What to Know About the U.S. Water Systems Cyberattacks

Wait 5 sec.

A cyberattack targeted the operating technology at over 30 water systems in Minnesota last week, including Plymouth's, state officials said. —Ellen Schmidt—APMalicious cyber activity has affected technology at water systems in at least seven states last week, forcing some facilities to switch to manual operations and prompting the FBI and Environmental Protection Agency (EPA) to warn facilities nationwide of hackers.  Minnesota IT Services said in a statement last week that at least 30 municipal water facilities were targeted July 26-27 and that it had “immediately activated the state's cybersecurity incident response capabilities.” Over the weekend, Michigan also reported cyberattacks on nine of its water systems. Without confirming just how widespread the attacks may have been or which states they affected, the FBI and EPA said in a joint statement that multiple incidents had occurred. It explained that hackers are remotely accessing internet-connected controls, changing administrator passwords, and “causing operational disruption” like flooding and pressure loss, which “could potentially allow untreated ground water to seep into pipes.”The incidents also came days after federal agencies updated a warning about ongoing Iranian cyber threats targeting U.S. critical infrastructure, though investigators have not publicly linked the latest attacks to Tehran.Read More: Why Cybersecurity Threats Are GrowingUnited States water systems are a part of critical infrastructure in the country, which makes them attractive targets for cyberattacks. The EPA has warned in recent years that a significant number of local water systems had critical or high-risk vulnerabilities, including “outdated software, poor network security, weak access controls, and a lack of employee cybersecurity training.” But it has also indicated that it’s up to individual operators to protect their own systems from external threats. An EPA spokesperson pointed TIME to Administrator Lee Zeldin’s comments on FOX on Saturday, where he called on utility operators and local entities to protect themselves.“There is a lot of individual responsibility on the part of companies and local water systems and infrastructure and local municipalities and state governments,” he said.“Even water organizations with mature cybersecurity processes should validate their external connections,” the Cybersecurity and Infrastructure Security Agency (CISA) said in an alert issued last week. It outlined several mitigations, including adding extra layers of password security and disconnecting key systems from the internet. In practice, this responsibility is split between local utility operators and federal oversight bodies, with funding coming from both federal allocations and municipal budgets, making cybersecurity upgrades difficult to coordinate.And vulnerabilities may be present within water systems of all sizes, CISA said in its alert, which further noted that the agency was “observing a significant increase in cyber threat actors.”But the impact of the latest round of attacks has been limited, according to state officials. The attacks primarily resulted in an interruption of service at the facilities, rather than putting Americans at risk by means such as exposing their drinking water to contamination.Dale George, the director of communications for Michigan’s Department of Environment, Great Lakes and Energy, said in a statement Saturday that “all systems continued to operate safely.”Federal agencies are investigating who might be behind the latest attacks.“The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties,” the FBI said in a statement to TIME. “Cybersecurity threats are a serious concern for our nation’s water infrastructure, including the communities, businesses, hospitals, schools, and other critical infrastructure sectors that rely on these critical lifeline services,” EPA Assistant Administrator for Water Jess Kramer said in an advisory released by CISA in April.The advisory, which warns about Iranian cyberattacks targeting the internet-connected systems commonly used to operate pumps, motors, and valves, was updated on July 22—just days before the latest attacks on U.S. water systems.Could Iran be connected to the attacks?The FBI, EPA and CISA put out a joint statement last week to accompany the advisory updates. It warned of “ongoing Iranian-affiliated cyber activity” targeting critical U.S. infrastructure, including “Water and Wastewater Systems, Energy and Government Services and Facilities, to include local municipalities.” When water systems were attacked in the following days, it quickly drew attention to the possibility of Iranian involvement—especially in light of the similarity to an incident from 2023, involving a cyberattack on a municipal water facility in Pittsburgh, Pennsylvania. CISA attributed it to a group called CyberAv3ngers, which is affiliated with the Islamic Revolutionary Guard Corps. "If a hack like this can happen here in Western Pennsylvania, it can happen elsewhere in the United States," lawmakers wrote in a letter to the Attorney General.The latest attacks also come at a moment when Iran has both an apparent motive and well-established cyber capabilities.They took place amid escalating tensions between the U.S. and Iran, marked by near-daily strikes and an ongoing standoff over control of the Strait of Hormuz. When asked about potential Iranian involvement, President Donald Trump dismissed the suggestions and instead, without offering evidence, blamed Minnesota."You know who's behind it? Minnesota. Because they're grossly incompetent,” Trump said during a televised Cabinet meeting at Camp David on July 31. “I think the governor's behind it. I don't think there was an Iranian cyberattack. I think that Minnesota ought to get its act together."He continued, “They like to say, 'Oh, it was Iran.' Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota.”Minnesota Gov. Tim Walz, who has repeatedly come under attack by Trump, fired back on social media, pointing out how the Trump Administration’s Department of Governmental Efficiency (DOGE) “took an axe to CISA and left the U.S. exposed to cyber attacks.” In 2025, DOGE performed sweeping workforce reductions to the agency, which is responsible for coordinating civilian cybersecurity, leading to a loss of roughly one-third of its workforce.In a separate statement on X, Walz suggested Iran targeted Minnesota as retaliation for Trump’s recent strikes on its infrastructure.“This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran,” Walz said.Emphasizing comments that he recently shared on X, Trita Parsi, Executive Vice President of the Quincy Institute for Responsible Statecraft, said that it would be reasonable for Iran to attempt cyber attacks as a “warning” that it is prepared to retaliate for U.S. strikes.And Parsi tells TIME that Iran is more than capable of fulfilling the threat.“Iran is a highly capable cyber power, only one tier below the U.S., China, and Russia, and in some aspects on par with Israel,” he says. “It has in the past demonstrated a clear ability to target industrial control systems, water facilities, and energy infrastructure.”The joint statement issued last week by federal agencies also underscored Iran's cyber capabilities. “Iranian cyber actors continue to target U.S. critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. However, he added, “The FBI is committed to identifying, disrupting, and imposing costs on those responsible. Sharing timely, actionable intelligence is a critical part of that work.”As investigators work to determine who was behind the attacks, federal officials have continued to point operators to the updated advisory for guidance on defending against future incidents. In the statement accompanying its release, Leatherman urged network defenders to use the recommendations to "identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on."