News From Multiple Perspectives

Water system cyberattacks reported across multiple US states

Published August 3, 2026 at 6:02 AM UTC

Authored by
Every article published on DirectionFreeNews undergoes editorial review by our editorial team. Our editors research publicly available information from multiple trusted news organizations, compare differing perspectives, verify key facts, and publish balanced summaries intended to help readers better understand important events. Our editorial process is designed to reduce editorial bias by considering multiple reputable sources rather than relying on a single viewpoint

Federal authorities are investigating a series of cyberattacks that have targeted water and wastewater systems in at least seven states. The incidents, which began around July 27, 2026, have forced some municipal facilities to switch to manual operations after hackers gained remote access to critical control technology. While officials have not reported any contamination of water supplies, the disruptions have caused issues such as loss of water pressure and localized flooding in some areas.

The attacks primarily target internet-connected devices known as programmable logic controllers, or PLCs. These devices are essential for automating and monitoring functions like pumps and water treatment processes. According to a joint alert from the FBI and the Environmental Protection Agency, attackers have been exploiting these systems by changing IP addresses and administrator passwords, effectively locking local operators out of their own networks.

Minnesota was among the first to report widespread issues, with state officials confirming that over 30 municipal water facilities were targeted. Since then, reports have emerged from other states, including Michigan and Georgia. The FBI and EPA are urging water utilities nationwide to immediately disconnect any internet-exposed control systems and implement stronger security measures, such as unique passwords and secure firewalls.

Investigators are currently working to identify the perpetrators behind this campaign. While some reports have suggested potential links to Iranian hackers—citing similarities to previous attacks on U.S. infrastructure—authorities have not yet made a formal attribution. Officials are also exploring the possibility that the attackers may be intentionally mimicking foreign actors to sow confusion or exploit existing geopolitical tensions.

For the general public, the primary impact has been operational, with some utilities forced to revert to manual control to ensure safety. Experts emphasize that the water sector remains a high-priority target due to its critical role in daily life and the historical vulnerability of its aging or internet-exposed infrastructure. As the investigation continues, the focus remains on securing these systems to prevent further disruptions and ensuring the continued safety of public water supplies.