U.S. Water Utilities Report Cyber Incidents in Multiple States

Water and wastewater utilities across the United States have reported a wave of cyber incidents affecting facilities in at least seven states. Minnesota authorities said on July 28 that water treatment plants serving more than 30 communities had been hit in coordinated attacks. The FBI said two days later that incidents at utilities in at least seven states had, in some cases, degraded water operations.
Reports have since emerged from Arkansas, Georgia, New Jersey and Michigan, in addition to Minnesota. The incidents have drawn particular concern because the United States has more than 150,000 water systems, many operated by local organisations that may have limited cybersecurity resources and specialist expertise.
Attribution remains unconfirmed
The U.S. government has not publicly named the actor responsible for the campaign. Iran is the leading suspect in reporting on the incidents, following a warning from the Cybersecurity and Infrastructure Security Agency that Iranian hackers were targeting internet-connected devices in water systems and the energy sector. CISA had first issued that warning in April and updated it before the Minnesota incidents.
WaterISAC, the nonprofit information-sharing group for the water sector, told members that the reported activity aligned with the campaign described in CISA’s warning. The Washington Post also reported that U.S. intelligence agencies were confident Iran, particularly the Islamic Revolutionary Guard Corps, was responsible, although no public attribution had been made and the specific unit was not identified.
Operational disruption and exposed controllers
The reported impact was not uniform, but the FBI said some incidents resulted in loss of pressure and flooding. Loss of pressure could potentially allow untreated groundwater to seep into pipes. In Braham, Minnesota, a water plant was taken offline for several hours and the town urged its approximately 1,700 residents to conserve water. Maple Plain briefly declared a state of emergency.
In a county outside Atlanta, local officials temporarily advised residents to boil water as a precaution. These events illustrate how disruption to operational systems can quickly become a public-service and communications issue, even where lasting damage has not been reported.
Internet exposure is a material concern. Cybersecurity firm Forescout said it found more than 2,800 controllers in U.S. water systems exposed online. Exposure alone does not mean an attacker can take control of a process or create physical effects, but recent cases show that accessible systems can contribute to operational disruption.
What water operators should take from the incidents
For water operators and other critical-infrastructure organisations, the immediate practical implication is to identify internet-facing operational technology, limit and secure remote access, and ensure teams can respond safely if digital controls are disrupted. The incidents also underline the need for incident procedures that address both plant operations and timely communication with customers and local authorities.

