Water Sector Under Siege: Cyberattacks Spread Across 12 US States
A growing number of US states have been hit by a sophisticated hacking campaign targeting water and wastewater facilities, with at least 12 states confirmed to be affected so far. The attacks, which began in late July, have raised concerns about the potential for disruptions to critical infrastructure.
The first state to report attacks was Minnesota, where over 30 community water systems were targeted on July 26 and 27. Michigan has also confirmed that a small number of communities have been hit by malicious cyber activity, while South Dakota has reported a cyberattack in one of its cities. Georgia’s Clayton County Water Authority recently announced that it had experienced a temporary disruption to its operational systems and water service, resulting in reduced pressure in some areas.
Wisconsin has been mentioned as potentially affected, but officials have yet to confirm any intrusions. Meanwhile, several major water utilities have reported that they have not been impacted by the attacks. New York has not commented on whether it has been hit by the campaign, but officials this week announced over $9 million in grants to help 153 water systems boost their cybersecurity.
The FBI has shared details on the attackers’ actions and potential impact. The agency explained that the hackers are targeting programmable logic controllers (PLCs) made by Rockwell Automation, which are used to control industrial equipment. By remotely tampering with these devices, the attackers can change settings and turn off alarms, potentially allowing untreated water to seep into pipes.
The FBI has warned that the attacks could have significant consequences, including loss of pressure and flooding. In some cases, this could allow untreated groundwater to enter pipes, posing a risk to public health. The extent of the impact will depend on various factors, including the type of equipment controlled by the PLCs and the functionality of the devices.
The US has yet to officially attribute the attacks to any particular nation or group, but Iran has emerged as the primary suspect. Federal investigators have been looking into Iran’s potential involvement, and a non-public report from WaterISAC cited evidence that the attacks were aligned with previous hacking campaigns linked to Iran.
To help defenders protect against these types of attacks, CISA has urged the water sector to prioritize protecting operational technology (OT) systems, particularly PLCs. Federal agencies have also updated an April advisory on Iranian attacks aimed at OT devices, warning that ICS devices made by Siemens, Schneider Electric, and Rockwell Automation are vulnerable.
For those in the water sector, it’s essential to take immediate action to protect against these types of attacks. This includes implementing robust security measures, such as firewalls and intrusion detection systems, as well as regularly updating software and conducting vulnerability assessments. By taking proactive steps to secure their OT systems, organizations can help prevent disruptions to critical infrastructure and ensure public safety.
In addition to protecting individual facilities, it’s also crucial for the water sector to share information and best practices to stay ahead of emerging threats. By collaborating with federal agencies and other stakeholders, organizations can better understand the nature of these attacks and develop effective countermeasures.
Source: SecurityWeek — 2026-08-05