The FBI indicates that a growing number of water systems in the US have been fending off cyberattacks aimed at disrupting their operations.
The incidents began on Monday and involved water and wastewater utility companies in at least seven US states. “Some of that activity degraded water operations,” the agency said in a Thursday alert with the Environmental Protection Agency.
The alert arrives after Minnesota reported a “coordinated cyberattack” targeting more than 30 community water systems on Sunday into Monday. The FBI’s advisory shows the hacking attempts have been much wider in scope.
The agency warns that hackers have been exploiting programmable logic controllers (PLCs), or specialized computers used to control industrial systems, specifically the MicroLogix 1100 and 1400 series from Rockwell Automation/Allen-Bradley. Hackers are targeting internet-exposed PLCs and then changing device configurations, such as the IP addresses and passwords. This can block a utility provider from monitoring and controlling its water system.
“Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated groundwater to seep into pipes,” the alert adds. In response, the FBI and EPA are urging affected companies to disconnect their PLCs from the public-facing internet, implement firewall rules, and ensure their IT systems are secured with complex, unique passwords.
On Thursday, Minnesota officials said they’re continuing to investigate the breach of its water systems, which also involved hackers tampering with PLCs and computer screen operators. “State agencies are working directly with impacted water systems to contain the activity, assess potential impacts, restore normal operations, and reduce the risk of further disruption.”
Recommended by Our Editors
US officials reportedly suspect that Iran was behind the attack in Minnesota, but for now, the state says it “has not attributed the activity to a specific actor.” In April, the FBI and NSA warned that Iranian hackers were working to exploit vulnerable PLCs from Rockwell Automation.
The water system intrusions occur amid renewed military strikes between the US and Iran. Other hacks earlier this year, including an intrusion into the personal Gmail account of FBI Director Kash Patel, have also been blamed on Iran.
About Our Expert
Michael Kan
Principal Reporter
Experience
I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.
Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.
Click Here For The Original Source.
