Federal authorities are currently investigating a series of cyberattacks that have disrupted water and wastewater systems across at least seven U.S. states. The incidents, which first gained significant attention after impacting over 30 municipal systems in Minnesota, involve the remote tampering of internet-connected industrial control equipment. While investigators have not yet reached a definitive conclusion regarding the perpetrator, intelligence assessments have identified Iran as the primary suspect, citing a pattern of activity consistent with previous state-linked cyber operations. The attacks have forced several local utilities to revert to manual operations to ensure the safety and continuity of water services.
The technical focus of the investigation centers on programmable logic controllers, or PLCs, which are specialized computers used to manage physical processes like water pressure and chemical treatment. Federal agencies, including the FBI and the Environmental Protection Agency, have issued urgent warnings urging utility operators to disconnect these devices from the public internet and implement stronger security measures, such as multifactor authentication and complex passwords. These steps are intended to prevent unauthorized access that could potentially lead to equipment damage or service interruptions.
Despite the scale of the disruptions, officials have emphasized that there is no evidence that drinking water supplies have been contaminated or rendered unsafe for public consumption. The primary impact has been operational, requiring staff to manage systems manually while security teams work to secure the compromised technology. As the investigation continues, federal agencies are working to determine the full extent of the campaign and whether additional states or facilities have been targeted. The situation remains fluid, with authorities focused on both immediate remediation and long-term hardening of critical infrastructure against future threats.