At least 12 states have reported cyberattacks targeting water and wastewater systems in late July and continuing into August, but the larger story extends far beyond the water sector. For CIOs, CISOs and CSOs, the most important takeaway isn’t that water systems were attacked. It's how they were attacked.
According to the FBI, the Environmental Protection Agency (EPA) and the Cybersecurity and Infrastructure Security Agency (CISA), attackers gained access to internet-facing operational technology (OT) devices and disrupted physical operations by altering configurations, changing passwords and disabling monitoring capabilities.
Federal agencies warn that the same tactics could target industrial control systems across manufacturing, energy, transportation and other critical infrastructure sectors.
For water utilities, the attacks led to operational disruptions and, in some cases, boil-water notices. For manufacturers and infrastructure operators, similar attacks could halt production, damage equipment, create safety risks or disrupt supply chains.
The CISA also warns that undocumented remote-access pathways, including vendor-installed connections and cellular modems, may be creating exposure that organizations don't fully understand.
Exposed PLCs gave attackers a path into water systems
According to an FBI and EPA public service announcement, water and wastewater utilities in at least seven states reported cyber incidents, with the number of affected states later reported to have grown to a dozen. In several cases, organizations were forced to switch to manual operations, and some incidents resulted in boil-water notices.
Minnesota was among the hardest-hit states, with officials reporting that more than 30 municipal water facilities were targeted between July 26 and 27. Michigan and Rapid City, South Dakota, also reported incidents. State officials said there was no evidence of water contamination and that affected systems continued operating safely.
Federal officials said the attackers targeted specific industrial control systems used by water utilities, including Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs) from Rockwell Automation.
The FBI and EPA have not formally attributed the attacks. However, some officials and cybersecurity experts have suggested possible links to Iran based on similarities to previous campaigns and broader geopolitical tensions.
Federal agencies recommend restricting OT access and connectivity
Federal agencies are urging operators to remove critical OT assets from direct internet exposure, strengthen passwords, limit remote access and restrict communications to authorized systems. According to the FBI, attackers changed PLC IP addresses and passwords after gaining access, causing organizations to lose monitoring and operational control of affected devices.
Also, the decline of traditional air-gapped environments has increased exposure across critical infrastructure sectors, according to a Fortinet solution brief on its OT Security Platform.
While none of the reported incidents resulted in water contamination, they have renewed concerns about the cybersecurity of critical infrastructure nationwide. Investigations remain ongoing, and agencies continue to urge organizations with internet-connected industrial systems to review their OT security controls.
Why OT security is now a business resilience priority
The lesson for technology and security leaders is straightforward: this isn’t just a water-sector problem. It’s a critical infrastructure problem.
Organizations should identify internet-exposed OT assets, review remote-access pathways, strengthen IT/OT segmentation and validate their ability to continue operating when automated systems become unavailable.
These incidents demonstrate that OT security is increasingly a business resilience issue. Organizations best positioned to withstand future attacks will be those that understand and secure the connections between their digital and physical operations.
To take a deeper dive into critical infrastructure cyber vulnerability and response tactics, read the story in our sister publication SecurityInfoWatch.com, “Critical Infrastructure Under Siege.”