US Agencies Warn of Widespread Water Utility Cyberattacks
Federal agencies and state officials are investigating coordinated cyberattacks on water systems across seven states, with evidence pointing toward Iranian-linked hackers.
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, and Environmental Protection Agency (EPA) issued a joint warning on July 31, 2026, regarding a surge in cyberattacks targeting water and wastewater systems across the United States. Since July 27, utility companies in at least seven states reported incidents where hackers remotely accessed internet-facing programmable logic controllers (PLCs) to disrupt monitoring and control capabilities. The FBI noted that some attacks caused flooding and loss of water pressure.
Minnesota was the primary target, with over 30 community water systems hit between July 26 and 27. In Braham, a treatment plant went offline for two hours, and the city of Plymouth disconnected cellular equipment to halt the intrusion. While drinking water remained safe, some operators were locked out of their systems by changed passwords. Investigators are specifically examining vulnerabilities in Rockwell Automation MicroLogix 1400 PLCs as a likely entry point.
U.S. and state officials, including the Minnesota Fusion Center, believe Iranian-linked hackers are responsible, coinciding with intensified military conflict between the U.S. and Iran. However, President Donald Trump dismissed these claims during a cabinet meeting at Camp David on July 31, instead attributing the breaches to the "grossly incompetent" leadership of Minnesota Governor Tim Walz. Federal agencies continue to urge critical infrastructure operators to remove publicly exposed PLCs from the internet to prevent further disruptions.