Sweeping Cyberattack on Water Systems Shakes Multiple States
Qwenews.com – A sweeping cyberattack on water systems has struck utilities across several American states, forcing facilities to issue boil-water advisories and switch to manual operations by disconnecting from network connections. Federal authorities describe this as one of the most significant cyber incidents targeting water infrastructure in recent years, with industry experts calling it particularly severe.
For about seven days, the US Cybersecurity and Infrastructure Security Agency, along with the FBI and Environmental Protection Agency, have been working to strengthen water facilities and ensure drinking water safety remains intact. So far, no contamination events have been reported.
Minnesota Leads the Response
Minnesota authorities provided the first public signs of the coordinated attacks, reporting that hackers struck approximately 30 water systems during the weekend from Sunday night through Monday morning. A memorandum released by the Minnesota Bureau of Criminal Apprehension and reviewed by CNN outlined the attackers’ probable objectives.
“The likely desired impact” of the intrusion at water facilities was “to cause loss of system pressure and subsequent potential contamination of water supply,” the memo stated.
The attackers are specifically targeting programmable logic controllers, commonly known as PLCs, which are connected to the internet and enable machinery communication at water treatment plants and industrial facilities. These controllers oversee critical functions including water pressure monitoring and chemical dosing to maintain system safety.
“I suspect that those attackers are going to … continue to look nationally across the infrastructure,” John Israel, Minnesota’s chief information security officer, told CNN on Tuesday.
Expanding Scope and Suspects
His assessment proved accurate. Approximately six states have documented related cyber incidents within the past week, according to several sources with knowledge of the ongoing investigation.
Wisconsin officials identified malicious cyber activity at their water facilities on Monday, issuing a memo through the state’s Department of Natural Resources that urged utilities to “immediate action to prevent potentially serious impacts to our systems.”
While federal officials have not formally attributed responsibility, Iran is being treated as a primary suspect. Authorities remain cautious about potential false flag operations. CISA issued a warning on Thursday emphasizing that hackers “are targeting water entities of all sizes” and recommending that facilities disconnect vulnerable industrial equipment.
“The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented,” Gus Serino, a longtime cybersecurity specialist focused on the water sector told CNN.
Serino continued, noting that “While the inherent resilience of the water sector helped limit operational impacts, these incidents once again demonstrate that many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls capable of preventing or significantly impeding this type of attack.”
Historical Context and Industry Concerns
The water sector has faced persistent challenges with funding and workforce training for cyber defense capabilities. The Water Information Sharing and Analysis Center, which serves as an industry hub for cyber threat intelligence, has recommended that utilities strengthen their systems over the past week.
Iran possesses a documented history of targeting the water sector, including activities during the ongoing conflict with the United States. CNN reported in April that hackers linked to Iran successfully disrupted operations at multiple US oil and gas facilities as well as water sites.
“The rising number of water compromises is deeply concerning. So much depends upon water… No water, no hospital, no kidding… in 2-4 hours,” Joshua Corman, another industrial cybersecurity expert who co-founded I am the Cavalry, a volunteer group that focuses on cybersecurity for resource-poor organizations.
Corman emphasized the double-edged nature of modern connectivity: “Water systems have enjoyed the benefits of remote access, but now those who wish us harm have it, too.” He concluded with a critical question for the industry: “With great connectivity comes great responsibility. We should be asking ourselves if we’re doing enough.”

