FBI Probes Cyberattacks on Water Infrastructure Across Seven States, Including Michigan

0
27

Key Takeaways

  • A coordinated cyber campaign has targeted water and wastewater infrastructure in at least seven U.S. states, with nine systems in Michigan confirmed as part of the effort.
  • Although attackers attempted to alter passwords and network settings—sometimes locking operators out—state officials report that all affected systems continued to operate safely and no public‑health impacts were observed.
  • Federal agencies, including the FBI, are investigating the incidents; Iran is viewed as a primary suspect, though no official attribution has been made.
  • Michigan’s Department of Environment, Great Lakes, and Energy (EGLE), the Great Lakes Water Authority (GLWA), and the Michigan State Police (MSP) are actively monitoring the situation, sharing alerts, and urging local facilities to harden their cybersecurity posture.
  • Cybersecurity experts stress that the attacks reflect a broader, rising trend toward critical‑infrastructure targeting and recommend routine practices such as patch management, anomaly monitoring, staff training, and incident‑response planning rather than panic.

Overview of the Cyberattack on Michigan Water Systems
State officials confirmed that nine Michigan water systems were subjected to a cyberattack that attempted to interfere with operational technology controlling water treatment and distribution. The Michigan Department of Environment, Great Lakes, and Energy (EGLE) first became aware of the threat after receiving a federal cyber alert warning of possible tampering with supervisory control and data acquisition (SCADA) systems. Following the alert, EGLE noted a small number of reports from municipal operators describing activity consistent with the federal warning—such as unauthorized login attempts and changes to network configurations. Despite these incidents, EGLE emphasized that all systems remained operational, local crews swiftly addressed the issues, and there was no evidence that drinking‑water safety or public health was compromised.


Scope of the Attacks Across the United States
Michigan was not an isolated case. Authorities reported that at least seven states have experienced similar intrusions targeting water and wastewater facilities, with Minnesota recording the highest number of compromised systems. In several instances, hackers went beyond reconnaissance and actively modified passwords and network settings, effectively locking legitimate operators out of their control panels and hindering their ability to regulate water flow or treatment processes. The pattern suggests a coordinated effort aimed at disrupting essential services rather than isolated, opportunistic probes. While the exact number of affected utilities nationwide remains under review, the multi‑state nature of the campaign has prompted heightened vigilance from both state and federal agencies.


Federal Response and Suspect Attribution
The FBI acknowledged the recent surge in reporting concerning the water and wastewater sector, confirming that the agency and its interagency partners are fully engaged in protecting critical infrastructure. Although authorities have not publicly named a perpetrator, U.S. intelligence and investigative officials have indicated that Iran is viewed as a primary suspect in the campaign. This assessment aligns with broader concerns about state‑sponsored actors seeking to test or undermine the resilience of American essential services. The FBI urged organizations to remain alert, report suspicious activity, and follow established cybersecurity guidelines while investigations continue.


Michigan’s Monitoring and Coordination Efforts
The Great Lakes Water Authority (GLWA), which serves a large portion of southeastern Michigan, issued a statement clarifying that its own water and wastewater systems have not been impacted by the attacks. GLWA said it is closely monitoring the evolving situation and remains prepared to respond should any threats emerge. Meanwhile, the Michigan State Police (MSP) reported that it is actively coordinating with EGLE and federal partners, communicating with municipal water systems statewide, and encouraging facilities using the potentially compromised software to apply recommended security patches and follow applicable cybersecurity guidance. Both agencies stressed the importance of timely information sharing to mitigate further risk.


Communities Unaffected and Transparency Challenges
While nine systems were confirmed as targets, several Michigan communities have publicly stated they were not affected. Notably, Oakland County officials confirmed that their water infrastructure showed no signs of intrusion. State authorities have refrained from disclosing the specific municipalities involved, citing ongoing investigations and the need to avoid tipping off potential adversaries. This lack of public detail has led to some speculation, but officials maintain that withholding specifics is a precautionary measure designed to protect the integrity of the response effort and prevent further exploitation.


Expert Perspective on the Rising Threat Landscape
Cybersecurity specialist Talena Adams, founder of Brown Gurl Cyber, characterized the attacks as part of an escalating trend toward targeting critical infrastructure. Adams noted that sectors such as water, energy, health care, and transportation are experiencing a rise in attempted intrusions compared with previous years. She emphasized that many organizations continue to rely on legacy technology that is difficult to update, creating vulnerabilities that sophisticated threat actors can exploit. Adams urged vigilance—not panic—highlighting practical steps such as maintaining up‑to‑date software, monitoring networks for anomalous behavior, conducting regular employee training, and establishing robust incident‑response plans as essential defenses against evolving cyber threats.


Recommendations for Strengthening Water‑Sector Cybersecurity
In light of the recent incidents, experts and government agencies alike are urging water utilities to adopt a proactive security posture. Key recommendations include: implementing multi‑factor authentication for remote access to control systems; segmenting operational technology networks from corporate IT environments to limit lateral movement; conducting regular vulnerability assessments and penetration testing; ensuring timely application of security patches and firmware updates; developing and rehearsing clear incident‑response procedures that define roles, communication channels, and recovery steps; and fostering a culture of cybersecurity awareness among staff through periodic training and simulated phishing exercises. By integrating these practices, utilities can improve resilience against both current threats and future campaigns targeting essential services.


Conclusion
The cyberattacks on nine Michigan water systems—part of a broader, multi‑state campaign targeting water and wastewater infrastructure—underscore the growing vulnerability of critical infrastructure to digital threats. Although prompt responses by local operators and state agencies prevented any public‑health consequences, the incidents serve as a stark reminder of the need for continuous vigilance, robust cybersecurity hygiene, and close collaboration among utilities, state agencies, and federal partners. As threat actors refine their tactics, the water sector must prioritize modernization of legacy systems, proactive threat detection, and comprehensive readiness to safeguard the essential services that communities rely upon every day.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here