Water infrastructure attacks disrupt systems across at least seven US states
CISA warned of significantly increased malicious activity against internet-facing water-sector operational technology. Incidents affected utilities in at least seven states, including more than 30 Minnesota systems, while investigators assessed a possible Iran link.
Affected
CISA reported a significant increase in malicious activity targeting water and wastewater utilities and urged operators to remove publicly exposed programmable logic controllers and other operational technology from the internet as soon as possible. The FBI said utilities in at least seven states had reported PLC-related incidents.
More than 30 community water systems in Minnesota were affected after activity began on 26 July 2026. According to CISA, intruders changed passwords to lock out operators and altered PLC IP addresses, disconnecting the controllers. The disruption led to boil-water notices and sustained manual operation.
State and federal investigators were assessing whether the Minnesota incidents were connected to Iran. A reported WaterISAC memo tied the activity to Iran, but CISA's 30 July alert did not mention Iran. Attribution therefore remained under investigation rather than definitively established.
CISA warned that even organisations with mature security processes should validate external connections, including cellular modems installed by operators, vendors or systems integrators that may be missing from routine inventories and attack-surface scans. Internet-facing OT carries increased risk of configuration changes, operational disruption and, in severe cases, physical damage.
Operators should follow CISA's immediate guidance by identifying exposed OT, removing direct internet access and validating all external and remote connections. The reported lockouts, address changes and need for manual operation show the operational consequences without requiring assumptions about unreported manipulation or attacker motives.
Sources