FBI Warns Cyber Attackers Target Water Systems in Seven States

0

Hackers are remotely accessing water system controls in at least seven states — changing passwords, altering settings, and causing operational chaos including pressure loss and flooding, the FBI warned this weekend.

The attacks represent one of the most widespread and coordinated campaigns against American water infrastructure in recent years, exposing vulnerabilities in systems that serve millions of residents across the country. Cybersecurity experts have long warned that water facilities, particularly smaller municipal operations, remain attractive targets for malicious actors seeking to disrupt essential services.

Michigan officials reported Saturday that nine water systems in the state had been targeted following Minnesota’s disclosure earlier this week that more than 30 systems were hit. The FBI confirmed at least five additional states have been affected.

The scale of the intrusions has raised concerns among federal and state officials about the security posture of water infrastructure nationwide. Water systems represent critical infrastructure that communities depend on daily, making them high-value targets for those seeking to create disruption or send political messages through cyberattacks.

Dale George, director of communications for Michigan’s Department of Environment, Great Lakes and Energy, said the state received reports soon after a federal cyber alert was issued Tuesday warning of attempts to tamper with operational technology at water facilities.

“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said.

The FBI’s Cyber Division issued a stark warning Thursday on X, describing how malicious actors are conducting attacks targeting operational technology devices at water and wastewater facilities nationwide.

Programmable logic controllers, or PLCs, are industrial computers that control machinery and processes in water treatment facilities. When these devices are connected to the internet without proper security measures, they can become entry points for hackers seeking to manipulate critical infrastructure operations.

“These threat actors are remotely accessing internet-facing PLCs, changing IPs and passwords, and causing operational disruption, including pressure loss and flooding,” the FBI said.

State and local officials nationwide are on high alert following the wave of intrusions targeting computer systems that monitor and manage municipal water supplies, though Minnesota authorities emphasized there is no indication drinking water has been compromised.

The distinction between system access and actual contamination is critical for public understanding. While hackers gained entry to control systems, there is no evidence suggesting they successfully poisoned or contaminated water supplies in ways that would pose immediate health risks to consumers.

Minnesota officials noted that most confirmed intrusions targeted operational technology used for remote equipment monitoring and control. They clarified that an “impacted” system experienced confirmed cyber activity but did not necessarily lead to service disruptions for residents.

The New York Times cited Iran as the culprit behind the attacks, but President Donald Trump pushed back hard during a Cabinet meeting at Camp David on Friday.

Trump instead blamed Minnesota Governor Tim Walz and the state’s leadership for the breaches, calling them “grossly incompetent.”

The disagreement over attribution highlights the complexity of cybersecurity investigations and the political sensitivities surrounding infrastructure attacks. Determining the source of cyberattacks often requires extensive forensic analysis and intelligence gathering, and premature attribution can complicate diplomatic and law enforcement responses.

While the source of the attacks remains under investigation, Iranian-linked hackers have shown persistent interest in U.S. water infrastructure for years, according to the Associated Press.

Previous incidents have demonstrated that foreign adversaries view water systems as potential leverage points. The relatively low security standards at many facilities, combined with the essential nature of water services, make them appealing targets for actors seeking to demonstrate capability or retaliate for geopolitical tensions.

EPA data shows that 97 percent of the nation’s 156,000 public water systems each serve fewer than 10,000 people — smaller facilities that may lack the cybersecurity resources of larger municipal operations.

These smaller systems often operate with limited budgets and minimal IT staff, making it difficult to implement robust cybersecurity measures or maintain constant monitoring for threats. Many rely on outdated equipment and may not have dedicated personnel trained in cybersecurity best practices, creating systemic vulnerabilities across the nation’s water infrastructure.

The FBI said in a separate statement Saturday that the agency and interagency partners “are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties.”