Federal agencies say cyberattacks against municipal water and wastewater systems were reported in at least seven states this week, prompting an urgent advisory from the FBI and the Environmental Protection Agency. Officials warned that malicious actors have been trying to disrupt critical water infrastructure and urged utilities to take immediate protective steps.
The agencies’ public notice said utilities have reported incidents to the FBI and that some of the intrusions degraded operations. The advisory did not list the affected states. Separately, law enforcement officials have said a recent campaign in Minnesota hit more than 30 municipal water facilities and showed signs consistent with activity attributed to Iran-linked actors, though investigators have not publicly confirmed a specific perpetrator.
Minnesota authorities said there is no indication that any public water supplies were contaminated. The federal Cybersecurity and Infrastructure Security Agency (CISA) noted in its own alert that some larger water infrastructure intrusions elsewhere have led to boil-water notices and prolonged manual operations, but it did not identify locations for those impacts.
Technical details in the FBI/EPA bulletin describe attackers remotely accessing internet-facing devices used to manage water systems, changing IP addresses and passwords, and removing operators’ monitoring and control capabilities. The agencies warned that certain brands of operational control equipment—particularly programmable logic controllers (PLCs) and other industrial control devices—were being targeted. They recommended removing PLCs from direct internet exposure by placing them behind secure gateways and firewalls, enforcing strong passwords, and restricting device-to-device communications with access control lists.
State-level responses varied. A Wisconsin Department of Natural Resources bulletin alerted water utilities that intelligence suggested some systems in Wisconsin might be susceptible to connections by malicious actors and urged immediate mitigation. Minnesota’s information technology agency disputed parts of Wisconsin’s bulletin, saying Minnesota has not reported pressure drops across multiple systems or law enforcement responses tied to pressure changes. Emily Zimmer, a Minnesota IT spokesperson, also emphasized that attribution requires careful technical and intelligence analysis and that federal partners are leading that work.
The incidents have drawn attention amid broader warnings from U.S. agencies about aggressive cyber activity traced to Tehran-linked groups. Late last month, CISA and other federal partners urged critical infrastructure operators to harden defenses after public assessments that Iran-backed actors were attempting to penetrate online automated devices used in infrastructure management.
The situation drew political reactions as well. Former President Donald Trump publicly criticized Minnesota leaders, while Gov. Tim Walz responded by saying the attacks reflect modern warfare and criticized the federal response to threats tied to the conflict with Iran.
Cybersecurity experts say the strikes highlight vulnerabilities in the operational technology that runs water systems and the need for more public awareness and readiness. Bryson Bort, founder of industrial control system cybersecurity firm Scythe, said the disclosures underscore that there are adversaries willing to harm U.S. infrastructure and that utilities and policymakers must prepare accordingly.
The FBI and EPA advisory focused on practical defenses rather than naming culprits: segmenting and shielding control systems from the public internet, enforcing robust authentication, monitoring for unauthorized connections, and limiting control communications to authorized devices. Agencies urged operators nationwide to implement those measures quickly to reduce the risk of further disruption.