Wave of cyberattacks puts water sector on alert as FBI investigates incidents across multiple states

Philipp Katzenberger I I Jr Uoe Ro Cq Unsplash (1)

Headshot Es Headshot

A coordinated series of cyberattacks targeting U.S. water systems has expanded beyond Minnesota, with Michigan now confirming that nine utilities experienced similar incidents as federal investigators work to determine who is behind the campaign.

The attacks, first disclosed after more than 30 Minnesota community water systems were targeted during a 48-hour period in late July, represent one of the most widespread cyber campaigns against the U.S. water sector in recent years. While officials say there have been no known impacts to drinking water quality or public health, the incidents have renewed concerns about the security of the industrial control systems that operate treatment plants, pump stations and distribution networks.

According to the Associated Press, the attacks primarily targeted operational technology used to remotely monitor and control water infrastructure. In Minnesota, officials said some utilities temporarily lost remote control capabilities, while communities including Braham and Plymouth asked customers to voluntarily reduce water use as operators shifted to manual operations. In Braham, attackers briefly disabled operating controls for the city's wells and treatment plant, leaving the community reliant on water stored in its elevated tank until systems were restored.

Michigan officials announced Aug. 1 that nine water systems in the state had also been targeted. The FBI is investigating the incidents, and state officials said all affected systems continued operating safely without impacts to water quality.

The attacks come just days after the FBI, CISA, EPA, Department of Energy and other federal agencies issued a joint cybersecurity advisory warning that Iranian-affiliated cyber actors are actively targeting internet-connected programmable logic controllers (PLCs) used throughout U.S. critical infrastructure, including water and wastewater facilities. Rather than deploying ransomware, the advisory warns that attackers are attempting to manipulate operational technology by changing controller configurations, passwords and engineering files, actions capable of disrupting normal plant operations.

Although federal investigators have not officially attributed the Minnesota and Michigan incidents to a specific group, the attacks closely resemble tactics described in the recent federal advisory, and investigators are examining possible links to Iranian-affiliated threat actors.

READ MORE: 6 wastewater facility cybersecurity tips from Robert Siciliano

For water utilities, the incidents highlight a growing shift in cyber risk. Rather than focusing solely on business networks or customer data, attackers are increasingly probing the operational technology that controls pumps, valves, chemical feed systems and treatment processes. Many smaller utilities continue to rely on legacy equipment, limited cybersecurity staffing and internet-connected remote access systems, making the sector an attractive target for nation-state actors and other sophisticated threat groups.

Federal agencies are urging utilities to review remote access to industrial control systems, remove internet-facing PLCs wherever possible, strengthen authentication and ensure operators can continue running critical facilities manually if digital control systems become unavailable.

Page 1 of 4
Next Page