2 min read

Hackers disrupt seven US water utilities

The FBI and EPA warn that hackers have disrupted seven US water utilities since July 27, with flooding and pressure loss reported.

Image: Engadget

Seven water and wastewater utilities across the US have been hit by cyberattacks since July 27, 2026, degrading their ability to operate critical systems, according to a public service announcement from the FBI and the Environmental Protection Agency (EPA). Victims told the FBI that the incidents caused flooding and loss of water pressure.

How the attacks disrupt water operations

The attackers are focusing on Programmable Logic Controllers (PLCs), devices that help utilities monitor and control physical systems. According to the FBI, the hackers remotely accessed internet-facing PLCs and changed their IP addresses and passwords, blocking utility staff from managing or monitoring operations.

The agency and EPA recommend that utilities:

  • Use secure gateways and firewalls to prevent direct internet exposure.
  • Set stronger passwords.
  • Configure access control lists so only authorized communications can pass between system devices.

The reported effects extend beyond temporary loss of control. The FBI said some facilities experienced flooding and pressure loss. In a warning to utilities, it said reduced pressure could allow untreated groundwater to seep into pipes, creating a broader operational impact than low water pressure alone.

Recommended reading

Arch Linux suspends AUR adoption after malware surge

The federal warning follows the infiltration of more than 30 municipal water facilities in Minnesota over the past week. NBC News reported that the incidents showed hallmarks of Iranian involvement, but law enforcement has not confirmed whether Iran was responsible.

Wired reported seeing a memo sent to members of the Water Information Sharing and Analysis Center (WaterISAC), an industry group for water utilities. The memo reportedly said the Minnesota Fusion Center, a state-level intelligence-sharing organization, warned that the activity matched a campaign previously described by the Cybersecurity and Infrastructure Security Agency (CISA).

“ongoing malicious cyber activity impacting public drinking water systems across Minnesota”

WaterISAC memo, as reported by Wired

CISA warned in April that Iran-affiliated hackers were targeting water infrastructure and other entities. The agency has not publicly established that the Minnesota incidents or the seven attacks across the US were carried out by the same actors.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Engadget

/ Keep reading