Water sector cyberattacks are continuing to expand across the United States, with more states reporting incidents related to recent intrusions targeting water and wastewater facilities. While the overall count keeps rising, officials have not disclosed details for every affected location yet. What has become clear, however, is that the campaign’s technical focus and potential impacts deserve urgent attention from defenders.
According to reporting referenced by ABC News, at least 12 states have been hit. The names of only a limited number of impacted states are known publicly, and the information varies from confirmed disruptions to suspected activity under investigation.
Which states have reported water system attacks
Minnesota was among the first to report attacks. Community water systems in the state were reportedly targeted on July 26 and 27, with more than 30 organizations affected. Shortly after, Michigan officials confirmed that a “small number” of communities experienced malicious cyber activity.
South Dakota also reported at least one city where the cyberattack appeared to be tied to the same broader activity. As the situation progressed, more entities stepped forward with official confirmations or clarifications.
Georgia and other public confirmations
The latest official confirmation mentioned in the coverage came from the Clayton County Water Authority in Georgia. The authority reported a “temporary disruption” that affected part of its operational systems and water service. In that case, some areas saw reduced water pressure, but service was restored within hours.
Wisconsin, meanwhile, has appeared in the news but had not publicly confirmed intrusions at the time of reporting. In parallel, representatives from several major water utilities indicated they had not been impacted by cyberattacks.
Grants and uncertainty in New York
New York had not indicated whether it was affected by this particular campaign. Even so, officials announced more than $9 million in grants designed to help 153 water systems improve their cybersecurity posture. This suggests that, regardless of whether specific intrusions occurred, the sector is preparing for threats that can disrupt operations.
Utah’s separate incident involving industrial control systems
Utah reported a hacker attack aimed at industrial control systems at an oilfield saltwater disposal facility. However, that intrusion was detected in March and does not appear to be connected to the more recent campaign affecting water and wastewater infrastructure. At the time of reporting, there were no additional reports of new attacks in Utah.
FBI updates: at least seven states confirmed
As of July 30, the FBI had officially confirmed that at least seven states were affected. In a cyber alert, the agency described the attackers’ focus on specific programmable logic controllers (PLCs) manufactured by Rockwell Automation.
Notably, the FBI’s alert indicated that there were no official reports of significant disruption and that drinking water remained safe. Even so, the FBI provided details on how malicious cyber actors operate and what kinds of operational effects could occur if systems are compromised.
How attackers may manipulate PLCs and operational settings
The FBI warned that malicious cyber actors are targeting PLCs that are exposed to the internet. In particular, the alert pointed to MicroLogix 1100 and 1400 series devices, and it highlighted techniques used to tamper with device configurations remotely.
Based on the FBI’s explanation, attackers may change IP addresses and modify authentication settings, including turning on and setting passwords. The result can be a loss of visibility into connected equipment. In some cases, attackers can also affect functionality, depending on how the PLC is configured and what it controls.
The FBI also shared examples of what defenders might observe. At least one organization reportedly found modified PLC project files after noticing differences in ladder logic across multiple sites. In addition, the FBI noted that similarities in network setup provided by third parties could allow attackers to replicate success across multiple customers when the underlying hardware and network conditions are similar.
Potential impacts: pressure loss and flooding
While many reports did not describe major disruptions publicly, the FBI still described possible operational effects that had been reported to investigators. Those effects included loss of pressure and flooding.
Pressure loss in water systems is particularly concerning because it can create conditions where untreated groundwater may seep into pipes. In other words, the risk is not only immediate disruption of service, but also potential consequences for water quality depending on how systems are designed and what safety controls are present.
Importantly, the FBI emphasized that the extent of impact could vary. It depends on factors such as whether the PLC was set up for monitoring or controlling equipment, which PLC model was involved, which functions the device supported, and whether the system could switch to manual operations when needed.
Attribution questions and the Iran-linked concern
At the time of the referenced reporting, the US had not officially disclosed who was behind the attacks. However, Iran was described as a primary suspect. The reasoning is that Iranian-linked hackers have been known to target ICS/OT environments, including in the water sector.
Investigators were reportedly looking into possible Iran involvement. In addition, the water sector information-sharing organization WaterISAC—described as an information-sharing hub for the sector—was reported to have cited evidence that the attacks were “aligned” with hacking campaigns previously associated with Iran.
What CISA urged the sector to do
In response to these kinds of threats, CISA urged organizations in the water sector to protect their OT environments, with a specific focus on PLCs. The guidance aligns with the FBI’s observations that attackers are searching for internet-exposed PLCs that can be reached for remote configuration tampering.
Federal agencies also updated an earlier advisory that had been issued in April. That update warned that ICS devices made by Siemens, Schneider Electric, and Rockwell Automation were targeted in Iranian attacks aimed at OT technologies.
Defender context: exposed PLCs and uncertainty about true vulnerability
Several details in the coverage add context for defenders trying to gauge risk. Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet. At the same time, it remains unclear how many of those devices are actually vulnerable or reachable in a way that enables exploitation.
This distinction matters. An exposed device may not always be misconfigured or exploitable in the same manner, but exposure still raises the probability of malicious actors discovering and attempting access. Security teams typically need to combine asset inventory with configuration review and network segmentation checks to understand which systems present real risk.
For organizations that want technical references, Infracritical reportedly shared a report summarizing currently known technical information for the OT security community. Such resources can help defenders map observed behavior to known attack patterns and prioritize remediation steps.
Why this matters for water utilities now
Even where public reports describe limited disruption, water sector cyberattacks highlight a serious vulnerability class: operational systems where PLCs support processes that directly affect service reliability and public safety. The FBI’s description of remote configuration tampering shows that attackers may focus on manipulating how connected equipment behaves, not just stealing data.
In addition, the reported pattern—where multiple sites can share similar third-party network setups—suggests that compromises can scale across organizations that have comparable architectures. That makes it essential for defenders to treat cybersecurity as an operational readiness issue, not only an IT concern.
As more confirmations emerge and investigative details continue to develop, utilities and system owners should focus on strengthening OT defenses around PLC exposure, reducing unnecessary connectivity, and ensuring that monitoring and manual override processes are effective when automation is compromised.
Conclusion
Water sector cyberattacks have now been reported across multiple states, with at least 12 reported incidents and at least seven confirmed by the FBI at the time of the referenced updates. The central technical theme is the targeting of internet-exposed PLCs, which attackers may manipulate to disrupt visibility, modify configurations, and potentially cause operational effects such as loss of pressure or flooding.
While drinking water was reported to remain safe in official statements referenced here, the possible consequences and the scale of internet exposure make this an urgent priority for OT defenders. Utilities that act early—by reducing exposure, validating PLC configurations, and improving resilience—will be better positioned as the situation evolves.
Source: https://www.securityweek.com/water-sector-cyberattacks-reportedly-hit-at-least-12-states/
