Security

Cyberattacks on US Water Systems Spread to at Least Seven States

Hackers have targeted water and wastewater utilities in at least seven states, locking operators out of monitoring systems in attacks the FBI and CISA have linked to Iranian actors, SecurityWeek and the Philadelphia Inquirer reported this week.

C
By Chris Vega Space Reporter
August 8, 2026 / Updated August 19, 2026 / 6 min read

A wave of cyberattacks on US water and wastewater systems has spread to at least seven states, according to reporting this week from SecurityWeek and the Philadelphia Inquirer, with the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) pointing to Iranian actors behind a campaign that began late last month.

12 Hours of Locked-Out Operators

Two South Jersey towns — Cape May and Woodbine — confirmed their water systems were hacked in the early morning hours of July 27, the Inquirer reported on August 7. In Cape May, hackers changed the IP address of the water department's computer system, temporarily locking out officials; in Woodbine, communications to the water monitoring system were cut off and had to be reactivated manually. Both systems were impacted for about 12 hours, though officials said water never stopped running and remained safe to consume, and no customer data was compromised.

A National Campaign

Minnesota reported that operational technology systems at more than 30 water and wastewater facilities were targeted on July 26 and 27, with nine facilities impacted in Michigan. ABC News reported Georgia is also among the affected states. "After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality," the FBI said in a statement. Last month, CISA, the FBI, and the CIA issued a joint statement linking Iran to cyberattacks against the same class of hardware.

An Exposed Attack Surface

Internet security firm Censys reported that roughly 10,000 industrial control systems from Rockwell, Siemens, and Schneider Electric are exposed to the internet, though it is unclear how many are actually vulnerable. The campaign underscores how the nation's smallest utilities — often running aging control equipment with little security staffing — have become a target for state-backed operators probing US critical infrastructure.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.