US Cyber Agency Warns of Rising Water System Cyberattacks
The U.S. government’s civilian cyber defence agency has warned of a sharp rise in cyberattacks targeting technology used to operate water and wastewater systems. Officials have urged operators to remove internet-connected control systems as quickly as possible to reduce the risk of further intrusions.
The warning follows reports that more than 30 community water systems in Minnesota were targeted in a coordinated cyberattack on July 26 and 27, according to the state’s information technology agency.
The FBI said late on Thursday that water and wastewater utility companies in at least seven U.S. states have reported similar incidents. In some cases, the cyber activity disrupted water operations.
Federal Agencies Investigate Coordinated Attacks
U.S. officials and investigators reviewing the incidents believe hackers linked to Iran are likely responsible for the attacks in Minnesota, according to a New York Times report. Iranian government representatives did not immediately respond to requests for comment.
The White House referred questions about the Minnesota incidents to the FBI. The bureau also did not immediately comment on the reported Iranian involvement.
The attacks come amid heightened tensions between the United States and Iran, with both countries exchanging missile strikes and issuing further threats. However, cyber activity linked to Iranian groups targeting U.S. water facilities began before the current conflict.
Earlier this year, several cyberattacks linked to Iranian-affiliated groups also targeted U.S. organisations, including medical services company Stryker and the Los Angeles County Metropolitan Transportation Authority.
Water Systems Experience Operational Disruptions
State and local officials said the Minnesota attacks did not compromise the safety of drinking water. Nevertheless, several systems were temporarily taken offline and required manual resets before operations could resume.
The Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers have, in some cases, changed passwords to lock operators out of critical systems. The agency also said hackers disconnected certain devices from operational networks, resulting in boil water notices and prolonged periods of manual operation.
According to the FBI, unidentified victims have reported operational consequences that included reduced water pressure and flooding at some facilities.
Minnesota IT Services confirmed that its investigation remains ongoing. Officials said most confirmed cases involved technology used to remotely monitor and control water infrastructure, including programmable logic controllers (PLCs) and the operator interfaces used to manage them.
John Israel, Minnesota’s chief information security officer, said the state has shared relevant information with the federal government. He added that federal agencies are assessing the incidents as part of a broader national investigation to determine whether they can be attributed to a specific threat actor.
Experts Link Activity to Earlier Campaigns
Cybersecurity experts said the recent attacks closely resemble earlier campaigns attributed to Iranian-affiliated hackers.
Cynthia Kaiser, a former senior FBI cybersecurity official, said it is highly likely that the Minnesota incidents represent a continuation of previous efforts targeting programmable logic controllers and other critical infrastructure technology. She noted that CISA, the FBI, the National Security Agency and other federal agencies issued a joint advisory in April outlining similar threats.
The advisory was updated on July 22 to expand the list of targeted devices and include newer techniques and activities associated with the campaign.
Kaiser, now an executive at cybersecurity firm Halcyon, said the updated advisory suggests that the campaign has broadened, evolved technically or resumed with increased activity.
Chris Day, public sector chief technical officer at cybersecurity firm Tenable, also said the Minnesota incidents appear consistent with previously identified Iranian-linked activity. He added that reports of water systems being temporarily taken offline represent a notable escalation compared with earlier attacks.
With inputs from Reuters

