Authorities are examining a wave of cyber intrusions targeting water and wastewater facilities across multiple US states, prompting renewed focus on critical infrastructure security, industrial control system vulnerabilities and coordinated cyber threat preparedness.
US federal and state authorities are investigating a coordinated series of cyberattacks that targeted water and wastewater infrastructure across several states, raising fresh concerns about the cybersecurity of critical public utilities. While investigators are exploring possible links to Iran-affiliated threat actors, officials have stressed that no formal attribution has been made and the investigation remains ongoing.
The attacks affected dozens of community water systems, disrupting automated operational technology and forcing several utilities to temporarily switch to manual controls. Despite the operational impact, authorities have confirmed there is no evidence that drinking water quality has been compromised or that public water supplies have been interrupted.
The first incidents were reported in Minnesota, where more than 30 community water systems experienced unauthorised access attempts over a two-day period in late July. State officials described the activity as a coordinated cyber campaign targeting essential infrastructure, while noting that forensic investigations are still underway.
According to officials, the timing, attack patterns and targeted systems resemble tactics observed in previous cyber operations directed at critical infrastructure, though investigators have not publicly identified those responsible.
Industrial control systems become primary target
Authorities believe the attackers focused on internet-connected programmable logic controllers (PLCs), which are widely used to automate operations at water treatment plants, pumping stations and wastewater facilities. These devices regulate critical functions such as water pressure, chemical treatment, pumps and other operational processes.
Investigators said the attackers exploited internet-facing PLCs that lacked adequate cybersecurity protections rather than using highly sophisticated techniques. Internal assessments suggest the objective may have been to interfere with system pressure and potentially create conditions that could increase operational risks if left unchecked.
Officials warned that poorly secured industrial control systems remain attractive targets for cybercriminals and state-sponsored groups because they often operate with outdated configurations or insufficient network protection.
Several affected communities were able to maintain uninterrupted water and wastewater services by quickly shifting to manual operations. Utilities in cities including South St. Paul, Braham and Plymouth restored normal functioning after isolating compromised systems, preventing any disruption to residents.
Critical infrastructure security under greater scrutiny
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA) and state authorities are jointly coordinating the response, assisting affected utilities while assessing the broader scope of the campaign.
Although federal investigators are examining whether the attacks share characteristics with previous operations linked to Iranian cyber groups, officials cautioned that cyber adversaries often imitate known tactics to obscure their identities and complicate attribution.
Earlier advisories from CISA had warned that Iran-linked hackers were targeting internet-exposed industrial controllers manufactured by major automation vendors, highlighting vulnerabilities in operational technology environments. However, authorities emphasised that no confirmed evidence currently connects the latest incidents to Iran.
Cybersecurity experts say the coordinated nature of the attacks highlights growing risks facing water infrastructure as utilities increasingly rely on connected operational technologies. Industry specialists have urged operators to disconnect internet-exposed industrial devices wherever possible, strengthen authentication controls, implement continuous monitoring and improve incident response capabilities.
The latest incidents have renewed calls for stronger cybersecurity safeguards across critical infrastructure sectors, with experts warning that even relatively simple attacks can disrupt essential public services when operational technology lacks basic security protections. As investigations continue, federal agencies are encouraging utilities nationwide to review their cyber defences to reduce exposure to similar threats in the future.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




