Water Systems in Seven States Hacked
Malicious cyber actors have targeted water and wastewater utilities in at least seven states. The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued warnings that attackers were attempting to disrupt critical water infrastructure.
Shadowy actors targeted water facilities connected to the internet. After gaining remote access, they changed IP addresses and passwords, causing loss of monitoring and control functionality. Reported effects included flooding and drops in water pressure, which can allow untreated water to enter distribution pipes.
Iran & China
U.S. officials have linked the activity to Iranian-affiliated actors, in the wake of U.S. attacks on the Strait of Hormuz. More than 30 municipal water facilities in Minnesota were affected in the initial wave. A Cybersecurity and Infrastructure Security Agency (CISA) advisory, originally issued in April and updated on July 22, documented Iranian-affiliated actors exploiting devices at water facilities across U.S. critical infrastructure since at least March 2026. The activity included theft of project files and manipulation of device logic.
A separate threat comes from Chinese state-sponsored actors. According to federal reports, the group known as Volt Typhoon has been pre-positioned in U.S. critical infrastructure, including drinking-water facilities. Officials deem that these actors seek the capability to disrupt operations during future geopolitical tensions rather than to cause immediate crises.
Documented Vulnerabilities
Weaknesses that allow this exploitation are long-standing. The Cyberspace Solarium Commission noted in 2020 that water utilities remained largely ill-prepared to defend against cyber-enabled disruption.
Water systems remain primarily under local and state jurisdiction. Experts have repeatedly urged operators to remove internet-exposed operational technology from public networks — the single most effective step available — yet many systems continue to rely on such connections.
The recent attacks did not introduce new vulnerabilities. They exploited internet-exposed controllers, weak access controls, and incomplete risk planning that have long been documented.
The question that people should be asking is not only who hacked the water systems, but who decided that protecting them was less important than everything else government has been doing with taxpayer money.
Published with permission off thenewamerican.com