U.S. authorities have issued an urgent cybersecurity warning following a sharp increase in cyberattacks targeting water and wastewater systems, highlighting the growing risks facing critical infrastructure as cyber threats continue to evolve.
The Cybersecurity and Infrastructure Security Agency (CISA) urged operators of water utilities to immediately strengthen their defenses, including disconnecting industrial control systems from the internet whenever possible and minimizing external network exposure.
Coordinated Attacks Target Dozens of Water Systems
The warning follows reports that more than 30 community water systems in Minnesota were targeted in a coordinated cyberattack on July 26 and 27.
The Federal Bureau of Investigation (FBI) also confirmed receiving reports from water utilities in at least seven states, noting that some of the attacks disrupted normal water operations.
Although officials stressed that drinking water safety was not compromised, several facilities were forced to restart systems manually after operational disruptions.
How the Attacks Disrupted Operations
According to federal cybersecurity agencies, attackers changed operator passwords in several cases, preventing personnel from accessing industrial control systems.
Hackers also disconnected devices from operational networks, forcing some utilities to issue precautionary boil-water advisories and continue operating manually until systems could be restored.
The FBI added that some affected facilities reported reduced water pressure and localized flooding as a result of operational impacts.
Industrial Control Systems Under Attack
The attacks primarily targeted industrial control technologies used to monitor and operate water infrastructure, including programmable logic controllers (PLCs), remote monitoring systems, and operator interfaces.
These technologies are essential for managing pumps, water pressure, treatment facilities, and overall distribution networks, making them attractive targets for cybercriminals.
Investigation Continues
Federal investigators continue to examine the incidents, while media reports indicate authorities are evaluating whether hackers linked to Iran may have been involved. No official attribution has yet been announced.
Minnesota officials said they have shared technical evidence with federal agencies, which are assessing the attacks within a broader national cybersecurity investigation.
Growing Threats to Critical Infrastructure
The incidents underscore the increasing cyber risks facing critical infrastructure worldwide, particularly sectors such as water, energy, transportation, and telecommunications.
Cybersecurity experts emphasize that organizations operating industrial control systems should strengthen network segmentation, regularly update security measures, and isolate operational technology from the public internet whenever feasible.
The latest warning serves as another reminder that protecting critical infrastructure has become a national security priority in an era of increasingly sophisticated cyber threats.
