Water Facilities in 12 States Hit by Cyberattacks. The Real Story Is How Attackers Gained Access.

Cyberattacks targeting water utilities in late July and early August demonstrate how exposed OT systems can disrupt physical operations. For CIOs, CISOs and infrastructure leaders, the incidents highlight growing risks from internet-connected industrial controls and the need to strengthen OT security.

Key Highlights

  • Cyberattacks against water utilities in 12 states show how internet-exposed OT systems can disrupt critical infrastructure operations beyond the water sector.
  • Federal agencies warn that the same tactics used against water facilities could target manufacturing, energy, transportation and other industrial environments.
  • The incidents reinforce that OT security is now a business resilience issue requiring stronger asset visibility, segmentation and operational continuity planning.

At least 12 states have reported cyberattacks targeting water and wastewater systems in late July and continuing into August, but the larger story extends far beyond the water sector. For CIOs, CISOs and CSOs, the most important takeaway isn’t that water systems were attacked. It's how they were attacked.

According to the FBI, the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA), attackers gained access to internet-facing operational technology (OT) devices and disrupted physical operations by altering configurations, changing passwords and disabling monitoring capabilities. 

Federal agencies warn that the same tactics could target industrial control systems across manufacturing, energy, transportation and other critical infrastructure sectors. 

For water utilities, the attacks led to operational disruptions and, in some cases, boil-water notices. For manufacturers and infrastructure operators, similar attacks could halt production, damage equipment, create safety risks or disrupt supply chains. 

The CISA also warns that undocumented remote-access pathways, including vendor-installed connections and cellular modems, may be creating exposure that organizations don't fully understand.  

Exposed PLCs gave attackers a path into water systems

According to an FBI and EPA public service announcement, water and wastewater utilities in at least seven states reported cyber incidents, with the number of affected states later reported to have grown to a dozen. In several cases, organizations were forced to switch to manual operations, and some incidents resulted in boil-water notices

Minnesota was among the hardest-hit states, with officials reporting that more than 30 municipal water facilities were targeted between July 26 and 27. Michigan and Rapid City, South Dakota, also reported incidents. State officials said there was no evidence of water contamination and that affected systems continued operating safely. 

Federal officials said the attackers targeted specific industrial control systems used by water utilities, including Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs) from Rockwell Automation. 

The FBI and EPA have not formally attributed the attacks. However, some officials and cybersecurity experts have suggested possible links to Iran based on similarities to previous campaigns and broader geopolitical tensions.

Federal agencies recommend restricting OT access and connectivity

Federal agencies are urging operators to remove critical OT assets from direct internet exposure, strengthen passwords, limit remote access and restrict communications to authorized systems. According to the FBI, attackers changed PLC IP addresses and passwords after gaining access, causing organizations to lose monitoring and operational control of affected devices. 

Also, the decline of traditional air-gapped environments has increased exposure across critical infrastructure sectors, according to a Fortinet solution brief on its OT Security Platform

While none of the reported incidents resulted in water contamination, they have renewed concerns about the cybersecurity of critical infrastructure nationwide. Investigations remain ongoing, and agencies continue to urge organizations with internet-connected industrial systems to review their OT security controls. 

Why OT security is now a business resilience priority

The lesson for technology and security leaders is straightforward: this isn’t just a water-sector problem. It’s a critical infrastructure problem.

Organizations should identify internet-exposed OT assets, review remote-access pathways, strengthen IT/OT segmentation and validate their ability to continue operating when automated systems become unavailable. 

These incidents demonstrate that OT security is increasingly a business resilience issue. Organizations best positioned to withstand future attacks will be those that understand and secure the connections between their digital and physical operations. 

To take a deeper dive into critical infrastructure cyber vulnerability and response tactics, read the story in our sister publication SecurityInfoWatch.com, “Critical Infrastructure Under Siege.”

About the Author

Theresa Houck

Theresa Houck

Contributor

Theresa Houck is an award-winning B2B journalist with more than 35 years of experience covering industrial markets, strategy, policy, and economic trends. As Senior Editor at EndeavorB2B, she writes about IT, OT, AI, manufacturing, industrial automation, cybersecurity, energy, data centers, healthcare, and more. In her previous role, she served for 20 years as Executive Editor of The Journal From Rockwell Automation magazine, leading editorial strategy, content development, and multimedia production including videos, webinars, eBooks, newsletters, and the award-winning podcast “Automation Chat.” She also collaborated with teams on social media strategy, sales initiatives, and new product development.

Before joining EndeavorB2B, she was an Industry Analyst at Wolters Kluwer in its human resources book publishing operation. Before that, she spent 14 years with the Fabricators & Manufacturers Association, Intl., serving as Executive Editor of four magazines in the sheet metal forming and fabricating sector, where she managed and executed editorial strategy, budgets, marketing, book publishing, and circulation operations, and negotiated vendor contracts.

Houck holds a Master of Arts in Communications from the University of Illinois Springfield and a Bachelor of Arts in English from Western Illinois University.

Quiz

mktg-icon Your Competitive Edge, Delivered

Stay ahead of the curve with weekly insights into emerging technologies, cybersecurity, and digital transformation. TechEDGE brings you expert perspectives, real-world applications, and the innovations driving tomorrow’s breakthroughs, so you’re always equipped to lead the next wave of change.

marketing-image