Unidentified hackers targeted municipal water and wastewater utilities in at least seven U.S. states this week, the FBI said [1].
These attacks target critical infrastructure that provides essential drinking water and sanitation to millions of citizens. The breach of these systems could lead to widespread public health crises if water quality or distribution is compromised.
The cyberattacks focused on internet-exposed computers known as programmable logic controllers [2]. These devices are used by municipal water systems to manage operational functions. The FBI said the intrusions caused loss of pressure and other operational disruptions [2].
In Minnesota, the impact was particularly severe. More than 30 water systems in that state were hit by the attacks [3]. This concentration of targets suggests a coordinated effort to destabilize regional utility services.
While the FBI has issued a public service announcement regarding the threats, the origin of the attacks remains a subject of investigation. Some reports indicate that the activity may be linked to Iranian actors attempting to disrupt critical U.S. infrastructure [4, 5].
Officials have urged utility providers to secure their networks and remove controllers from the public internet to prevent further access. The FBI said it continues to monitor the situation as more utilities assess the extent of the damage to their systems [1].
“The intrusions caused loss of pressure and other operational disruptions.”
This wave of attacks highlights a systemic vulnerability in U.S. municipal infrastructure, where legacy hardware like programmable logic controllers are often left exposed to the public internet. The potential involvement of a foreign state actor suggests that water utilities are now being viewed as viable targets for geopolitical leverage or asymmetric warfare, shifting the threat landscape from data theft to physical operational disruption.



