Water utilities in seven U.S. states have been hit by cyberattacks since July 27, according to a public warning from the FBI and the Environmental Protection Agency. The incidents targeted systems that connect digital commands to physical treatment and distribution equipment. Reports of flooding and lost water pressure show why the campaign is more serious than a routine network breach.
The agencies have not named the affected states or released a full account of the damage. They say the attacks degraded water operations, while the Cybersecurity and Infrastructure Security Agency has separately warned that some intrusions disabled digital controls and resulted in boil-water notices. That leaves the public with a clear risk picture but limited information about individual facilities.
Investigators are focusing on internet-facing programmable logic controllers, or PLCs. These devices help utilities monitor and control industrial equipment. The attackers were able to reach exposed devices remotely, change IP addresses and passwords, and prevent operators from managing their systems as they normally would.
How the Water Utility Attacks Worked
Engadget reported that the FBI had received reports of flooding and pressure loss after the intrusions. A drop in pressure can allow untreated groundwater to seep into pipes, turning a digital disruption into a potential water-quality problem. The warning does not say that every affected utility experienced contamination, but it explains why pressure control matters beyond the treatment plant's computer network.
The campaign appears broader than the seven utilities named in the federal warning. More than 30 municipal water facilities in Minnesota were infiltrated over the previous week, according to reporting cited by Engadget and WIRED. Law enforcement has not confirmed that Iran was responsible, but a memo obtained by WIRED linked the Minnesota activity to a hacking campaign previously described by CISA as Iran-affiliated.
WIRED reported that the FBI's alert did not identify the other targeted states or describe the extent of disruption at each site. The FBI and EPA are working with affected utilities, while CISA is urging operators to remove internet exposure from devices that connect directly to physical equipment. The lack of a public state-by-state accounting makes it impossible to judge whether the incidents produced one consistent level of service interruption.
Why Exposed Industrial Controls Matter
PLCs are not ordinary office computers. They translate software instructions into changes in pumps, valves and other equipment that keep water moving through a system. When an attacker changes access credentials or blocks a controller from the operators' screens, staff may lose the ability to observe conditions or respond quickly to a malfunction.
That vulnerability is amplified by the way many smaller utilities manage limited technical resources. A controller exposed for remote maintenance may be convenient during normal operations, but the same connection can become an entry point for an intruder. The federal advice is therefore straightforward: place secure gateways and firewalls between operational devices and the open internet.
The agencies also recommend stronger passwords and access-control lists that permit communications only from authorized devices. Those measures will not answer every question about the current campaign, but they reduce the number of paths an attacker can use to reach equipment. They also give operators a practical way to separate remote convenience from the controls that must remain protected. Attribution remains unsettled. WIRED described Iranian-affiliated hackers as the leading suspect and connected the Minnesota incidents to an earlier CISA warning, while Engadget noted that law enforcement has not confirmed the country was involved. President Donald Trump blamed Minnesota Governor Tim Walz's administration for the attacks, but that political claim does not establish who entered the systems or what caused the operational disruptions.
What Utilities Need to Establish Next
The immediate priority is to identify every internet-facing controller, remove unnecessary exposure and confirm that authorized accounts still control the devices. Utilities also need to determine whether pressure changes, flooding or boil-water notices were linked to the intrusions or arose from separate operational faults. Public reporting should distinguish those findings from the broader warning so that residents are not left guessing about local conditions.
The campaign also demonstrates why water cybersecurity cannot be measured only by stolen files or locked office computers. A PLC intrusion can affect a physical process even when the attacker never takes data from a traditional corporate server. That connection between network access and public service makes small utilities part of a national security problem, regardless of whether the final attribution points to Iran or another actor.
For now, the confirmed facts are narrower than the most alarming headlines. Seven states have reported affected water or wastewater utilities, the FBI and EPA are involved, Minnesota suffered a larger cluster of intrusions, and officials are warning operators to close exposed control paths. The damage, the identities of most victims and the attribution remain incomplete.
The strategic lesson is already visible. Water systems need to treat remote control access as an operational safety issue, not merely an IT setting. Strong passwords, allow-lists and secure gateways can reduce exposure, but they cannot replace detailed incident reporting and independent verification. Until authorities publish more about the affected facilities, the responsible assessment is that the campaign is a serious warning of physical consequences, not proof that every targeted utility suffered the same level of harm.