A series of cyber incidents aimed at disrupting water and wastewater infrastructure has heightened alert levels across several states. Federal authorities are scrutinizing attacks that have impaired operations and exposed key vulnerabilities in essential public services.
Federal Alert on Cyber Threats
On July 30, the FBI and Environmental Protection Agency (EPA) made a joint warning. They reported malicious cyber actors targeting water and wastewater systems in at least seven states since July 27, 2026. These cyber threats have caused operational disruptions and in some cases, adversely affected water operations.
Malicious Tactics Used in Attacks
The FBI alert detailed that attackers focused on internet-facing Programmable Logic Controllers (PLCs). These devices monitor and control industrial equipment at water and wastewater facilities. Hackers altered IP addresses and passwords, impacting monitoring and control capabilities. Consequences included flooding and loss of pressure in targeted systems.
Authorities advised utilities to disconnect exposed control systems from the internet and bolster cybersecurity measures. The states affected have not been disclosed yet. News outlets have reached out to the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) for more information.
Minnesota Reports Significant Cyber Activity
Minnesota has faced significant threats, with over 30 attacks reported across the state. These incidents gained national attention when former President Donald Trump addressed cybersecurity threats, criticizing the state’s handling of the situation.
Currently, it remains unknown who orchestrated these cyberattacks. Investigations continue to determine their origins.
Michigan and South Dakota Incidents
In Michigan, an attack affected a water system. Some communities reported incidents with similar tactics to those in the FBI and EPA alerts. The Department of Environment, Great Lakes, and Energy confirmed no threat to drinking water supplies after hackers altered equipment settings.
Rapid City, South Dakota, disclosed a cyberattack on a wastewater lift station. Although the city’s water quality and public safety remained unaffected, efforts are ongoing to investigate the incident.
California Probes Cyber Incident
California has also encountered cyber threats. In June, hackers accessed an active Cal Water customer’s account but did not penetrate internal networks of the utility. While the investigation is ongoing, there was no disruption or evidence of intrusions into water distribution systems.
Potential Link to Iranian Hackers
Federal investigators explore a possible connection between these attacks and Iranian hackers. Although no formal conclusion has been reached, officials examine similarities with past Iranian-linked cyber operations against U.S. water infrastructure.
The question of who is responsible remains politically sensitive. Presidential remarks dismissed premature allegations of Iranian involvement in the attacks on Minnesota.
Broader Implications for Water Systems
The FBI’s alert indicates a broader issue that might extend beyond the publicly acknowledged incidents. These recent threats underscore the increasing vulnerability of water systems serving millions and highlight the need for robust cybersecurity measures.
Investigation efforts continue to uncover perpetrators and assess if connections exist among the attacks in Minnesota, Michigan, South Dakota, California, and additional states.

Compensation Available in Labcorp Data Breach Settlement
Transforming Healthcare with AI: A Human-Centric Approach
White House to Exempt Some AI Systems from Government Vetting
SpaceX Reports Significant Loss After Initial Public Offering
Understanding the Rise of AI-Powered Phishing Scams
Concerns Arise Over Anthropic’s New AI Model and Transparency in AI Journalism