🧬 Interested in pharma, biotech and medical device news? Visit PharmaDeviceNews.com →

Cyberattacks hit water systems in seven states as FBI warns of pressure loss and flooding

Cyberattacks hit water utilities in seven states as the FBI warns hackers caused pressure loss, flooding and control-system failures.

Cyberattacks targeting water and wastewater utilities have expanded beyond Minnesota to at least seven states, prompting the Federal Bureau of Investigation and Environmental Protection Agency to issue an urgent warning about hackers gaining access to internet-connected industrial control equipment. Federal authorities said some incidents degraded water operations, producing effects that included loss of pressure and flooding, although there has been no confirmed widespread contamination of public drinking water. The warning followed a coordinated attack against more than 30 Minnesota community water systems on July 26 and July 27, where hackers interfered with technology used to monitor wells, treatment equipment and distribution networks. Investigators are examining possible links to Iranian-affiliated cyber groups, but no government agency has publicly made a final attribution, and President Donald Trump said on July 31 that he did not believe Iran was responsible.

The FBI and Environmental Protection Agency said malicious actors were targeting operational technology devices, including Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers. These specialized computers can control or monitor pumps, valves, pressure levels, treatment equipment and other physical processes inside water facilities. Hackers remotely accessed devices that were directly exposed to the internet, changed internet protocol addresses and passwords, and caused operators to lose visibility or control of connected systems.

Federal authorities advised utilities to remove programmable logic controllers from direct internet exposure, place remote access behind secure gateways and firewalls, use strong passwords and limit communications to authorized equipment. The warning reflects concern that the Minnesota incidents may represent part of a wider campaign against smaller American utilities whose operational systems remain accessible online.

How hackers disrupted water operations without contaminating Minnesota drinking supplies

Minnesota officials said most confirmed attacks involved remote-monitoring and control technology rather than the water itself. Being listed as an affected community therefore did not necessarily mean that residents lost service or received unsafe water. It meant investigators had confirmed malicious activity involving the utility’s operational systems.

Braham, a city of approximately 1,700 people north of Minneapolis, experienced one of the clearest operational disruptions. Hackers shut down controls connected to the city’s well and water-treatment plant, temporarily leaving the community dependent on water already stored inside its water tower. Officials asked residents to minimize consumption for several hours while employees investigated the outage and restored operations. The city said the incident did not affect water quality.

Plymouth, which has approximately 80,000 residents, also confirmed that its water infrastructure communications had been disrupted. Municipal crews continued operating the system during the outage, preventing changes to water levels or quality, and communications were restored by Tuesday afternoon.

The limited public impact shows that manual controls, stored water and operational safeguards worked in several Minnesota communities. However, the FBI disclosed that utilities elsewhere had experienced pressure loss and flooding. Loss of pressure is particularly concerning because low pressure can allow untreated groundwater or other contaminants to enter damaged or poorly sealed pipes.

The operational effects depend on how a compromised controller is configured. A device used only to monitor equipment may leave operators temporarily unable to see system conditions without directly stopping a pump. A controller that actively manages pumps, valves or pressure can create more serious physical disruption if hackers alter its settings or lock employees out.

See also  EU delivers entire thermal plant to Ukraine: What this operation signals about Europe's long-term energy and defense posture

At least one affected organization discovered modifications to programmable logic controller project files after noticing differences in the system’s ladder logic, the instructions governing automated industrial processes. Federal investigators also found similarities in technology and network configurations across victims, raising the possibility that attackers exploited weaknesses replicated by third-party equipment installers or service providers.

This pattern can turn one poorly secured configuration into a national vulnerability. If multiple utilities use the same equipment, default settings and remote-access structure, attackers who compromise one installation may be able to repeat the process against dozens of other customers.

Why small water utilities have become attractive targets for state-linked hackers

Water systems are among the most essential but unevenly protected parts of United States infrastructure. Large metropolitan utilities may employ dedicated cybersecurity personnel and maintain sophisticated backup networks. Smaller communities often operate with limited budgets, small technical teams and equipment installed years before modern cyber threats became a daily operational concern.

Remote access can be valuable because it allows technicians to check equipment without traveling to isolated wells, pumps or treatment facilities. The same convenience becomes a vulnerability when industrial controllers are connected directly to the public internet, protected by weak credentials or left running outdated software.

Hackers do not necessarily need to contaminate drinking water to create disruption. Locking operators out of a control screen, stopping a pump, altering pressure or forcing a community to issue a boil-water advisory can generate fear, consume emergency resources and attract national attention. The psychological impact can be disproportionate to the technical complexity of the attack.

Iranian-affiliated actors have previously targeted industrial equipment used by water systems and other critical infrastructure sectors. The Cybersecurity and Infrastructure Security Agency updated an advisory on July 22 describing Iranian-affiliated advanced persistent threat actors accessing internet-facing programmable logic controllers and expanding the types of equipment being targeted.

Cybersecurity researchers and unnamed officials have said the Minnesota incidents resemble earlier Iranian-linked activity, particularly because of the targeted technology and attack methods. The Federal Bureau of Investigation has not publicly identified a perpetrator, however, and Minnesota officials have said attribution remains under investigation.

Trump rejected the suspected connection during a July 31 Cabinet meeting at Camp David. He said he did not think Iran was responsible and instead criticized Minnesota’s government as incompetent. His assessment conflicted with reports that investigators considered the attacks consistent with an Iran-linked cybersabotage campaign, but the president did not provide technical evidence supporting his conclusion.

The conflicting statements make careful attribution essential. Cyber groups can imitate another actor’s techniques, use foreign infrastructure or deliberately leave misleading evidence. Governments generally require intelligence, forensic data and operational context before formally blaming another country for an attack on critical infrastructure.

US-Iran conflict raises the stakes of attacks on civilian infrastructure

The cyber incidents occurred while the United States and Iran were exchanging missile strikes across the Middle East, creating concern that cyber operations may be becoming another front in the conflict. Iranian-linked hacking activity against American infrastructure predates the current war, but heightened military tensions provide additional motive for disruptive attacks that remain below the threshold of conventional warfare.

See also  Brent crude tops $105 as Strait of Hormuz remains shut in largest supply disruption in global oil market history

Cyberattacks offer governments and affiliated groups several strategic advantages. They can create economic and political pressure without risking aircraft or personnel, while uncertainty over attribution makes immediate military retaliation more difficult. Attacking dozens of small utilities can also force federal agencies to investigate a wide geographic area and require state and local governments to defend thousands of separate facilities.

Water systems are especially sensitive because reliable access to drinking water is inseparable from public confidence. A brief outage can affect hospitals, schools, fire departments and businesses even when the water remains safe. A more sophisticated operation capable of manipulating treatment chemicals or maintaining prolonged control could create much more severe consequences.

The latest attacks do not appear to have reached that level. Minnesota authorities reported no known contamination, and communities generally restored affected systems quickly. The incidents nevertheless demonstrate that hackers could gain access to equipment controlling physical infrastructure rather than merely stealing data.

This distinction separates operational-technology attacks from conventional corporate breaches. A stolen database creates privacy and financial risks. A compromised industrial controller can change what machinery does in the physical world, including whether a pump runs, a tank fills or pressure remains within safe limits.

The expansion to at least seven states suggests the challenge is national rather than confined to one Minnesota vendor or community. Federal authorities did not identify all affected states or utilities, partly because revealing individual vulnerabilities could create additional security risks.

The FBI and Environmental Protection Agency’s warning is therefore intended to force immediate defensive action before another wave of attacks occurs. Disconnecting exposed controllers may reduce remote convenience, but federal officials have concluded that leaving critical equipment directly available through the internet creates an unacceptable risk.

The Minnesota attacks expose a larger funding and accountability problem

Technical recommendations alone may not solve the underlying vulnerability. Thousands of American water and wastewater systems serve small populations with limited revenue. Replacing industrial equipment, hiring cybersecurity specialists and maintaining around-the-clock monitoring can be expensive, particularly for communities already struggling to repair aging pipes and treatment plants.

Federal and state governments can issue standards and advisories, but local utilities need money, personnel and practical implementation assistance. Requirements that are not matched by funding may leave the smallest systems technically responsible for controls they cannot afford to modernize.

Equipment manufacturers and contractors also face scrutiny. The FBI noted that similarities in third-party network configurations may have allowed hackers to repeat their success across multiple customers. Vendors that install remote-access systems without strong authentication, monitoring or network separation can create common points of failure across otherwise unrelated utilities.

The response will need to address procurement standards as well as operator behavior. Utilities should not receive internet-connected industrial systems configured with predictable settings or inadequate protection. Manufacturers and installers may be required to design secure access as the default rather than expecting small municipal teams to retrofit security later.

See also  US warns Israel: Airstrikes on Lebanese forces could trigger wider conflict

The attacks also create an accountability challenge for the federal government. Officials must determine whether the incidents were coordinated by one actor, identify how the attackers selected their targets and establish whether access remains inside any systems. Restoring equipment does not necessarily prove that every unauthorized account, configuration or hidden entry point has been removed.

The immediate outcome in Minnesota was considerably less severe than the worst-case scenario. Water remained safe, communities used manual operations and local crews restored systems. That limited disruption should not be mistaken for evidence that the threat was minor.

A coordinated actor reached the technology behind essential public services in more than 30 communities and apparently repeated similar operations across several states. The next campaign could target more capable equipment, exploit weaker emergency procedures or occur during extreme heat, flooding or another crisis when utilities have less capacity to respond.

Key takeaways from the cyberattacks on United States water systems

  • The Federal Bureau of Investigation said water and wastewater utilities in at least seven states had reported cyber incidents since July 27, showing that the threat extended well beyond Minnesota.
  • More than 30 Minnesota community water systems were targeted during a coordinated wave of attacks on July 26 and July 27.
  • Hackers accessed internet-facing programmable logic controllers used to monitor or control pumps, pressure, treatment equipment and other physical water-system functions.
  • The attackers changed internet protocol addresses and passwords, causing some operators to lose monitoring access or control over connected equipment.
  • Federal authorities said operational effects across victims included loss of water pressure and flooding, although Minnesota officials reported no confirmed contamination of drinking water.
  • Braham temporarily relied on water stored in its tower after attackers shut down controls connected to its well and treatment plant.
  • Investigators are examining similarities to earlier Iranian-affiliated cyber activity, but the Federal Bureau of Investigation has not publicly identified the attacker.
  • Donald Trump said he did not believe Iran was responsible, placing the president publicly at odds with reports about investigators’ preliminary suspicions.
  • Small utilities are vulnerable because many lack dedicated cybersecurity staff, depend on aging equipment and use remote-access systems that may be exposed directly to the internet.
  • The federal warning shows that securing water infrastructure will require stronger equipment configurations, vendor accountability and funding for local utilities, not merely emergency password changes.


Discover more from Business-News-Today.com

Subscribe to get the latest posts sent to your email.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts