Malicious cyber activity targeted internet-connected water controls in at least seven U.S. states, with some incidents degrading operations after intruders changed IP addresses and passwords, the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) disclosed in a July 30 alert.
Scope of the attacks and affected hardware
The FBI said utilities in at least seven states had reported incidents since July 27. Minnesota separately said its systems were targeted on July 26 and 27. The attacks targeted operational technology (OT) used to monitor and control physical equipment.
The affected devices included Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs) made by Rockwell Automation, an industrial automation vendor.
Physical impacts and state-level responses
Some operators lost the ability to monitor or control connected equipment. The FBI said reported operational effects included pressure loss and flooding. At least one organization reported modified PLC project files after noticing ladder-logic discrepancies across several sites.
The impact at each site depended partly on what the controller operated and whether personnel could switch to manual controls.
Minnesota IT Services (MNIT), the state’s central IT agency, reported that more than 30 community water systems were targeted July 26 and 27. State officials were not aware of any active requests for residents to change their drinking-water use as responders assessed the affected systems.
Questions remain over attribution and previous campaigns
The federal alert did not identify an attacker. CBS News reported that investigators were examining possible Iranian involvement and whether the actor had attempted to appear Iran-based, citing U.S. officials and sources familiar with the incident. The sources cautioned that attribution could change as investigators collected more technical evidence.
The investigation follows an April federal advisory attributing a separate campaign against internet-facing industrial controls to Iranian-affiliated actors. Six agencies said the activity had disrupted Rockwell controllers across government, water and energy organizations since at least March.
The advisory also cited similar earlier activity by CyberAv3ngers, an Iran-affiliated group that compromised at least 75 U.S.-based Unitronics devices in a campaign that began in November 2023.
The July alert does not connect the latest incidents to the earlier campaign. It pointed instead to a potentially repeatable exposure: similarities in network setups supplied by third parties may give attackers an opportunity to repeat successful access across multiple customers. Because PLCs monitor or control connected equipment, losing digital access can require operators to run facilities manually.
Manual operation and secure recovery
The FBI and EPA recommended that utilities remove controllers from direct internet exposure, restrict communications through firewalls and access-control lists and compare running project files with known-good copies. The alert also recommends that operators “practice and maintain the ability to operate OT systems manually,” test continuity plans and check that restored backups do not contain malicious logic.
Mickey Bresman, CEO of identity-security company Semperis, said utilities should prepare for the possibility that an attacker already has access rather than treating a compromise as a remote scenario.
“Responses to constant cyber threats will be more effective if water utilities and other critical infrastructure providers operate under the assumption that adversaries are already inside their networks and if they have a tested crisis response plan ready to activate,” Bresman told TechInformed.
Bresman said operators should prioritize the infrastructure components most essential to recovery, test response procedures using realistic scenarios and plan how to disconnect network access during an incident.
“Focus not just on fast recovery, but on secure recovery. Making sure that the bad actors are not in the restored environment is paramount.”
Regulatory hurdles and federal workforce shortages
Cybersecurity review during public water system sanitary surveys remains voluntary at the federal level. The EPA withdrew a 2023 interpretation that would have required states to evaluate the cybersecurity of operational technology during sanitary surveys or through an equivalent process after the Eighth Circuit stayed the memorandum during litigation.
The incidents also arrive amid congressional scrutiny of the Cybersecurity and Infrastructure Security Agency (CISA), the national coordinator for critical infrastructure security and resilience. A June 16 release from Sen. Mark Warner’s office said CISA had lost nearly one-third of its workforce since January 2025. In the accompanying letter, Warner said five of the agency’s 10 regional directors were serving in acting roles and that states and industry had reported disruptions to service delivery. His letter predates the water attacks and does not assess CISA’s response to them.