The FBI has issued an urgent warning after cyberattacks struck drinking water and wastewater utilities across at least seven U.S. states, disrupting operations and prompting boil-water advisories in some communities. According to a Public Service Announcement released on July 30, 2026, the attacks began on July 27 and have already degraded water operations, raising alarms about the vulnerability of America's critical infrastructure.
Scope and Impact of the Attacks
The FBI did not disclose which states were affected, but confirmed that the incidents involved unauthorized access to internet-facing programmable logic controllers (PLCs) and other operational technology (OT) devices. In several cases, the intrusions were severe enough to trigger boil-water advisories, meaning residents were urged to boil tap water before drinking or cooking. Critical infrastructure cybersecurity has become a top national security concern as threat actors increasingly target utilities.
NBC News reported that on the same day the FBI warning went public, Minnesota alone suffered cyberattacks on more than 30 municipal water systems. Anonymous officials told the network the attacks bore "the fingerprints of Iranian involvement", pointing to a sophisticated and coordinated campaign.
Iranian Connection and Political Fallout
The FBI had already warned a week earlier that Iran-backed hacking groups were actively probing U.S. critical infrastructure, including water and wastewater systems. A joint advisory from the FBI, CISA, EPA, and other agencies linked the activity to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC), particularly the CyberAv3ngers/Shahid Kaveh group. These actors have been exploiting PLCs from manufacturers like Rockwell Automation, Schneider Electric, and Siemens to manipulate operational displays and disrupt processes.
President Trump, however, publicly dismissed the intelligence, denying Iranian involvement and instead blaming Minnesota Governor Tim Walz, a prominent Democrat. This split between the White House and federal security agencies deepened concerns about the government's ability to mount a unified response. Iran cyber threat to US infrastructure has been a recurring theme in intelligence assessments, but the lack of political cohesion could hamper mitigation efforts.
How the Attackers Operated
The cyber actors targeted PLCs connected directly to the public internet without proper authentication. Once inside, they:
- Downloaded and replaced legitimate project files with malicious versions
- Manipulated human-machine interface (HMI) and SCADA displays to show false readings
- Caused pumps, valves, and chemical dosing systems to behave erratically
- Triggered alarms and emergency shutdowns, overwhelming plant operators
These techniques, detailed in a CISA advisory (AA26-097A), highlight how insecure remote access can allow nation-state adversaries to inflict physical damage without stepping foot inside a facility.
Government and Industry Response
The FBI urged all water and wastewater utilities to immediately disconnect any internet-exposed OT equipment, including PLCs, HMIs, and SCADA systems, and to implement multifactor authentication and network segmentation. The Environmental Protection Agency (EPA) has also begun coordinating with state regulators to assess compliance with cybersecurity best practices.
Industry groups like the Water Information Sharing and Analysis Center (WaterISAC) have issued alerts and are sharing indicators of compromise (IOCs) to help operators detect intrusions. Several affected utilities have hired incident response and forensics teams to investigate the full scope of the compromise.
FAQ: What You Need to Know
Which states were hit by the water cyberattacks?
The FBI has not publicly named the seven states, but NBC confirmed Minnesota was one of them. Other states likely include those with smaller, rural water systems that often lack robust cybersecurity.
Is my tap water safe to drink?
If you live in an affected area, follow any official boil-water advisories. The attacks primarily disrupted operational controls, but in some cases may have affected water quality. Always check local water utility announcements.
Who is behind the attacks?
U.S. intelligence points to Iran-affiliated groups, specifically the IRGC-CEC's CyberAv3ngers, though the White House has disputed this. Investigations are ongoing.
What should water utilities do to protect themselves?
The FBI and CISA recommend disconnecting internet-facing PLCs, using VPNs with MFA, monitoring OT network ports (44818, 2222, 102, 502), and applying patches. Free resources are available at CISA's Stop Ransomware site.
Has this happened before?
Yes. In 2021, a hacker attempted to poison a Florida water treatment plant by altering chemical levels. Since then, attacks on water systems have escalated, with Iranian actors increasingly targeting OT assets.
Follow Discussion