News From Multiple Perspectives

FBI investigates cyberattacks on US water systems

Published August 2, 2026 at 6:02 AM UTC

Authored by
Every article published on DirectionFreeNews undergoes editorial review by our editorial team. Our editors research publicly available information from multiple trusted news organizations, compare differing perspectives, verify key facts, and publish balanced summaries intended to help readers better understand important events. Our editorial process is designed to reduce editorial bias by considering multiple reputable sources rather than relying on a single viewpoint

The FBI and the Environmental Protection Agency are investigating a series of cyberattacks targeting public drinking water and wastewater systems across at least seven U.S. states. The incidents, which began around July 27, 2026, involve hackers remotely accessing operational technology to disrupt monitoring and control functions. In Minnesota alone, more than 30 community water systems were affected, and Michigan has also reported impacts on nine of its facilities. While some operations experienced degradation, including reports of pressure loss, officials in both states have confirmed that all systems are currently operating safely and there is no immediate public health concern.

The attacks specifically target internet-facing programmable logic controllers, which are industrial computers used to manage equipment like pumps and valves. By exploiting these devices, attackers have been able to change IP addresses and set new passwords, effectively locking out local operators. Federal authorities have issued a public service announcement urging utility providers to disconnect these controllers from the public internet, implement stronger authentication, and maintain the capability to operate systems manually if digital controls are compromised.

While investigators are currently probing potential links to Iranian hackers, no definitive attribution has been made. Officials are also considering the possibility that the attackers may be attempting to mimic Iranian tactics to sow confusion. The situation remains fluid as federal agencies continue to collect technical evidence from the affected sites. For now, the primary focus for local operators is ensuring that all systems are secured and that manual overrides are ready to prevent any future service disruptions.