Thu 06 Aug 2026 / 09:43 ET
Kernel
Hardware 3 min read

US water system cyberattacks prompt warning on exposed controllers

Federal agencies report attacks on water utilities in at least seven states, while Iran remains an unconfirmed suspect in Minnesota.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

US water system cyberattacks prompt warning on exposed controllers
img: Tom's Hardware

US water system cyberattacks reported in at least seven states have prompted warnings about internet-exposed industrial controllers, while the suspected link to Iran in Minnesota remains unproven. The FBI and Environmental Protection Agency said utilities had reported incidents and that some malicious activity had degraded water operations, NBC News reported.

The confirmed picture is narrower than claims that 45 municipalities were hit. Reporting identified more than 30 municipal water facilities targeted in Minnesota and incidents reported across at least seven states. The FBI and EPA did not name the states in their public service announcement.

A law-enforcement official told NBC News that the Minnesota activity bore hallmarks of Iranian meddling and remained under investigation. Minnesota officials and the U.S. government had not publicly assigned responsibility for the Minnesota incidents, and the FBI and EPA did not identify a culprit for incidents in other states. A New York Times report said investigators believed the attack on dozens of Minnesota systems was probably the work of Iranian hackers.

What happened in the US water system cyberattacks?

The technical pattern described by the Cybersecurity and Infrastructure Security Agency is blunt: attackers accessed programmable logic controllers, or PLCs, that were exposed to the internet, then changed passwords and IP addresses. That can lock operators out and disconnect the devices from their normal network access.

CISA said on July 30 that it had observed a significant rise in activity targeting PLCs in the water and wastewater sector. The agency said the activity had led to boil-water notices and prolonged use of manual operations in some cases, without identifying the affected systems or locations. Minnesota's information technology agency said there was no indication that the breaches had contaminated municipal water supplies.

Braham, Minnesota, was among the affected communities and was running its water service manually, according to Tom's Hardware. Mayor Nate George said the city had received guidance on responding and strengthening its defenses, but said IT infrastructure upgrades were costly for a municipality with fewer than 2,000 residents.

What are water utilities being told to do?

CISA's alert tells utilities to remove PLCs and other operational technology from direct internet exposure. Where remote access is required, it recommends using a VPN or gateway device instead of connecting directly to a PLC, changing default passwords, restricting access to approved IP addresses, and retaining a known-clean controller backup.

The alert also warns that even utilities with established security processes should check for undocumented cellular modems installed by operators, vendors or system integrators. Those connections may not show up in routine scans, which is not a great time for an asset inventory to become archaeology.

Wisconsin officials said in a bulletin that Minnesota had reported pressure drops in several incidents. Minnesota IT spokesperson Emily Zimmer disputed that characterization, telling NBC News that the state had not reported pressure reductions across multiple systems or linked pressure changes to law-enforcement responses.

President Donald Trump publicly rejected the Iran theory and blamed Minnesota officials. Gov. Tim Walz responded that Trump knew other states had also been hit and described the incidents as part of modern warfare. Those statements do not resolve the investigation, and no public U.S. attribution had been made at the time of the reports.

This story draws on original reporting from Tom's Hardware.

More Hardware/

view all ↗