WASHINGTON — Malicious hackers have targeted the operational technology of water and wastewater utilities in at least seven U.S. states, disrupting monitoring and control systems and forcing some operators to fall back on manual procedures, federal investigators said. The FBI and Environmental Protection Agency reported that some incidents degraded water operations, including cases involving pressure loss and flooding.
The campaign, underway since July 27, focused on internet-exposed programmable logic controllers, or PLCs, used to monitor and operate pumps, valves and other equipment. In a July 30 public warning, the FBI said attackers remotely changed device addresses and passwords. That cut operators off from equipment displays and, in some cases, from the equipment itself.
Authorities have not publicly identified the attacker. Officials are examining whether Iranian hackers were involved, but investigators have also considered the possibility that someone tried to make the activity appear Iran-based. That means attribution remains an open investigative question, not an established fact. Previous warnings about Iran-affiliated groups targeting American infrastructure provide context, but they do not prove responsibility for this campaign.
Minnesota reported attacks affecting more than 30 community water systems. Michigan later said nine systems experienced activity consistent with the federal alert, while stressing that operators resolved the issues and that no known public-health danger resulted. The Associated Press reported that all affected Michigan systems continued operating safely.
Local incidents show why the technical details matter. In Braham, Minnesota, attackers shut down controls for a well and treatment plant, temporarily leaving the city dependent on water stored in its tower. In Plymouth, communications with water towers and sewer lift stations were interrupted before operators restored them. Officials said drinking-water quality was not compromised, and several utilities maintained service by shifting to manual control.
A national-security problem at municipal scale
The attack surface is not a futuristic military network. It is thousands of small public utilities, many with limited staff, aging equipment and remote connections installed by vendors over many years. A single exposed controller can become a door into a physical process. Changing a password on a website is inconvenient; changing the configuration of a pump controller can affect pressure, storage and the safe movement of water.
That asymmetry is attractive to hostile states and criminals. An attacker does not have to poison a reservoir to create fear or impose costs. Disabling visibility, forcing crews to travel to remote sites and making communities question whether their taps are safe can produce disruption far beyond the technical damage. The campaign therefore belongs in the same national-resilience conversation as power grids, hospitals, ports and communications networks.
The federal warning offers a practical diagnosis. Utilities should remove industrial controllers from direct public-internet exposure, mediate remote access through secure gateways, replace default or weak passwords, restrict which devices can communicate and preserve a tested ability to operate manually. Those steps are basic, but basic security is often where decentralised infrastructure is weakest. The FBI also warned that similar configurations supplied by the same third parties may allow attackers to repeat one successful technique across multiple customers.
Resilience requires more than an alert
America’s local ownership of water systems is a strength when it keeps decisions close to communities, but it can become a vulnerability when small operators are left to defend industrial networks against nation-state-level threats. Federal agencies can publish indicators and advice; Congress and state governments must ensure utilities have the money, expertise and procurement standards to act on them.
Public officials also owe residents disciplined communication. Prematurely blaming a foreign government may inflame a conflict and contaminate an investigation. Minimising the incidents because water remained safe would be equally irresponsible. CBS News reported that authorities were still collecting technical evidence even as the scope widened.
The most reassuring fact is that local operators caught problems, isolated equipment and kept water flowing. The most troubling is that attackers could reach physical controls in the first place. Manual backups prevented a cyber incident from becoming a public-health emergency this time. A serious national response should make sure communities are not depending on luck the next time.

Comments
Loading comments…