Cyberattacks targeting water and wastewater utilities have affected facilities in at least seven states, prompting a coordinated response from federal agencies and renewed warnings about the cybersecurity risks facing critical infrastructure.
More than 30 municipal water systems in Minnesota were targeted in late July, with additional attacks reported at nine water systems in Michigan. Some affected utilities temporarily switched to manual operations or shut down portions of their systems, although state officials said the incidents did not compromise drinking water quality and that systems continued to operate safely.
According to the FBI, EPA and the Cybersecurity and Infrastructure Security Agency, multiple incidents involved hackers remotely accessing internet-connected programmable logic controllers, changing administrator passwords and disrupting system operations.
Federal officials from the FBI and EPA said in a joint statement that the attackers targeted Rockwell Automation/Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 series. "Operational effects reported to the FBI have included loss of pressure and flooding," read the statement. "Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations."
The FBI and EPA recommended the following precautions for critical infrastructure asset owners and operators:
• Disconnect PLCs from the public-facing internet.
• Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable.
• Strictly control network access to PLC devices.
• Place physical and software key switches into the run position to block unauthorized changes to logic, configuration and firmware.
• Practice and maintain the ability to use operational technology systems manually.
• Review project files running on PLCs for unauthorized changes.
• Plan for end-of-life replacements for devices when possible.
Ongoing cyber threats
The incidents occurred shortly after federal agencies updated an advisory warning of ongoing cyber threats to U.S. critical infrastructure from Iranian-affiliated actors. While investigators haven't linked the latest attacks to Iran, the updated guidance highlighted previous attempts by Iranian hackers to target PLCs and other industrial control systems used to operate pumps, motors and valves.
Cybersecurity experts say internet-exposed industrial control devices remain an attractive target because attackers can identify connected equipment through internet scans and attempt to gain access using default manufacturer passwords that have never been changed. In the recent incidents, officials say there were no ransom demands, suggesting the attacks were intended to disrupt operations or create public concern rather than generate financial gain.
Federal officials have also emphasized that many water systems continue to face significant cybersecurity challenges, including outdated software, weak network security, inadequate access controls and limited cybersecurity training. Although federal agencies provide guidance and oversight, responsibility for securing water infrastructure is shared among utilities, municipalities, states and federal partners, with cybersecurity investments often dependent on both local and federal funding.
CISA noted that organizations of all sizes may have vulnerabilities and urged utilities to validate internet-facing connections and implement recommended safeguards as cyber threats against the sector continue to increase.
AWWA statement
American Water Works Association CEO David LaFrance also issued a statement about the cyberattacks. "The recent cyber attacks on multiple U.S. water systems underscore the importance of remaining vigilant against evolving cyber threats. Water professionals understand their profound responsibility to protect the health, safety and well-being of the communities they serve every day.
"Utilities across the water community are continually working to strengthen cybersecurity and improve resilience following cyber attacks. Success depends on access to timely threat intelligence, technical expertise, continual training, and the financial resources needed to secure critical systems."
The AWWA supports these efforts through a range of cybersecurity resources, including its Getting Started Guide and interactive cybersecurity assessment tool. These resources help utilities identify vulnerabilities, prioritize improvements and strengthen resilience.
Continue reading for free

















