Key Takeaways
- The NSA issued a nationwide alert about cyberattacks targeting drinking‑water and wastewater treatment facilities across the United States.
- Washington State’s Department of Ecology urged local utilities to review the advisory and implement protective measures.
- Bellingham officials confirmed they are aware of the threat and have existing cybersecurity protections, regular threat assessments, and response plans in place.
- Cybersecurity Dive reports that public utilities in at least twelve states—including Minnesota, Michigan, Georgia, South Dakota, and New Jersey—have been hit, with a coordinated attack affecting over thirty community water systems in Minnesota in July 2026.
- Multiple federal agencies (CISA, FBI, DOE, EPA) echoed the warning, advising utilities to isolate critical systems from the internet, monitor for anomalous activity, and report suspicious behavior.
Overview of the NSA Alert
The National Security Agency recently issued an alert highlighting a surge in cybersecurity incidents aimed at drinking‑water and wastewater treatment facilities nationwide. The notice, disseminated through the state Department of Ecology, described the threat as a coordinated effort that could compromise operational technology, potentially disrupting essential services. Ecology’s Friday statement urged all public utilities in Washington to read the accompanying Public Service Announcement and to assess how the described tactics, techniques, and procedures might affect their own systems. The alert underscores the growing concern that critical infrastructure, long considered low‑profile targets, is now attracting sophisticated adversaries seeking to exploit vulnerabilities in supervisory control and data acquisition (SCADA) networks and related software.
State and Local Response
In reaction to the NSA advisory, the Washington State Department of Ecology emphasized that water and wastewater operators must review the outlined mitigation actions and apply preventive hardening to reduce the likelihood of an attack. Deputy Director of Public Works Michael Olinger of the City of Bellingham told The Bellingham Herald that the municipality treats cybersecurity with utmost seriousness because water and wastewater are essential services. He noted that Bellingham already maintains protective measures, conducts regular threat assessments, and has response plans ready should an incident occur. Olinger added that the steps recommended in the federal alert align with the city’s current practices, indicating that local officials are not starting from scratch but are reinforcing existing safeguards.
Scope of Attacks Across States
According to the digital‑industry publication Cybersecurity Dive, public utilities in at least twelve states have been targeted in recent cyber incidents, including Minnesota, Michigan, Georgia, South Dakota, and New Jersey. The outlet reported that the first public discovery of the threat emerged in Minnesota, where more than thirty community water systems were hit in a coordinated attack spanning July 26‑27, 2026. This wave of intrusions suggests a pattern of attackers seeking to exploit common software or hardware weaknesses across multiple jurisdictions, rather than isolated incidents. The geographic spread underscores the systemic nature of the risk and highlights the need for a unified, nationwide approach to defending critical water infrastructure.
Involvement of Multiple Federal Agencies
The warning did not originate from the NSA alone. The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE), and the Environmental Protection Agency (EPA) have all issued statements or advisories concerning the same vulnerability. Each agency emphasized different facets of the threat: CISA focused on infrastructure resilience, the FBI on criminal investigation and reporting mechanisms, the DOE on energy‑related operational technology parallels, and the EPA on environmental and public‑health implications. Their coordinated messaging reflects a whole‑of‑government strategy to alert utilities, share threat intelligence, and prescribe concrete defensive steps.
Recommended Mitigation Actions
Both the FBI and the EPA specifically urged operators of water and wastewater treatment plants to disconnect their control‑system computers from the public internet where feasible, thereby reducing the attack surface available to remote threat actors. They also advised utilities to monitor networks for anomalous activity, to report any suspicious behavior to appropriate law‑enforcement or cyber‑security authorities, and to review the tactics, techniques, and procedures detailed in the NSA advisory. Ecology’s statement echoed these recommendations, urging Washington utilities to apply the suggested mitigation and preventative hardening actions to minimize the chance of a successful breach. The guidance underscores a shift toward air‑gapping critical systems and enhancing incident‑response readiness.
Context and Publication Details
The story was originally published on August 21, 2026, at 2:38 PM by The Bellingham Herald, a daily newspaper serving Whatcom County and surrounding areas. The article was written by veteran reporter Robert Mittendorf, who covers civic issues, weather, traffic, and housing‑affordability topics for the outlet. The timing of the piece places it shortly after the federal alert was issued, providing local readers with timely information about how the nationwide cybersecurity threat is being addressed at the state and municipal levels. The Herald’s coverage reflects its role in disseminating public‑safety information to community stakeholders.
Author Background
Robert Mittendorf has been a journalist since 1984 and joined The Bellingham Herald’s staff to cover a broad range of local‑government and community‑interest beats. In addition to his reporting duties, he served thirty‑three years as a volunteer firefighter for the South Whatcom Fire Authority, retiring in 2025. This background gives him a unique perspective on public‑safety matters, including the intersection of emergency services and infrastructure resilience. His experience lends credibility to his coverage of the cybersecurity threat facing water and wastewater systems, allowing him to translate technical advisories into accessible information for residents and officials alike.

