Cyberattack
Details
Event title
United States - Cyberattacks Hit Water Systems in at Least 12 US States, With Minnesota Among Hardest Hit Authored by: Samannay Biswas Updated A
Source
Severity
Mid
Event date (UTC)
2026-08-06 06:55:29
Last update (UTC)
2026-08-06 06:55:29
Area range
Multiple cities / districts wide event
Address/Affected area(s)
Minnesota
A coordinated wave of cyberattacks targeting municipal water and wastewater systems has spread across at least 12 US states, with Minnesota emerging as one of the hardest-hit, where hackers targeted more than 30 water systems. The incidents are being described as one of the broadest known cyber campaigns against America's critical water infrastructure, raising fresh concerns over the security of essential public utilities.
According to ABC News, hackers targeted water and wastewater utilities across multiple states, prompting investigations by federal agencies and local authorities. The attacks follow an earlier warning from the Federal Bureau of Investigation (FBI), which said at least seven states had reported cyber intrusions targeting systems that control water pumps, pressure levels and valves at treatment plants.
Water Operations Disrupted
Federal officials said several of the cyberattacks disrupted normal operations at water treatment facilities, leading to pressure losses, flooding and temporary operational failures.
The Cybersecurity and Infrastructure Security Agency (CISA) said some affected utilities were forced to switch to manual operations after digital control systems were compromised. Several communities also issued precautionary boil-water advisories because of reduced water pressure.
Despite the operational disruptions, officials stressed that drinking water remains safe, and there is no evidence that water quality has been compromised.
Minnesota Among Hardest Hit
Minnesota has emerged as one of the worst-affected states, with hackers reportedly targeting more than 30 municipal water systems in a coordinated campaign.
State and local authorities are working alongside federal cybersecurity agencies to restore normal operations, strengthen network security and investigate the attacks.
Iran Suspected, Investigation Ongoing
Several media reports have suggested investigators suspect Iranian-linked hackers may be behind the widespread attacks, although US officials have not formally attributed responsibility.
President Donald Trump last week dismissed reports pointing to Iran, saying he did not believe the cyberattacks were carried out by Tehran.
Federal agencies continue to investigate the origin, scope and methods used in the campaign.
Internet-Connected Systems Exploited
The FBI said many of the targeted industrial control systems were never intended to be connected to the internet, but had been left accessible online.
Hackers allegedly exploited those internet-facing devices to gain access, change passwords and lock utility operators out of systems used to monitor and control water infrastructure.
Cybersecurity experts have long warned that exposed industrial control systems represent an attractive target for cybercriminals and state-backed hacking groups because they often protect essential public services.
Longstanding Security Concerns
The attacks have intensified longstanding concerns over the cybersecurity of America's water infrastructure.
Unlike the electricity sector and many other critical infrastructure industries, most US water utilities are operated by local governments, many of which have limited budgets, outdated technology and small cybersecurity teams.
As a result, investments in digital security often compete with funding for schools, roads, emergency services and other local priorities.
Experts have repeatedly warned that aging infrastructure, insufficient cybersecurity personnel and outdated software leave many utilities vulnerable to increasingly sophisticated cyber threats.
Volunteer Experts Helping Utilities
To address these vulnerabilities, volunteer cybersecurity specialists have spent the past two years working with local water utilities to strengthen digital defences.
Their efforts include identifying internet-exposed systems, improving password protections, securing industrial control equipment and enhancing monitoring capabilities to detect cyber intrusions before they disrupt operations.
Critical Infrastructure Under Growing Threat
The latest incidents underscore growing concerns that cybercriminals and foreign adversaries are increasingly targeting essential infrastructure beyond government agencies and private companies.
Federal authorities continue to urge water utilities nationwide to disconnect unnecessary internet-facing industrial systems, strengthen cybersecurity protections and implement additional safeguards to reduce the risk of future attacks.
The coordinated attacks serve as another warning that safeguarding critical public infrastructure has become an increasingly urgent national security priority as cyber threats continue to evolve.