
Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure.
In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.
The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation.
In an email this week, a spokesperson for Minnesota’s information technology services agency said there were no indications the breaches contaminated any municipality’s water supply.
The new federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions.
The warning highlights the vulnerability of some U.S. infrastructure systems to meddling by adversaries at a time when the conflict in Iran is escalating militarily and the U.S. has been unable to find a way out of the war it started along with Israel.

The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities.
The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.
The agencies did not identify the culprit behind the breaches. Similarly, the U.S. government and state officials have not publicly attributed the malicious activity in Minnesota to a specific actor.
“Attribution requires careful analysis of technical evidence alongside broader national and international threat intelligence, and our federal partners are best positioned to lead that work,” said Emily Zimmer, a spokesperson for Minnesota’s information technology agency.
The breach in Minnesota happened just days after U.S. officials publicly warned that Iran-backed hackers were targeting the nation’s critical infrastructure amid the escalating military conflict between Washington and Tehran.
In a public advisory July 22, the Cybersecurity and Infrastructure Security Agency, as well as the FBI and other federal agencies, urged companies to boost their defenses, saying Tehran-linked hackers were trying to breach online automated devices used to manage infrastructure systems.
U.S. intelligence agencies have also cautioned that Iran is increasingly able and willing to carry out aggressive cyber operations and that it tried to target water systems in 2023.
Two years ago, the EPA warned that cyberattacks against water utilities nationwide were becoming more frequent and more severe. In an enforcement alert in May 2024, the agency said about 70% of utilities inspected by federal officials over the past year had violated standards meant to prevent breaches or other intrusions.







