Cyberattacks struck more than 30 water systems across Minnesota on July 26 and 27 before spreading to facilities in at least seven US states, disrupting operations, forcing manual controls, and exposing water cybersecurity gaps across essential public infrastructure nationwide.
This caused service interruptions, flooding, lower water pressure and communication failures involving wells, pumps and water towers.
Although officials said drinking water remained safe, the American water cyberattack showed how weak passwords, outdated equipment and internet-connected controls can turn local security failures into national risks.
Attacks Reach Water Systems Across Seven States
Minnesota IT Services activated the state’s water cybersecurity response after more than 30 municipal facilities were targeted. Michigan later reported incidents affecting nine water systems, while federal authorities said related activity had reached at least seven states.
The FBI and Environmental Protection Agency (EPA) commented on the water utility cyberattack news and said attackers remotely accessed operational technology, changed administrator passwords and disrupted equipment.
In some cases, utilities lost control of programmable logic controllers used to automate and monitor pumps, valves, and other treatment processes.
Cybersecurity Dive reported that the water utility cybersecurity hackers changed device IP addresses, cutting operators off from their systems. Some utilities issued boil-water notices or returned to manual operations after losing access to remote sites.
“Many systems have experienced operational disruptions due to loss of communications with remote sites, including wells, pump stations, lift stations, and water towers,” an EPA spokesperson told Cybersecurity Dive.
Minnesota officials said most water cybersecurity attacks affected programmable logic controllers and human-machine interfaces; the screens operators use to manage water equipment. The targeted devices included products made by Rockwell Automation, Schneider Electric, and Siemens.
Rockwell Automation advised MicroLogix 1400 customers to remove exposed equipment from the internet, create offline backups, and prepare recovery procedures. The company said American water cyberattack users could restore access by powering down devices and reinstalling batteries, although the process erases stored programs and network settings.
Despite the American water cyberattack, state officials said the attacks did not contaminate drinking water. Dale George, communications director for Michigan’s Department of Environment, Great Lakes and Energy, said all affected systems continued operating safely.
Old Technology Leaves Utilities Exposed
Water and wastewater facilities are attractive targets because they support homes, hospitals, schools, businesses, and critical services. Yet many local utilities use aging technology, limited water system cybersecurity budgets, small technical teams and equipment designed before internet connectivity became common.
The EPA has warned that water system cybersecurity faces outdated software, poor network protection, weak access controls, and insufficient employee training. Responsibility is divided among local operators, municipalities, states and federal agencies, making upgrades difficult to fund and coordinate.
Cybersecurity and Infrastructure Security Agency (CISA) urged every water organization, including those with established security programs, to review external connections, strengthen passwords and disconnect important equipment from the internet where possible about the catastrophic cyberattack of water systems.
“Even water organizations with mature cybersecurity processes should validate their external connections,” CISA said in its alert.
Federal officials have not identified who carried out the attacks. The incidents followed updated warnings about Iranian-affiliated groups targeting US water, energy and government systems, but investigators have not linked Tehran directly to this campaign.
Authorities connected the activity to earlier warnings involving vulnerable industrial controllers. Iran-linked groups have targeted US water and energy infrastructure for months, according to Cybersecurity Dive, expanding across equipment from several manufacturers.
A similar water cybersecurity incident occurred in 2023, when CyberAv3ngers, a group linked to Iran’s Islamic Revolutionary Guard Corps, attacked a Pennsylvania water facility. That history raised questions about Iranian involvement as tensions between Washington and Tehran increased.
Attribution remains uncertain, and officials are focusing on restoring services and reducing exposure. The FBI said it was working with partners, while the EPA held a call with hundreds of utility representatives to share technical guidance.
The impact of the water cybersecurity attacks should not hide the larger warning.
Water systems can continue operating manually for short periods, but repeated attacks against exposed equipment could cause wider service failures, public health concerns, and costly emergency responses.
Preventing a cyberattack on water treatment plant systems and protecting US water infrastructure requires more than local action.
Federal funding cyberattacks requirements, updated equipment and shared threat intelligence will be necessary to close weaknesses before attackers turn temporary disruption into a broader crisis.
Inside Telecom provides you with an extensive list of content covering all aspects of the Tech industry. Keep an eye on our News section to stay informed and updated with our daily articles.