Cyberattacks on US water systems have expanded to at least seven states, including Minnesota and Michigan, according to federal officials and a New York Times report on August 2. The FBI and EPA reported that the activity "degraded water operations," with some facilities issuing boil-water notices or switching to manual operations — though officials stressed there is no evidence drinking water was contaminated or unsafe.
The Iran Angle
Federal investigators consider Iran the leading suspect, though the assessment remains preliminary: Tehran has escalated cyber operations since the US–Israel war against it began five months ago, and the intrusions appear to carry no financial motive — a hallmark of state-sponsored disruption rather than ransomware. Michigan confirmed nine municipal water systems reported issues.
President Trump downplayed the attacks, suggesting Minnesota was "behind it" — a claim Governor Tim Walz dismissed — while experts described the intrusions as opportunistic targeting of internet-connected operational systems.
Advice for Utilities
CISA has advised facilities to unplug vulnerable controllers from the internet and move them behind firewalls, echoing guidance issued after earlier waves of attacks on water, energy, and industrial targets. The widening scope — from single-plant incidents to a multi-state campaign — is straining a sector long criticized for weak operational-technology security, where aging controllers often predate modern authentication.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.