Key Takeaways
- The FBI has observed a sharp increase in malicious cyberattacks targeting water utilities in seven states within a two‑week window.
- Minnesota and Michigan have been publicly named as affected states; no major water‑supply outages have been reported so far.
- A recent FBI issued a Public Service Announcement urging operators to harden cybersecurity, isolate operational technology from the internet, and be ready to switch to manual controls.
- Cybersecurity expert Matt Hartman emphasizes that essential services like water are high‑value targets for adversaries, including nation‑states.
- Hartman warns that any local utility could be disrupted at any moment and stresses the need for continual preparedness.
- The federal government can help raise the baseline protection for municipal systems so they are not left to defend against sophisticated foreign threats alone.
- The Southern Nevada Water Authority declined interview requests but confirmed it monitors threats and updates defenses accordingly.
Overview of the FBI Alert
The Federal Bureau of Investigation has issued a warning after detecting a notable surge in malicious cyber activity aimed at water utilities across seven states in less than two weeks. The attacks have varied in sophistication, with some incidents causing operational disruptions such as drops in water pressure and localized flooding. While the full roster of impacted states remains undisclosed, the FBI confirmed that Minnesota and Michigan are among those affected. Importantly, despite these intrusions, there have been no widespread interruptions to drinking‑water delivery or wastewater treatment services reported to date. The bureau’s alert underscores the growing vulnerability of critical infrastructure to cyber threats and serves as a call to action for municipal operators to bolster their defenses before more severe consequences arise.
Details on Affected States and Observed Impacts
Although the FBI has not released a complete list of the seven states involved, the acknowledgment of Minnesota and Michigan provides a concrete reference point for the geographic scope of the threat. In the reported cases, attackers have managed to infiltrate supervisory control and data acquisition (SCADA) systems or other operational technology (OT) layers, leading to measurable effects on water distribution networks. For example, certain intrusions resulted in temporary loss of pressure that could affect firefighting capabilities or consumer service, while others triggered unintended valve openings that contributed to localized flooding. Fortunately, the disruptions have remained limited in scale, and utilities have been able to restore normal operations through existing contingency measures. Nonetheless, the pattern demonstrates that even relatively modest cyber intrusions can produce tangible physical consequences, heightening concerns about the resilience of water infrastructure.
FBI Public Service Announcement Recommendations
In response to the rising threat landscape, the FBI released a Public Service Announcement (PSA) directed at municipal water and wastewater operators. The PSA outlines three immediate actions: first, enhance overall cybersecurity posture by implementing multi‑factor authentication, regular patch management, and network segmentation; second, disconnect operational technology networks from the public internet as soon as feasible to reduce the attack surface; and third, develop and rehearse procedures for reverting to manual controls should automated systems be compromised. The agency stresses that these steps are not merely precautionary but essential for maintaining service continuity in the face of increasingly sophisticated adversaries. By following the PSA’s guidance, utilities can limit the potential for attackers to pivot from IT environments into critical OT domains where they could manipulate pumps, valves, or treatment processes.
Expert Insight: Why Water Systems Are Attractive Targets
Matt Hartman, Chief Strategy Officer for the Merlin Group and a recognized cybersecurity authority, elaborated on the motivations behind the targeting of water utilities during an interview at the Black Hat Cybersecurity Conference. He described water and wastewater systems as “lifeline sectors” that, alongside transportation and energy, provide indispensable services to the public. Because disruptions in these sectors can immediately affect health, safety, and economic stability, they become high‑value objectives for adversaries seeking to exert pressure, demonstrate capability, or achieve strategic goals. Hartman noted that the perceived low profile of local utilities often leads to a false sense of security, making them appealing to actors who anticipate weaker defenses compared with larger, more regulated entities.
Nation‑State Threats and the Need for Constant Vigilance
Hartman further warned that the threat is not limited to criminal hackers or hacktivist groups; nation‑states engaged in geopolitical competition with the United States could view local water systems as viable targets for low‑cost, high‑impact operations. He illustrated this point with a hypothetical scenario: a small utility in “state X, county Y” being singled out by a foreign power intent on testing its cyber capabilities or sowing confusion. According to Hartman, anyone working in critical infrastructure operators must adopt a mindset of perpetual readiness, recognizing that an attack could occur at any moment without warning. This vigilance includes continuous monitoring, timely threat intelligence sharing, and regular drills that simulate both cyber and physical failure modes to ensure staff can respond effectively under stress.
Federal Government’s Role in Elevating Baseline Protection
Highlighting the limitations of expecting individual municipalities to defend against sophisticated foreign actors on their own, Hartman argued that the federal government bears responsibility for raising the baseline of cybersecurity across the sector. He suggested measures such as providing subsidized access to advanced threat‑detection tools, establishing mandatory minimum standards for OT security, and facilitating information‑sharing hubs where utilities can receive real‑time alerts about emerging threats. By leveling the playing field, the federal approach would enable smaller systems to focus on operational resilience rather than attempting to match the capabilities of well‑resourced nation‑state adversaries. Hartman emphasized that a collaborative framework—combining federal resources, state coordination, and local expertise—is essential to safeguard the nation’s water supply against evolving cyber risks.
Response from the Southern Nevada Water Authority
Channel 13 sought comment from the Southern Nevada Water Authority (SNWA) regarding the FBI’s alert and the broader threat environment. The authority declined to provide an interview, citing a policy of not discussing specific cybersecurity efforts publicly. However, an SNWA spokesperson confirmed that the agency actively monitors for cyber threats and continuously updates its defensive posture to adapt to changing tactics. This stance reflects a common approach among utilities that prioritize operational security while maintaining discretion about specific defensive measures. The authority’s acknowledgment of ongoing vigilance aligns with the FBI’s recommendation that utilities remain alert and prepared, even when they choose not to disclose details publicly.
Conclusion and Broader Implications
The recent wave of cyberattacks on water utilities serves as a stark reminder that critical infrastructure is increasingly in the crosshairs of malicious actors. While the immediate impacts have been contained, the potential for more severe consequences—such as prolonged water shortages, contamination risks, or cascading failures in dependent sectors—remains real. The FBI’s PSA, expert warnings from figures like Matt Hartman, and the cautious stance of utilities such as the Southern Nevada Water Authority collectively underscore the need for a layered defense strategy. Strengthening cybersecurity hygiene, isolating vital OT networks, preparing manual fallback procedures, and leveraging federal support are all critical steps that municipal operators must embrace. As threat actors continue to refine their tactics, the resilience of water systems will depend on sustained investment, cross‑sector collaboration, and a culture of readiness that treats cyber risk as an ever‑present operational concern.

