The US Cybersecurity and Infrastructure Security Agency (CISA) has warned of a growing wave of cyberattacks targeting the nation’s water and wastewater systems after a coordinated incident affected dozens of community water facilities in Minnesota.
According to CISA, attackers are increasingly targeting programmable logic controllers (PLCs), the automated devices that manage critical water infrastructure. In several cases, hackers changed system passwords, preventing operators from accessing equipment and forcing some facilities to switch to manual operations while issuing boil water advisories.
The warning follows reports from Minnesota’s state IT agency that more than 30 community water systems experienced a coordinated cyberattack earlier this week. The attacks reportedly occurred on July 26 and 27 and involved unauthorized access to systems used for remote monitoring and operational control.
State officials confirmed investigators identified malicious activity affecting industrial control technology, although they said not every community experienced disruptions to water services.
Minnesota Chief Information Security Officer John Israel said relevant information has been shared with federal authorities, who are leading efforts to determine whether the attacks can be linked to a specific threat actor.
US investigators are reportedly examining whether the incident may have connections to Iran, although officials caution that the investigation remains in its early stages and no final attribution has been made. CISA declined to comment on reports regarding Iran’s possible involvement.
The warning comes amid heightened geopolitical tensions in the Middle East and follows previous federal advisories about cyber threats targeting critical infrastructure.
The United States operates approximately 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities, many of which rely on internet-connected industrial control systems that experts say remain vulnerable to cyberattacks.
Earlier this year, CISA warned that Iranian-linked hacking groups were targeting internet-connected operational technology, including PLCs manufactured by Rockwell Automation. The agency later expanded its advisory to include similar devices produced by other manufacturers, urging operators to strengthen cybersecurity protections across essential infrastructure.
Erizia Rubyjeana