Iran Suspected as Water Utility Cyberattacks Spread Across Seven States
The attacks are targeting internet-exposed industrial controllers.
Cyberattacks have reportedly targeted municipal water systems in at least seven states over the past week.
The activity led the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. All water systems are reported to be operating safely.
Earlier this week, authorities said cyberattacks targeted over 30 water systems in Minnesota. The source of the attacks is being investigated, but they came amid warnings that Iranian hackers have been focused on such systems.
The reports in Michigan surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems.
Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” said Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy. He later said nine systems were impacted.
“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said in an statement.
At Least Seven States Hit in Water Systems Cyberattack Linked to Iran https://t.co/ADA6KCQSlp
— Dawn Wildman (@WildmanDawn) August 1, 2026
According to one official, the attack had the “hallmarks of Iranian meddling”.
In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.
The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation.
…Thursday’s federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions.
Earlier this week, the Wisconsin Department of Natural Resources issued a bulletin to water contacts in the state, saying intelligence officials believed that “systems within Wisconsin may be susceptible to connections from malicious cyber actors.”
The attacks are targeting internet-exposed industrial controllers.
The FBI, Environmental Protection Agency and CISA all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities.
In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding.
Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services.
…Nick Anderson, acting director of CISA, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.”
As investigators work to identify the source of these attacks, the incidents are a much-needed reminder that water systems are now a frontline target in cyberspace.
Utilities will need to move quickly to harden internet-facing controls and tighten monitoring to reduce the risk of similar disruptions… and maybe begin making arrangements for options to return to more traditional technologies that are less exposed to cyberspace. Sometimes, the old ways are the best ways.
Just as important, federal and local partners must use what they learn from this investigation to strengthen defenses before a more serious attack can take hold.
Donations tax deductible
to the full extent allowed by law.






Comments
I just have to ask, what idiot decided to put stuff like that on the internet? That’s who’s responsible for the Cyber attacks, that stuff doesn’t need to be there and you can’t attack stuff that isn’t connected. Find the incompetent retards that did that and fire them
Yeah. A few elections ago, the elections cabal in Maricopa County was simultaneously denying that any of their machines were exposed to the internet, and listing “routers” on the list of equipment they were refusing to surrender to the forensic investigators.
Oops.
In theory, you can have a router for a completely local “intranet” that isn’t connected to the public internet.
If they had said “switch” I wouldn’t have given it a second thought, but router implies concentration and forwarding. And saying that you refused to disclose the “contents” of your router because they were security sensitive is practically an admission of guilt.
You would be surprised. I have worked in that world for 42 years, there is a lot of lip service towards OT security but most of the idiots at the top are of the DIB are clueless about OT security, I have spent the last 2 years writing a 1000 page book on the subject, literally a hand holding step by step instruction manual about how to build a Secure Connected Factory. Even the 50 million dollar a year automation integration company that i work for that directly works in the OIB refused to look at it.
WWCKD?
What would Col Kurtz do?
“Earlier this week, authorities said cyberattacks targeted over 30 water systems in Minnesota.”
So Iran is attacking Somalis? 🍿
I guess those 30 water quality districts should just sign some ceasefire agreements with Iran, and problem solved.
Bomb their power and water, route all their internet traffic to /dev/null. They want to play, show them we play nastier.
It did strike me that Iran is in no condition to be playing with other people’s water right now.
Asymmetric warfare of one form or another is the preferred tactic of lesser powers. They can’t win in a straight up fight v a much stronger/more powerful enemy so they, very wisely, find ways to punch above their weight outside conventional means. If you ain’t cheating you ain’t trying and there’s no such thing as ‘fair’ in armed conflict. Ultimately it doesn’t matter how or what means are used a facility is disrupted/damaged so long as the objective is achieved.
The cyber attacks illustrate bet are not occurring from Iran proper. Their hackers are located in Venezuela, Cuba and the US. It’s better to localize where the attacks are coming from. Bait them into attacking routers purposely left open to attack to back track the traffic. It’s why we have the NSA.
Definitely, the origin of the attacks are dispersed, they sure as heck ain’t all coming out of Tehran. Could even be hiring US Citizen hackers.
The larger point is these cyber attacks are …attacks. They are a legit form of modern warfare. Same.for what we’re watching in Ceuta or the ‘migrant’ surge under Biden. These are forms of asymmetric warfare and IMO its past time to begin regarding them the same way we would a conventional attack and stop pretending that an ‘attack’ requires a uniformed army. Anyone still insisting that only a uniformed force directly under open command and control by a Nation State can be considered an ‘invasion’ and thus a legitimate/credible threat should reconsider their interpretation in light of 9/11.
Joe Potatobrain rolled out the red carpet for invading terrorists. Majorkas gave them gift packs once they broke in. Taxdollars to the “educational system” have stupid kids defending the destruction of America.
I’m all for that. But you know, nobody is going to retrofit our constitutional language to take into account that attacks don’t require uniformed armies anymore (not even physical sorties, like Pancho Villa). That means our domestic traitors have even less to fear for all the actual treasons they continue to commit.
I have long wondered whether the 4th Amendment will survive Islam or, if it does, whether the US can survive the 4th Amendment.
Henry,
The issue isn’t the language/text of the Constitution that requires a retrofit aka amendment. What is required is to simply stop pretending not to know, ending willful blindness. I do agree the useful idiots will continue to claim only armies/nation States can ‘invade’. Frankly I’m tempted to.argue their continued denial of reality should result in their being involuntarily committed or at least removed from office.
Find out who they are, raid them, and shoot to kill. Screwing with with a water supply is akin to a WMD.
If you don’t want to shoot to kill or want to save a few of them for information invite them to take a vacation at a black base in some forsaken country and squeeze them until they spill everything. Yes I know torture is illegal and they claim is it doesn’t work but I don’t care about the former and I don’t believe the latter,
Explain again to me why you would expose ANY sort of utility control to the f^@*ing internet?
I smell a water rat.
This sounds very psy-oppy to me.
First, *Russia, Russia, Russia*. Then *China, China, China*. Now, *Iran, Iran, Iran*.
Don’t fall for it, Kids.
The government allowed utilities to force “dumb meters” on the public, which are internet vulnerable and RF contaminating; let alone their fire and explosion hazards.
Well, we DID bomb them.
Or refrigerators, AC thermostats all.sorts of appliances including electronic door locks.
Because the local officials were convinced by the tech industry that it was the thing to do. And in general, if done properly it isn’t a security problem. But few local government IT departments know what they are doing security wise and end up exposing critical software/infrastructure to the wild and wooly internet where it can be easily accessed and hacked.
eot
So you can control it from your headquarters. Of course, the sane way would involve using a VPN or something functionally similar.