technology & security••5 min read

Water Utilities Nationwide on Alert Following Coordinated Cyberattacks

Federal authorities are investigating a series of malicious cyber incidents targeting water and wastewater facilities across the United States. The attacks have disrupted critical operations, forcing some utilities to switch to manual systems to maintain public safety.

Water Utilities Nationwide on Alert Following Coordinated Cyberattacks

A Coordinated Strike on Public Infrastructure

A wave of cyberattacks has rattled water and wastewater facilities across the United States, prompting an urgent investigation by the FBI and the Environmental Protection Agency (EPA). The incidents, which have affected utilities in at least seven states—including significant activity reported in Minnesota and Michigan—have raised alarms about the vulnerability of the nation's most critical public services.

The attacks have forced multiple municipal utilities to pivot to manual operations to ensure the continued safety and distribution of water. While authorities are currently working to identify the actors responsible, the coordination and timing of these breaches suggest a deliberate attempt to probe the security of essential infrastructure.

Federal agencies are currently investigating the scope of cyber incidents impacting water infrastructure nationwide.
Federal agencies are currently investigating the scope of cyber incidents impacting water infrastructure nationwide.

How the Attacks Target Water Systems

According to alerts issued by federal agencies, the attackers are specifically targeting internet-facing Programmable Logic Controllers (PLCs). These are the digital brains of many water facilities, responsible for everything from monitoring chemical levels to controlling the physical flow of water.

  • Loss of water pressure: These cyber incidents have resulted in pressure drops that could allow untreated groundwater to contaminate the supply.
  • Operational disruption: Attackers have successfully disrupted the software used to manage monitoring and control equipment.
  • Forced manual intervention: Many utilities were required to switch to manual, non-digital operations to prevent further sabotage.
  • Potential for contamination: Authorities warn that a successful breach could potentially introduce contaminants into drinking water systems.

Cyberattacks on drinking water and wastewater systems directly threaten public health and community resilience. A single breach can disrupt treatment or introduce contaminants, damage equipment, and erode public trust.

— Jeffrey A. Hall, EPA Assistant Administrator for Enforcement and Compliance Assurance

Looking Ahead: Securing Our Water Supply

The EPA, FBI, CISA, and NSA have issued a joint advisory to help water systems identify specific vulnerabilities. This includes a push for better cyber resilience and securing internet-facing assets that have become prime targets for hostile groups. While the investigation into whether a single actor—or potential state-sponsored groups—is behind the coordinated effort continues, the event serves as a stark reminder of the fragile interface between modern technology and essential public resources.

Key Takeaways

  • Over 30 community water systems in Minnesota and several other states have reported cyber incidents.
  • The primary vector of attack involves internet-facing Programmable Logic Controllers (PLCs).
  • Operational impacts include loss of water pressure, which risks groundwater contamination.
  • Federal agencies, including the FBI and EPA, are leading the investigation and response efforts.
  • Many facilities have shifted to manual operations as a defensive, protective measure.

FAQ

Is my local water safe to drink?

Utilities affected by these attacks have generally shifted to manual operations to maintain the integrity of the water supply. Residents should follow guidance from their local water provider regarding any specific service alerts.

What specifically are the hackers targeting?

Hackers are targeting internet-facing Programmable Logic Controllers (PLCs), which are digital devices that monitor and control industrial equipment like water pumps and treatment sensors.

Are these attacks state-sponsored?

The FBI is currently investigating the source of the attacks. While investigators have identified similarities in timing and technology, they have not yet confirmed if the incidents were carried out by a single group.

What should water utilities do to protect themselves?

Federal agencies recommend that water utilities follow the joint cybersecurity advisory to identify exploitable vulnerabilities and strengthen the security of their internet-facing systems.

Related Videos

IDEM: Enhancing Cybersecurity in Water Infrastructure

Indiana Department of Environmental Management

Episode 262 Joshua Corman on Cyber Threats to Water Infrastructure

The Security Ledger

Critical Infrastructure Under Pressure: Energy, Water, & the Future of Cyber Defense (Part 2)

Mission Critical

Sources