Cyberattacks on US water systems span multiple states

Federal agencies warned that hackers hit internet-exposed water controls in at least seven states, with later tallies near a dozen. CISA is still finding exposed systems while Congress argues about funding.

Younes Bekrar8 min read
ShareXLinkedInFacebook
Cyberattacks on US water systems span multiple states

Late July into early August 2026, US water and wastewater utilities became a national cyber story for the least glamorous reason. Attackers reached internet-exposed controllers, changed passwords and settings, and knocked some plants into manual operation. The FBI, EPA, and CISA warned of incidents in at least seven states. Later reporting put the map closer to a dozen, including Minnesota, Michigan, Georgia, New Jersey, and South Dakota. Minnesota IT Services said more than 30 community systems were targeted. Georgia's Clayton County Water Authority described pressure drops and a boil-water advisory before recovery. TIME and Nextgov kept the operational picture ugly after the first headlines. This is not a novel exploit essay. It is an exposure and response story.

What happened to the water systems?

Operators and federal advisories describe remote access to programmable logic controllers and related interfaces that should never face the open internet. Attackers altered credentials and configurations. Effects included loss of monitoring, pressure anomalies, flooding risk language in federal statements, and shifts to manual control. Public health impacts were described as limited in official state comments, which is reassurance with an asterisk. Manual mode does not scale forever.

CISA's guidance has been blunt. Disconnect exposed controllers from the internet. Change default passwords. Validate external connections even if you think your program is mature. Acting Director Nick Andersen told Nextgov at Black Hat week that CISA was still finding exposed water controls while helping victims with the FBI, and that attribution was not the agency's immediate focus.

Readers in security should hear the pattern from older OT incidents. The vulnerability is often connectivity policy, not a brand-new cryptographic break.

What we know about blame and what we do not

Anonymous officials and some intelligence assessments discussed in outlets such as the Washington Post have pointed toward Iran-linked actors. Federal public language has referenced Iranian-affiliated activity against critical infrastructure in broader warnings. Andersen's on-record stance in Nextgov was that CISA was not doing attribution in that moment and was prioritizing assistance and hardening.

That gap matters. "Sources say" and "agency attributes" are different products. This article will not invent a courtroom-ready culprit. Utilities should patch and isolate regardless of which flag someone plants on a slide.

I will also not publish controller exploit steps. If you run a plant, follow CISA and EPA advisories and your state's incident channels.

Why CISA funding entered the politics

Multistate physical-world cyber effects revive the same congressional fight that never stays solved. Who pays to harden thousands of small utilities. How much of CISA's budget is treated as optional. Reporting around EPA revolving fund cuts in budget proposals has already alarmed people who expected federal money to backstop local OT upgrades. Exact bill horse-trading moves week to week. The structural point does not. Tiny utilities cannot staff a 24/7 SOC.

Bipartisan concern after visible infrastructure incidents is real even when the appropriations text is messy. Watch whether hearings produce cash and standards or only camera time.

I am filing this as critical infrastructure exposure with a manpower moral. The internet-connected pump is still the plot. More OT-adjacent coverage continues with Younes Bekrar in security.

Related reading on Skarvonix: our security category, the authors directory, and more from Younes Bekrar.

Frequently Asked Questions

How many states saw water system cyberattacks?

Federal warnings cited at least seven states. Later reporting described about a dozen states with similar activity, including a large cluster in Minnesota.

Were the water cyberattacks attributed to a country?

Some officials and sources have suspected Iran-linked actors, but CISA's acting director said publicly the agency was focused on response rather than attribution at that time.

What should water utilities do right now?

Follow CISA and EPA guidance. Remove operational controllers from the public internet, rotate credentials, and validate remote access paths with state and federal partners.

  • Zero Trust
  • Edge Computing
  • Privacy

Keep reading