Cyberattacks disrupt water utilities across seven US states
The FBI and EPA warn that hackers have attacked water and wastewater systems in at least seven states, causing operational disruptions. Authorities suspect possible Iranian involvement in recent incidents in Minnesota.

Federal agencies have issued a public alert about a wave of cyberattacks targeting critical water infrastructure in the United States. According to the FBI and the Environmental Protection Agency, seven water and wastewater utilities have been affected since July 27, 2026, leading to degraded service.
The attackers reportedly focus on programmable logic controllers, which are used to automate water treatment and distribution. By gaining remote access through internet-connected equipment, they change IP addresses and passwords, locking operators out of their own systems. Victims have told the FBI that the intrusions led to flooding and a loss of water pressure.
Officials are urging utilities to reduce their exposure by using secure gateways and firewalls, choosing stronger passwords, and employing access control lists so that only authorized communication between devices is allowed. The FBI also warned that losing pressure could allow untreated groundwater to enter pipes, creating a much more serious problem than simply having low water pressure.
The warning follows a separate wave of breaches at more than 30 municipal water facilities in Minnesota over the past week. NBC News reported that those attacks had the hallmarks of Iranian interference. While law enforcement continues to investigate and has not confirmed the country's involvement, Wired said it had seen a memo tying the Minnesota incidents to Iran.
The memo was distributed to members of the Water Information Sharing and Analysis Center, an industry group for water utilities. According to the center, the Minnesota Fusion Center — a state-level intelligence-sharing body — warned that the ongoing malicious cyber activity against public drinking water systems in Minnesota matched a hacking campaign previously described by the US Cybersecurity and Infrastructure Security Agency (CISA). In April, CISA issued its own advisory saying Iran-affiliated hackers were targeting water facilities and other critical infrastructure.


