Key Takeaways
- Federal agencies have warned that Iranian‑linked hackers are targeting Internet‑connected programmable logic controllers (PLCs) used in drinking‑water and wastewater systems, causing pressure loss and potential contamination.
- Although no successful attack or water‑quality problem has been reported in Washington state, hundreds of its water providers have been advised to harden their defenses.
- The FBI and CISA urge utilities to remove PLCs from direct Internet exposure, strengthen firewalls, enforce strict user controls, and consult Rockwell Automation’s security team and the EPA for technical support.
- Washington’s Department of Health has forwarded the federal alerts, is expanding oversight through a 2024 Cybersecurity Action Plan, and will make grant funding, training, and expert assistance available to the largest water and wastewater providers.
- The plan applies to the 249 largest drinking‑water suppliers (≥3,330 customers) and 100 wastewater departments handling >1 million gallons per day, but the state currently does not regulate or review cybersecurity incident‑response plans for these utilities.
Overview of the Threat
Hundreds of drinking‑water providers across Washington state have received advisories to bolster their cybersecurity after a series of suspected hacking incidents disrupted utilities in Minnesota and Michigan. So far, Washington has not experienced any confirmed breaches or water‑quality issues linked to these attacks, according to Karina Shagren, a spokesperson for the state Department of Emergency Management. Nevertheless, the Federal Bureau of Investigation (FBI) has identified at least seven states where tampering or attempted tampering with water‑system controls has been reported, underscoring a nationwide vulnerability. The alerts come as geopolitical tensions rise, with nation‑state actors increasingly viewing critical infrastructure as a viable target for cyber operations.
FBI Findings and Iranian Hackers
The FBI’s alert specifies that malicious cyber actors have been focusing on Internet‑connected programmable logic controllers (PLCs) manufactured by companies such as Rockwell Automation. By compromising these devices, attackers can alter operational parameters, leading to pressure loss, uncontrolled flooding, or the intrusion of untreated groundwater into distribution pipes. The bureau’s statements suggest that Iranian‑backed hackers are among the groups conducting these intrusions, motivated by the potential to cause widespread disruption to essential services. While the FBI had not publicly named a specific perpetrator as of the Thursday briefing, the pattern of activity aligns with known Iranian cyber‑espionage campaigns targeting U.S. critical infrastructure.
Impact on Washington State
Washington’s public water systems serve more than 6.2 million residents, yet the state has historically lacked a comprehensive inventory of cybersecurity safeguards across its myriad utilities. The Department of Emergency Management noted that, despite the advisory, no water‑quality problems have been detected and no successful attacks have been confirmed within the state’s borders. However, the sheer scale of the population reliant on these systems means that even a modest breach could have significant public‑health and economic repercussions, prompting officials to urge pre‑emptive hardening of defenses before any incident occurs.
Response from State Agencies
Upon receiving the federal warnings, the Washington State Department of Health promptly forwarded the alerts to all registered drinking‑water providers. The agency emphasized that while the immediate threat appears limited, proactive measures are essential to prevent future exploitation. State officials are also coordinating with the Department of Emergency Management and local public‑works offices to disseminate best‑practice guidance, conduct outreach, and monitor for any signs of anomalous activity across the water‑sector network.
Details of the Cyberattack Technique
According to the FBI, attackers gained remote access to utilities’ Internet‑enabled devices—primarily PLCs—by exploiting weak authentication or outdated firmware. Once inside, they changed IP addresses and passwords, effectively locking out legitimate operators and disrupting monitoring and control functions. The resulting loss of pressure can cause back‑regulation capabilities, allowing untreated groundwater to infiltrate potable‑water lines. The alert specifically names Rockwell Automation’s controllers as a frequent target, noting that many utilities have these devices directly exposed to the public Internet without adequate segmentation or firewall protection.
Recommendations for Utilities
To mitigate the risk, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) recommend several concrete steps: (1) disconnect PLCs from direct Internet access or place them behind robust firewalls; (2) enforce strong, unique passwords and multi‑factor authentication for all remote‑access accounts; (3) regularly update firmware and apply security patches supplied by vendors; (4) monitor network traffic for unusual login attempts or configuration changes; and (5) contact Rockwell Automation’s security response team and the Environmental Protection Agency (EPA) for technical assistance and incident‑response guidance. Utilities are also encouraged to develop and test detailed incident‑response plans that specifically address cyber‑induced process disruptions.
Broader Context of Critical Infrastructure Vulnerability
Public‑works infrastructure has long been identified as a high‑value target for cyber adversaries, particularly as warfare increasingly extends beyond traditional battlefields. A Washington‑state report observes that “driven by geopolitical conflicts, foreign threat actors recognize the vulnerability present in water and wastewater infrastructure and are motivated by the potential consequences of disrupting these critical systems.” The accessibility of legacy control systems, combined with limited cybersecurity resources at many smaller utilities, creates an attractive attack surface for nation‑states seeking to exert pressure or demonstrate capability without kinetic confrontation.
Washington State Cybersecurity Action Plan
In response to these threats, the state Department of Health has filed a “Cybersecurity Action Plan” mandated by federal law and endorsed two years ago by the National Security Council. The plan targets the largest 249 water suppliers—those serving at least 3,330 customers—and 100 wastewater departments that discharge more than one million gallons per day. Although the state presently does not regulate drinking‑water or wastewater facilities for cybersecurity weaknesses, nor does it routinely review utilities’ incident‑response plans for cyber considerations, the action plan lays the groundwork for future oversight, standardized reporting, and mandatory preparedness exercises.
Grant Opportunities, Training, and Oversight
As the action plan is implemented, eligible utilities will gain access to cybersecurity improvement grants, specialized training programs, and assistance from external security specialists. They will also be required to submit formal incident‑response plans that detail detection, containment, eradication, and recovery procedures for cyber events targeting operational technology. State auditors, who already perform occasional probes of water‑utility software for vulnerabilities, will intensify these assessments, helping to identify gaps before they can be exploited. The overall aim is to raise the baseline security posture across the sector while fostering a culture of continuous improvement and information sharing among providers.
Conclusion and Outlook
While Washington state has so far avoided any confirmed cyber‑induced water‑service disruptions, the advisories from federal agencies serve as a timely reminder that the threat landscape is evolving. By heeding the FBI and CISA recommendations—particularly the isolation of PLCs from the public Internet, strengthening authentication, and leveraging vendor and EPA support—the state’s water and wastewater providers can significantly reduce their exposure. The forthcoming Cybersecurity Action Plan, backed by grant funding and enhanced oversight, offers a structured pathway to transform voluntary best practices into enforceable standards. Continued vigilance, investment in staff training, and collaboration across local, state, and federal partners will be essential to safeguard the essential drinking‑water and wastewater services that millions of Washingtonians rely upon each day.

