Cyberattacks Push US Water Utilities Into a Wider Security Test

Cyberattacks on water utilities have now reached no fewer than seven states, after more than 30 Minnesota water and wastewater utilities were hit. The FBI and CISA are urging utilities to secure programmable logic controllers and limit who can connect to them.

WTF Index TERMINATOR
◄ Terminator 3 Idiocracy 0 ►

Cyberattacks on water control systems show digital tools being used to disrupt critical physical infrastructure.

Cyberattacks Push US Water Utilities Into a Wider Security Test

A hacking campaign against US water utilities has widened beyond Minnesota, with the FBI warning that utilities in no fewer than seven states have now been affected. The attacks have drawn attention because they target systems that connect software to physical equipment, a sensitive point in critical infrastructure.

The leading suspect remains Iranian-affiliated hackers. The warning follows earlier reporting that more than 30 water and wastewater utilities across Minnesota were hit in the last week.

What Happened

The campaign first drew broad notice after more than 30 water utilities across Minnesota were hit with cyberattacks. According to the source article, that already appeared to be perhaps the broadest and most disruptive hacking campaign to target American industrial control systems.

The FBI has now warned that the activity extends to no fewer than seven states. The bureau did not identify the targeted states, and it did not give a detailed public account of the disruption or damage caused by the attacks.

The FBI said it is working with the Environmental Protection Agency and affected utilities. CISA also issued its own advisory this week, saying the attacks had in some cases disabled digital controls and “resulted in boil-water notices.” That phrasing points to the practical stakes: when digital controls fail or are compromised, public water operations may have to take precautions that directly affect households and businesses.

Why Industrial Control Systems Matter

The attacks are significant because they involve industrial control systems. These are the technologies that link digital software to physical equipment, often in critical infrastructure settings.

In a water or wastewater utility, that kind of connection is not an abstract IT concern. Digital systems can help operate or monitor equipment that supports real-world service. When those systems are exposed, poorly secured, or reachable by unauthorized devices, the consequences can move beyond data loss and into operational disruption.

The source article does not provide a full technical breakdown of how each utility was affected. It does, however, identify programmable logic controllers as a key concern. These devices connect to physical equipment, and the FBI warned utilities to act immediately to reduce their exposure.

The Security Steps Officials Are Urging

The FBI’s guidance, echoing CISA’s advisory, is direct. Utilities should move quickly to reduce access to the digital devices that connect with physical equipment.

The recommended steps include:

  • Remove programmable logic controllers from direct exposure to the internet.
  • Protect those devices with strong passwords.
  • Set up allow-lists so only authorized devices can connect.

Those measures are basic, but in this context they are not minor. A utility does not need to publish every detail of its systems for exposed equipment to become a risk. If a device that helps bridge software and machinery can be reached too easily, it can become a point of leverage for attackers.

The advice also shows how much of critical infrastructure security depends on reducing unnecessary access. Strong passwords matter, but so does limiting the number of paths into the equipment in the first place. Allow-lists add another layer by narrowing connections to devices that have already been approved.

Attribution and the Political Response

The leading suspect behind the attacks remains Iranian-affiliated hackers. The source article says this was first laid out in a CISA advisory in April, and that a leaked memo obtained by WIRED connected that assessment to the more recent Minnesota utility attacks as well.

President Donald Trump on Friday instead blamed Minnesota Democratic governor Tim Walz’s administration for the attacks. The source article describes that as a partisan response and compares it to his denial of Russia’s hacking of the Democratic National Committee in 2016, even after US intelligence agencies had attributed that intrusion to the Kremlin.

For utilities, the immediate issue is less political than operational. The public guidance centers on securing programmable logic controllers, limiting exposure, and working with federal agencies where systems have been affected.

What This Signals for Public Infrastructure

The spread from Minnesota to no fewer than seven states changes the scale of the problem. It suggests that the campaign is not limited to one local cluster of utilities, even though the FBI has not publicly named the additional states or described the full extent of the harm.

Water systems are not just another category of digital target. They provide essential public services, and even limited disruption can force precautionary responses. The reported boil-water notices show how cybersecurity incidents can quickly become public-service incidents.

The source article does not say how long the campaign will continue, which utilities remain at risk, or whether every affected system experienced the same level of disruption. What it does make clear is that federal agencies are treating the exposure of control equipment as urgent.

For water and wastewater operators, the lesson is practical: internet-facing control devices create risk, especially when they are tied to physical systems. The immediate priority is to restrict access, strengthen authentication, and make sure only authorized devices can reach the equipment that keeps essential services running.