberattacks targeted municipal water and wastewater systems across at least seven U.S. states. The campaign, which began around July 26-27, 2026, represents a significant breach of critical infrastructure that forced some utilities to abandon automated systems.
According to federal officials, the attackers specifically targeted internet-facing programmable logic controllers (PLCs). These devices are essential for monitoring water pressure and managing chemical dosing. The impact was most severe in Minnesota, where more than 30 municipal water systems were hit. While some utilities were forced to switch to manual operations and issue boil-water notices to ensure safety, officials confirmed that no water contamination has been reported.
A Pattern of Vulnerability
This incident occurs as the U.S. water sector continues to struggle with chronic underfunding and a lack of specialized cybersecurity training. The current attacks mirror a pattern of activity linked to Iranian actors who have previously targeted U.S. industrial sites. In a similar 2023 campaign, hackers successfully exploited default passwords on internet-connected controllers to gain unauthorized access to operational technology.
National Security Implications
The scale and coordination of these attacks are described as unprecedented by experts. Gus Serino, a cybersecurity specialist, noted that the level of coordination seen in the Minnesota attacks is without precedent. Because water infrastructure is vital for hospital operations and basic survival, the ability of foreign actors to disrupt operational technology via simple internet-facing vulnerabilities poses a severe national security risk. The incident highlights a critical gap in the protection of the nation's most basic utilities.
Ongoing Investigations
Federal agencies are currently investigating the origin of the attacks, with a focus on potential links to Iran. However, the attribution remains a point of contention; U.S. President Donald Trump stated he does not believe an Iranian cyberattack was responsible, suggesting instead that the issue may be centered within Minnesota. Investigators continue to analyze the PLCs to determine the full extent of the breach and whether other states remain at risk.