Federal agency warns of growing cyber threat to water systems

Published July 31, 2026 5:42 PM EDT

FILE-Pedestrians walk past the Brooklyn Center water tower on April 14, 2021 in Brooklyn Center, Minnesota. (Photo by Joshua Lott/The Washington Post via Getty Images)

The Cybersecurity and ​Infrastructure Security Agency (CISA) sent an alert of a substantial rise in hackers targeting technology used to maintain and control water and wastewater systems.

CISA officials noted that it is observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector.

Hackers in some instances changed passwords to lock out operators and disconnect some devices from the networks, the federal agency added. 

RELATED: Israeli researchers say Iran behind Los Angeles transit system attack

Reuters reported that the warning from the cybersecurity agency comes a few days after Minnesota’s state agency announced over 30 community water systems in the state were targeted in a "coordinated cyberattack."

FBI officials released a statement on Thursday indicating that water and wastewater utility organizations in about seven states reported incidents to the federal agency, and that affected water operations. 

Cyber threats to water systems

Dig deeper:

U.S. officials and authorities probing the threat to water systems tell Reuters that it may be Iranian-connected hackers who are responsible for the Minnesota attacks, Reuters noted, citing a New York Times report. 

According to Reuters, Iranian-linked hacking activity targeting U.S. water facilities predates the ongoing war between the U.S. and Iran. However, several groups have executed a few cyberattacks on domestic U.S. organizations, including medical services company Stryker and the Los Angeles County Metropolitan Transportation Authority back in March.

State and local officials assert that the Minnesota attacks ​did not threaten water safety, but in some instances, certain systems were taken offline and were reset manually. 

Reuters spoke to Cynthia Kaiser, a former senior FBI cybersecurity official, who informed that news outlet that it is possible that the Minnesota hacking incidents were a continuation of prior Iranian-affiliated targeting of PLCs and other critical ​infrastructure technology noted ⁠by Cybersecurity and ​Infrastructure Security Agency (CISA), the FBI, the National Security Agency (NSA and other federal agencies in an April advisory.

The Source: Information for this story was provided by the Cybersecurity and ​Infrastructure Security Agency and Reuters, which received comments from a former FBI cybersecurity official, and a statement from the FBI. This story was reported from Washington, D.C.


 

Crime and Public SafetyU.S.U.S.