U.S. authorities have issued an urgent cybersecurity warning after a wave of attacks targeted drinking water and wastewater systems across multiple states. The FBI and the Environmental Protection Agency (EPA) say hackers have compromised critical infrastructure by exploiting internet-connected industrial control systems, causing operational disruptions at several utilities. The warning comes as officials work to determine the full scope of the attacks and strengthen defenses against future incidents.
According to the agencies, at least seven water and wastewater utilities have experienced cyberattacks since July 27, with some facilities reporting disruptions that affected normal operations. While there is no indication that drinking water quality has been compromised, officials warn that attacks on water infrastructure can quickly create risks for public health and essential services.
Hackers Targeted Internet-Connected Control Systems
In a public service announcement, the FBI said the attackers have been focusing on Programmable Logic Controllers (PLCs), which are widely used to automate and control industrial equipment at water treatment facilities. Investigators said the hackers gained remote access to internet-facing devices before changing passwords and network settings, preventing operators from monitoring and managing critical systems.
The FBI also revealed that several affected facilities experienced loss of water pressure and flooding after their operational technology was disrupted. Officials warned that reduced water pressure could allow untreated groundwater to enter water distribution systems, creating a much more serious problem than temporary service interruptions. The agencies are urging utilities to disconnect vulnerable operational technology from direct internet access wherever possible and strengthen network security through firewalls, secure gateways and stricter access controls.
Authorities are also encouraging operators to implement stronger password policies and configure access control lists so only authorized devices can communicate with industrial control systems. These recommendations form part of a broader effort to improve cybersecurity across critical infrastructure sectors that increasingly rely on internet-connected operational technology.
Minnesota Attacks Intensify Security Concerns
The latest warning follows another series of cyber incidents that affected more than 30 municipal water systems in Minnesota during the past week. Several communities temporarily experienced operational disruptions, prompting local authorities to ask residents to reduce water usage while technicians restored systems. Although water quality was not reported to be compromised, investigators described the incidents as a significant cybersecurity event affecting public infrastructure.
Investigators are examining whether the attacks are linked to a broader campaign previously associated with Iranian-affiliated hackers. Earlier this year, the EPA, FBI, CISA and other U.S. agencies jointly warned that Iranian-linked cyber actors were actively targeting internet-connected PLCs used across multiple critical infrastructure sectors, including drinking water and wastewater facilities. However, officials have not formally attributed the latest attacks to any specific group, and the investigation remains ongoing.
The issue has also become politically charged after President Donald Trump said he did not believe Iran was responsible for the Minnesota incidents, despite reports that investigators are examining possible links to previously identified Iranian cyber campaigns. Federal authorities have continued to emphasize that the investigation has not reached an official attribution.
Critical Infrastructure Faces Growing Cyber Threats
Cybersecurity experts have repeatedly warned that water utilities are becoming increasingly attractive targets because many rely on aging operational technology connected to modern networks. Smaller municipal systems often have limited cybersecurity budgets and fewer dedicated security professionals, making them more vulnerable to attacks on industrial control equipment. Federal agencies have expanded guidance and free technical assistance programs in recent months to help utilities identify vulnerabilities and improve cyber resilience.
The latest incidents underline the growing importance of protecting essential infrastructure as cyber threats become more sophisticated. While investigators continue working to identify those responsible, the FBI and EPA are urging utilities nationwide to review their cybersecurity practices immediately and secure internet-exposed operational systems before additional attacks occur.
