Cyberattacks Hit Water Systems in 12 States as Hidden Risks Surface 

Spread the love
A robotic hand reaching into a digital network on a blue background, symbolizing AI technology.
Photo by Tara Winstead

When residents in Braham, Minnesota, turned on their faucets one July morning, most had no reason to think that someone outside their community might be interfering with the machinery behind the water supply. 

The drinking water remained safe. Yet inside the local treatment plant, workers were dealing with something far from routine. Hackers had gained unauthorized access to a computer system and temporarily disrupted the facility’s operations. 

The incident was one piece of a much larger campaign. Water and wastewater facilities in at least 12 states have faced cyberattacks, sources familiar with the investigation said. The full list of affected states has not been publicly disclosed. 

Authorities have not reported contaminated drinking water or confirmed that the attacks created a direct public health emergency. Still, the campaign has exposed a quiet national vulnerability: many of the machines controlling America’s water systems can be reached through the internet. 

Minnesota became the clearest warning 

The scale of the threat became visible in Minnesota, where more than 30 community water systems were targeted over two days in late July. 

Minnesota IT Services described the activity as a coordinated cyberattack. State and federal investigators found signs of unauthorized access carried out with malicious intent, although officials did not immediately identify the attackers. 

Braham experienced one of the most noticeable disruptions. The city’s water treatment plant temporarily stopped operating after hackers accessed its systems. Employees restored service, and officials found no evidence that the drinking water had become unsafe

Plymouth also reported a temporary communications disruption involving water infrastructure. Other affected systems continued operating or switched to manual controls while technicians examined their networks. 

The events did not produce the dramatic images often associated with an attack on critical infrastructure. There were no collapsed towers, burning transformers or visibly damaged pipes. Instead, the danger appeared through computer screens inside facilities that most residents rarely see. 

Michigan later disclosed cyberattacks involving nine water systems. Officials said those facilities continued operating safely and that public health had not been harmed. 

The FBI is investigating the incidents with other federal and state agencies. The number of known targets could change as additional utilities examine their systems and report suspicious activity. 

How hackers can reach physical machinery 

A comprehensive aerial perspective of a water treatment plant in Red Wing, Minnesota.
Photo by Tom Fisk

Modern water plants rely on operational technology to move, treat and monitor water. Computerized controls can operate pumps, open valves, measure pressure and regulate parts of the treatment process. 

Among the most important devices are programmable logic controllers. These small industrial computers tell physical equipment what to do. 

Connecting them to the internet allows employees and contractors to monitor equipment remotely. It can save time and help small utilities manage operations with limited staff. 

That convenience can also create an entry point. A system left exposed online, protected by a default password or running outdated software, may allow an attacker to reach equipment from thousands of miles away. 

The danger extends beyond stolen files. Unlike an intrusion into an ordinary office network, an attack on operational technology can affect machinery in the physical world. 

The Environmental Protection Agency has warned that attackers could potentially disrupt treatment and water distribution, damage pumps and valves, or alter chemical levels. Authorities have not said that the attackers in the latest campaign attempted to contaminate water. 

The absence of contamination remains important. Residents should not assume their tap water is unsafe merely because a local facility experiences a cyber incident. Utilities and public health authorities issue boil-water notices or other instructions when conditions require them. 

However, the attackers demonstrated that access was possible. That alone gives investigators reason for concern. 

Investigators have not officially named the attackers 

Officials are examining whether actors linked to Iran played a role, but federal agencies have not publicly attributed the campaign to a country or organization. 

That distinction matters. Similarities in tactics or targeted equipment can guide an investigation, but they do not provide conclusive proof of responsibility. 

The latest attacks follow months of federal warnings about Iranian-affiliated cyber activity against American infrastructure. In April, the FBI, EPA, National Security Agency and Cybersecurity and Infrastructure Security Agency issued a joint warning about an ongoing threat

The agencies said hackers were exploiting internet-connected industrial controllers used at drinking water, wastewater, oil and gas facilities. Some incidents disrupted operations and forced employees to use manual controls. 

Iranian-linked hackers have targeted American water facilities before. In 2023, attackers gained access to equipment at several utilities that used controllers manufactured in Israel. That history makes Iran one focus of the current investigation, but it does not settle the question of who carried out the latest attacks. 

Until investigators release stronger evidence, any claim assigning responsibility should be treated as an assessment rather than a confirmed finding. 

Small utilities face a large security burden 

America’s water sector is highly decentralized. Thousands of local systems serve communities of dramatically different sizes and financial strength. 

A major city may employ dedicated cybersecurity specialists. A small town may rely on a few workers who handle treatment, equipment maintenance, regulatory paperwork and emergency repairs. 

That imbalance makes rural and small community systems attractive targets. Attackers do not need to defeat the strongest security in the country when they can search the internet for exposed machinery protected by weak credentials. 

EPA inspections have repeatedly found serious problems. In 2025, the agency identified vulnerabilities at 277 water systems and worked with utilities to correct issues involving access controls, authentication and internet exposure. 

Some of the most valuable protections are also among the simplest. Federal agencies recommend changing default passwords, enabling multifactor authentication, limiting remote access and keeping an updated list of connected equipment. 

Utilities also need offline backups and tested plans for operating manually. A treatment plant that can safely continue functioning without its internet connection is harder to disable completely. 

Technology alone will not solve the problem. Small utilities need trained personnel, reliable funding and clear channels for reporting attacks without fear that disclosure will bring only punishment or public panic. 

Safe water does not mean the warning should be ignored 

Aerial photograph showing the water tower and nearby residential area in Austin, Minnesota.
Photo by Tom Fisk

For the public, the immediate message is reassuring: officials have not reported that the latest attacks contaminated drinking water. 

Residents in affected areas should follow notices from local utilities rather than social media rumors. If authorities recommend boiling water or limiting its use, those instructions should be taken seriously. Without such an advisory, a cyberattack does not automatically mean the water is dangerous. 

The larger message is less comforting. Hackers have shown that systems controlling an essential public service remain reachable. 

A cyberattack does not need to poison water to cause harm. It can interrupt service, reduce pressure, delay treatment, damage equipment or force a utility to operate manually. A prolonged disruption could affect homes, hospitals, schools, firefighters and businesses at the same time. 

Clean water usually arrives without ceremony. A faucet opens, water moves through the pipes, and an unseen network of pumps, sensors and treatment equipment quietly does its job. 

That dependable service is precisely what makes water infrastructure both essential and attractive to attackers. 

The latest breaches caused limited disruption, and officials found no evidence that drinking water was contaminated. Still, the campaign exposed weaknesses that cannot be forgotten once the immediate investigation fades from public attention. 

It also allowed utilities to find vulnerable systems before a more serious emergency occurs. Federal agencies are now helping water providers strengthen passwords, restrict remote access, and prepare reliable manual backup procedures. 

With the danger finally in plain sight, can this warning help America build safer and more resilient water systems? 

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *