At least seven U.S. states reported cyberattacks affecting water systems, though officials say there is no evidence that public drinking water is unsafe. CISA warned of a sharp rise in attacks targeting programmable logic controllers (PLCs), which attackers have used to change passwords and IP addresses, prompting boil-water notices and manual operations. Investigators have not publicly attributed the incidents to a foreign actor, though some sources cite increased Iranian cyber activity. Federal, state and local teams are working to secure systems and restore normal operations.
Cyberattacks Hit Water Systems in Seven U.S. States; CISA Warns of PLC Targeting

At least seven U.S. states have reported cyber intrusions affecting water systems as local and state authorities work to ensure public drinking supplies remain safe.
There is no evidence that any public water supply is unsafe to drink, according to reporting by The New York Times. Minnesota was the first state to disclose the incident; Michigan and several other states have since reported similar activity.
"CISA is observing a significant increase in cyber threat actors targeting programmable logic controllers in the Water and Wastewater Systems sector," the Cybersecurity & Infrastructure Security Agency said in a release. The agency urged owners, operators and integrators of critical infrastructure to remove publicly exposed PLCs and other operational technology from the internet as quickly as possible.
CISA warned that attackers targeting exposed PLCs have modified passwords to lock out operators and have disconnected devices by changing IP addresses. Those actions have prompted boil-water notices in some communities and forced operators to switch to sustained manual operations while systems are restored and secured.
Dale George, director of communications for Michigan's Department of Environment, Great Lakes and Energy, told CBS News that "a small number of reports from Michigan communities indicat[ed] activity consistent with what federal agencies described." He added that "all systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern."
CBS reported that more than 30 community water systems in Minnesota experienced impacts tied to the cyber activity. Local operators and state teams have been working to identify vulnerabilities and restore normal operations.
Officials speaking to The New York Times said Iran has increased cyber operations against U.S. systems, but investigators have not definitively attributed these recent water-system incidents to any foreign actor. Past incidents have shown that water infrastructure can be a target, and investigators note the lack of an obvious financial motive makes typical criminal hackers a less likely explanation.
The incidents prompted political exchanges: President Donald Trump publicly blamed Minnesota and Gov. Tim Walz during a televised Cabinet meeting, while Walz accused the federal government of weakening cybersecurity protections and praised Minnesota experts for identifying and stopping the vulnerability. In Braham, Minn., Mayor Nate George said federal and local officials "are pretty sure it's Iranian actors," but officials have been cautious about making a formal public attribution.
Federal and state cybersecurity teams continue to investigate. CISA and other agencies are urging water and wastewater operators to take immediate steps to secure PLCs and other operational technology, remove exposed devices from the public internet, rotate credentials, and review logs and access controls.
Help us improve.




























