Key Takeaways
- Recent cyber attacks have hit water utilities in at least seven U.S. states, including Minnesota and Michigan, prompting FBI involvement.
- The Cybersecurity and Infrastructure Security Agency (CISA) warns that internet‑exposed programmable logic controllers (PLCs) are being actively targeted, leading to password changes, IP reconfiguration, boil‑water notices, and forced manual operations.
- CISA urges immediate removal of PLCs and other operational technology (OT) from the public internet, implementation of VPN‑based remote access, strong password controls, and IP allow‑listing.
- Although no drinking‑water contamination has been reported, the incidents underscore the potential for operational disruption and physical damage if OT assets remain exposed.
- Attribution is still under investigation, but timing aligns with heightened Iranian‑affiliated PLC exploitation noted in CISA Advisory AA26‑097A.
- The EPA and other federal agencies have begun proactive vulnerability assessments and are offering guidance, while organizations such as the National Rural Water Association facilitate coordination with state and federal partners.
Recent Surge in Cyber Attacks on U.S. Water Systems
A wave of cyber incidents targeting municipal water and wastewater facilities was reported last week across seven states, with Minnesota and Michigan specifically named in media coverage. The attacks were brought to the attention of the Federal Bureau of Investigation (FBI) after more than 30 water systems in Minnesota appeared to be hit in a coordinated effort over the weekend. Although the exact identities of the affected utilities have not been disclosed, the pattern indicates a broad, geographically dispersed campaign rather than isolated incidents. Notably, despite the disruption caused by the intrusions, authorities have confirmed that no contamination of drinking water has been detected as a direct result of the cyber activity.
CISA’s Warning from CISA
The Cybersecurity and Infrastructure Security Agency (CISA (CISA) advisory highlighting a specific operational technology. CISA noted are actively scanning for and exploiting internet‑connected programmable logic controllers (PLCs) from vendors such as Rockwell Automation/Allen‑Bradley, Schneider Electric, Siemens, and others. Once accessed, threat actors have altered PLC passwords to lock out legitimate operators and have modified the devices’ IP addresses, effectively disconnecting them from control networks. These actions have triggered boil‑water notices and forced utilities to revert to manual, labor‑intensive processes to maintain service continuity.
CISA‑Recommended Mitigations for Exposed OT
To curb the rising threat, CISA prescribes a set of concrete mitigations for water and wastewater entities. First and foremost, organizations should disconnect PLCs and other OT assets from the public internet; any required remote access must be routed through a virtual private network (VPN) or a dedicated gateway device rather than direct PLC connections. Second, enabling password protection and changing all default credentials is essential to prevent unauthorized logins. Third, implementing IP allow‑listing—restricting remote‑access permissions to known engineering laptops or other critical OT systems—helps ensure that only trusted devices can interact with the controllers. CISA also advises maintaining an up‑to‑date inventory of OT assets, conducting regular vulnerability scans, and segmenting OT networks from corporate IT environments to limit lateral movement.
Potential Iranian‑Affiliated Attribution and Broader Context
While the FBI’s investigation remains ongoing, analysts have observed a temporal correlation between the recent water‑sector intrusions and a surge in Iranian‑affiliated PLC exploitation documented in CISA Advisory AA26‑097A, released July 22. That advisory warned of ongoing cyber exploitation of internet‑connected OT devices across multiple critical infrastructure sectors, naming the same PLC manufacturers targeted in the water attacks. Although the FBI has publicly noted that the observed behavior so far is limited to Rockwell Automation/Allen‑Bradley MicroLogix 1100 and 1400 series PLCs, it cautioned that similar tactics could be employed against other brands. The overlap in timing, tactics, and targeted technology suggests that the current campaign may be part of a broader state‑linked effort to probe U.S. critical infrastructure resilience.
EPA’s Proactive Vulnerability Management and Federal Guidance
In parallel with the CISA warnings, the U.S. Environmental Protection Agency (EPA) highlighted progress made in 2025 toward hardening water systems against cyber threats. The EPA’s Office of Water reported that it had proactively identified cybersecurity weaknesses at 277 water utilities, focusing on components that control drinking‑water and wastewater processes—precisely the assets most attractive to threat actors. Remediation efforts included implementing stronger authentication protocols, enforcing strict access controls, applying technical patches, and introducing network‑segmentation measures. The EPA stressed that safeguarding these systems is vital not only for public health but also for supporting economic growth, as reliable water services underpin countless industrial and commercial activities.
Broader Threat Landscape and Recommendations for Utilities
The water sector has faced an escalating mix of threats in recent years, ranging from physical intrusions to sophisticated cyber campaigns such as ransomware and unauthorized access to online utility management portals. Threat actors now target organizations of all sizes, exploiting undocumented cellular modems, vendor‑installed equipment, and other OT connections that may slip through routine attack‑surface scans. CISA therefore advises even those utilities with mature cybersecurity programs to validate all external connections, ensure that OT devices are not inadvertently exposed, and continuously monitor for anomalous activity. Collaboration is encouraged through State Rural Water Associations, the National Rural Water Association (NRWA), and regional CISA offices, which can provide technical assistance, threat‑intelligence sharing, and incident‑response support. By adopting the recommended mitigations, maintaining vigilant oversight, and leveraging federal resources, water utilities can better defend against the evolving cyber‑physical threat landscape.

