FBI Warns of Cyberattacks Targeting Municipal Water Systems Across Seven States

ALN NEWS DESK
ALN NEWS DESK
Updated : Jul 31, 2026, 07:24 PM IST
6 min read
  • linkedin
  • twitter
  • facebook
  • instagram
  • whatsapp

The FBI and EPA have issued warnings about cyberattacks on municipal water systems in seven states, highlighting the ongoing threat to critical infrastructure.

Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency (EPA) to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. The escalation of these cyber threats raises serious concerns about the vulnerability of essential services that rely on digital systems for monitoring and control.

In a public service announcement issued on Thursday, the agencies detailed that numerous water and wastewater utilities had reported incidents to the FBI, with some malicious activities resulting in degraded water operations. While the announcement did not specify the states affected, it highlighted a growing trend of cyber threats targeting public utilities across the United States.

The warning follows a significant incident in Minnesota, where hackers targeted more than 30 municipal water facilities. This attack has been characterized by law enforcement officials as having potential links to Iranian cyber activities, although the investigation is ongoing and no definitive attribution has been made. This incident raises alarms about the sophistication and motivations behind such cyberattacks, especially given the geopolitical tensions involving Iran and the United States.

A spokesperson for Minnesota’s information technology services agency stated that there was no evidence to suggest that the breaches led to contamination of municipal water supplies. However, the federal Cybersecurity and Infrastructure Security Agency (CISA) noted in a separate alert that some larger attacks on water infrastructure had resulted in boil water notices and required sustained manual operations, although they did not specify the locations of these incidents.

Importantly, both Minnesota officials and the U.S. government have refrained from publicly attributing the malicious activities in the state to any specific actor, reflecting the complexities involved in cyber attribution. The FBI and the EPA similarly did not identify a culprit behind the breaches reported in the other states, which adds to the uncertainty surrounding the motivations and capabilities of the attackers.

In a related political response, President Donald Trump, during a press conference at Camp David, directed criticism towards Minnesota’s leaders, including Governor Tim Walz, who was the Democratic vice presidential nominee in the 2024 election. Trump stated, "I think I blame it on Minnesota because they’re grossly incompetent." This remark underscores the intersection of cybersecurity issues with political discourse, as leaders navigate the implications of such attacks on public safety and governance.

Governor Walz responded by asserting that Trump was aware of the broader context of the attacks and the involvement of other states. He emphasized that the situation represents a new form of modern warfare, linking it to the ongoing tensions with Iran and the need for a coherent strategy to address such cyber threats.

The advisory issued by the FBI and EPA focused less on identifying the attackers and more on the tactics employed during the attacks. The federal advisory indicated that malicious cyber actors (MCAs) specifically targeted certain brands of control systems commonly used by municipal water utilities. However, the FBI and EPA urged operators of all water systems to take precautionary measures to safeguard their infrastructure.

Earlier in the week, the Wisconsin Department of Natural Resources issued a bulletin to water contacts within the state, cautioning that intelligence officials believed that systems in Wisconsin may be vulnerable to attacks from malicious cyber actors. This bulletin indicated a heightened level of concern regarding the ongoing cyber threat landscape, prompting immediate action to mitigate potential risks to water systems.

In the warning, Wisconsin officials noted that Minnesota had reported instances where hackers managed to drop system pressures, which in several incidents triggered alarms and necessitated a response from law enforcement. The implications of such actions could be severe, potentially leading to public health crises if water supply systems are compromised.

The agencies detailed that hackers had remotely accessed internet-facing devices, altering IP addresses and passwords, which resulted in utilities losing monitoring and control capabilities. This highlights the critical need for robust cybersecurity measures in protecting essential infrastructure from cyber threats.

The federal advisory urged system operators to implement several key security practices, including removing programmable logic controllers (PLCs) from direct internet exposure by placing them behind secure gateways and firewalls. Additionally, operators were advised to use strong passwords and limit communications between authorized control system devices through access control lists. These recommendations reflect a proactive approach to cybersecurity, emphasizing the importance of safeguarding critical infrastructure.

Attribution of cyberattacks requires careful analysis of technical evidence alongside broader national and international threat intelligence. Zimmer, the spokesperson for Minnesota’s information technology agency, highlighted that federal partners are best positioned to lead such analytical efforts. This underscores the collaborative nature of cybersecurity, where local, state, and federal entities must work together to enhance resilience against cyber threats.

The breach in Minnesota occurred shortly after U.S. officials publicly warned that Iran-backed hackers were targeting the nation’s critical infrastructure amid escalating military tensions between Washington and Tehran. In a public advisory released on July 22, CISA, along with the FBI and other federal agencies, urged companies to bolster their defenses against potential breaches by Tehran-linked hackers, who were reportedly attempting to compromise online automated devices used to manage infrastructure systems.

U.S. intelligence agencies have increasingly cautioned that Iran possesses both the capability and the willingness to conduct aggressive cyber operations. In fact, there have been attempts to target water systems in the United States as recently as 2023. This evolving threat landscape necessitates heightened vigilance and preparedness from all sectors involved in critical infrastructure management.

Bryson Bort, the founder of the cybersecurity company Scythe and an expert in industrial control system security, commented on the recent disclosures by the FBI, emphasizing the need for increased public awareness regarding the risks associated with infrastructure breaches. He stated, "We need to be prepared. Attacks like this illustrate that there are folks who mean the U.S. harm today." Bort's remarks highlight the urgency of addressing cybersecurity vulnerabilities in public utilities, as well as the need for ongoing education and training for personnel responsible for managing these systems.

As the situation unfolds, it is clear that the implications of these cyberattacks extend beyond immediate operational disruptions. They raise critical questions about the resilience of essential services, the preparedness of state and local governments to respond to such threats, and the broader geopolitical context in which these cyber operations occur. The increasing frequency and severity of cyberattacks on municipal water systems underscore the importance of a coordinated national response to protect public health and safety in an increasingly digital world.

Get More Updates

To learn more about the latest developments in Crime & Law, stay updated with our exclusive reports and analyses on AiLensNews.

Related News