Federal authorities are investigating a coordinated cyberattack against drinking water and wastewater utilities in at least seven states, including an intrusion campaign in Minnesota that reportedly targeted more than 30 community systems within a two-day period.
The Federal Bureau of Investigation and the Environmental Protection Agency confirmed the widening scope of the attacks in a joint public service announcement issued Thursday. The warning indicated that malicious actors had gained access to industrial equipment responsible for controlling essential water and wastewater operations, causing disruptions at some facilities and forcing utility employees to intervene.
The investigation took on greater urgency after a Minnesota law enforcement intelligence memo indicated that the attackers’ stated objective was not limited to disabling equipment or interrupting service. According to information contained in the memo, the campaign was intended to interfere with water treatment operations in a manner that could contaminate public drinking water.
No contamination has been confirmed, and authorities have reported no illnesses connected to the attacks. Officials have also said there is no evidence that unsafe water reached homes, schools, hospitals or businesses in any affected community.
The attacks were directed at operational technology rather than the administrative computer systems commonly targeted in data breaches. Operational technology includes the industrial computers, sensors and remote-control equipment used to operate pumps, regulate pressure, monitor storage tanks, manage wastewater and oversee treatment processes.
At the center of the attacks were programmable logic controllers, specialized computers that automate physical equipment inside utility systems. These controllers can start and stop pumps, open and close valves, regulate treatment equipment and alert workers when operating conditions move outside normal limits.
Because many utilities use remote access to monitor facilities spread across large geographic areas, some control equipment can be reached through internet-connected networks. That access allows employees to respond quickly to mechanical problems, changing water levels and treatment conditions. It can also expose critical equipment when remote connections are protected by weak passwords, outdated software or inadequate network security.
Investigators determined that attackers entered some of those control environments and attempted to manipulate the equipment. Reported activity included changing passwords, altering system configurations and interfering with the ability of utility employees to monitor or control machinery.
Some affected facilities experienced degraded operations and temporary interruptions. Utility workers disconnected compromised devices, isolated portions of their networks and transferred certain processes to manual control while technicians restored access and examined the affected equipment.
Manual operation allowed facilities to continue treating and distributing water without relying entirely on the compromised automated systems. Water plant employees also continued testing water quality and monitoring chemical levels while federal, state and local authorities investigated the intrusions.
The available information has not established that attackers successfully changed chemical treatment levels or introduced a contaminant into any water supply. Public health safeguards remained in place, and abnormal conditions would generally be subject to detection through automated alarms, laboratory testing and direct observation by plant operators.
Water treatment facilities use several stages to protect drinking water, including filtration, disinfection, chemical monitoring and repeated testing before water enters a distribution system. Many facilities also maintain mechanical limits and independent monitoring equipment designed to prevent a single malfunction from creating an immediate public health emergency.
Those protections appear to have prevented the cyber activity from affecting drinking water quality. The reported intent of the attackers, however, has elevated the case beyond a conventional disruption of government computer networks.
The investigation involves the FBI, EPA, Cybersecurity and Infrastructure Security Agency, state intelligence centers, local law enforcement agencies and the operators of affected utilities. Investigators are examining how the attackers entered the systems, whether the same vulnerabilities were used in each state and whether additional utilities were accessed without immediately detecting the intrusion.
Federal authorities have not publicly identified all seven states involved. They also have not formally named a country, organization or hacking group as responsible.
Investigators are reportedly examining whether the activity shares methods or technical characteristics with earlier attacks associated with foreign cyber actors. Iranian-linked groups have previously been accused of targeting industrial equipment used by water utilities, but the current investigation has not produced a formal public attribution.
Determining responsibility for a cyberattack can require extensive analysis of compromised devices, network records, malicious software and communications infrastructure. Attackers frequently conceal their locations, route activity through systems in other countries and reuse publicly available tools to make identification more difficult.
The attacks have exposed continuing security challenges within the American water sector. The United States has thousands of public drinking water systems, ranging from large metropolitan utilities with dedicated cybersecurity departments to small community facilities staffed by only a handful of employees.
Smaller utilities often operate with limited budgets while maintaining aging pipes, pumps, treatment plants and storage facilities. Replacing physical infrastructure can consume much of the available funding, leaving fewer resources for cybersecurity personnel, updated industrial equipment and continuous network monitoring.
Many industrial control systems were also installed when water facilities operated primarily as closed mechanical environments. Remote connectivity was added later to improve efficiency, reduce travel between facilities and allow operators to respond to emergencies from outside a treatment plant.
Federal guidance has urged utilities to remove unnecessary control equipment from direct internet access, replace default passwords, use stronger authentication, install security updates and separate industrial systems from ordinary office networks. Utilities are also being encouraged to preserve manual operating procedures so essential services can continue when digital equipment becomes unavailable.
The attacks demonstrate how a compromise originating through a computer network can reach machinery responsible for providing an essential public service. A successful intrusion into operational technology can affect far more than electronic records. It can change how physical equipment behaves, interrupt treatment processes and place pressure on the employees responsible for keeping water safe and available.
Water service continued in the affected communities, and no drinking water contamination has been verified. The investigation remains active as federal authorities search for additional compromised systems, work to identify those responsible and warn utilities across the country to examine the security of their industrial equipment.
For communities throughout the United States, the case has placed water cybersecurity alongside treatment, testing and infrastructure maintenance as a central part of protecting the public drinking water supply.

