Skip to content
Beveiligingsnieuws

US Water Cyberattacks Spread Across States

Impliceert vertrouwen 4G/5G-kernen

What started as a cyber incident in Minnesota’s water and wastewater sector is now drawing wider attention. As more information has emerged, the US water cyberattacks appear to have reached at least seven states, raising concerns about how attackers may be targeting operational technology (OT) across critical infrastructure.

Minnesota announced that OT systems at more than 30 water and wastewater facilities were targeted during an attack window on July 26 and 27. While public communications from cities were limited, the messages that did appear aimed to reassure residents that drinking water remained safe and that most operations were not visibly disrupted.

Even so, multiple outlets reported that additional states were impacted. The broader pattern has also kept the focus on Iran-linked activity, with sector-focused reporting describing evidence that aligns with previously known campaigns.

Beyond Minnesota: more states confirm malicious activity

Local officials in Minnesota reported the impact at a high level, noting that operational systems were targeted at dozens of facilities. In many cases, cities did not publicly describe significant operational consequences. One city temporarily took a water plant offline in response, but most reported no operational impact that would affect public safety.

As reporting expanded, mainstream media sources said they had learned from references that at least seven states were involved. The names of several affected states were not confirmed publicly at the time of publication, but a few jurisdictions did share additional details.

Michigan: a small number of communities

Michigan officially confirmed that a “small number” of communities experienced malicious cyber activity. Michigan’s statement emphasized continuity: all systems continued to operate safely, and there were no public health concerns reported.

South Dakota: Rapid City and lift-station activity

Rapid City in South Dakota also reported a cybersecurity incident. The city’s description points to a specific part of its wastewater operations—its lift stations—used to move wastewater as part of the municipal system.

In a post on Facebook, Rapid City stated that, at no time, were the city’s water or wastewater infrastructure systems put in jeopardy. The city also assured residents that the water supply remains safe and protected.

Georgia included among targeted states

ABC News reported that Georgia is among the states targeted in the water sector cyberattacks. However, the other impacted states beyond the ones mentioned publicly were not identified at the time of writing.

Why Iran is discussed as the likely threat actor

Iran was quickly raised as the primary suspect, largely because of past reporting about Iranian hackers targeting industrial control systems (ICS) and OT environments, including in the water sector. While the US government had not made a public attribution at the time, several mainstream media reports said federal investigators were looking into potential Iranian involvement.

One factor referenced by sector reporting was alignment evidence found by a Minnesota Fusion Center. According to reporting about a WaterISAC document, the information suggested that the attacks were “aligned” with hacking campaigns the US had previously linked to Iran.

That document was described as being marked TLP:Amber and not intended for broad public dissemination, which helps explain why technical and attribution details have remained limited.

What defenders can learn even without full technical details

Detailed technical information has not been widely published by every city affected. Still, some observations from Minnesota officials and industry understanding of OT environments can guide defenders on what to look for.

Cellular-connected equipment as a likely access path

One Minnesota city indicated the incident involved equipment connected via cellular communications. Security professionals generally view OT endpoints that reach the internet through cellular networks as a potential intrusion vector—especially when devices are exposed or poorly segmented from other parts of the environment.

This focus on cellular connectivity also matches past observations: Iranian-linked attackers have reportedly targeted water facilities in Israel using vulnerable cellular routers. While every environment differs, the common theme reinforces why OT network paths deserve close review.

Program logic controllers (PLCs) are a critical focus

After the Minnesota incident came to light, the US Cybersecurity and Infrastructure Security Agency (CISA) urged the water sector to protect OT systems, specifically programmable logic controllers (PLCs). PLCs often sit at the core of industrial processes, meaning that compromise could have direct operational consequences—even if initial impacts appear limited.

In addition to the post-incident messaging, federal guidance preceding the event reportedly included warnings about OT-targeting activity associated with Iranian threats.

Those warnings referenced Iranian attacks aimed at OT devices and noted targeting of industrial control systems produced by Siemens, Schneider Electric, and Rockwell Automation. The reporting also highlighted a data point from Censys, which estimated that roughly 10,000 Rockwell, Siemens, and Schneider PLCs were exposed to the internet—though it was not clear how many were actually vulnerable.

Sector updates and ongoing reporting for OT teams

Because the public record contains limited technical details from each affected location, OT defenders benefit from centralized, continually updated references. Industry reporting has pointed to an evolving compilation of known technical information for defenders.

One resource mentioned in the coverage is an analysis that is updated continuously to summarize current knowledge of the intrusion chain and relevant indicators. While such summaries cannot replace local investigation, they help teams compare findings, prioritize log review, and cross-check suspicious network behavior.

Practical steps for organizations protecting OT

Even without access to every incident detail, the themes in public reporting offer clear defensive priorities for water and wastewater operators and other OT owners.

  • Review internet exposure pathways: Identify OT endpoints that can be reached from outside via any transport, including cellular connections.
  • Strengthen PLC protection: Apply hardening practices and ensure PLC environments are managed with secure access controls.
  • Improve segmentation: Reduce opportunities for attackers to move from one network zone to another.
  • Increase monitoring around OT communications: Validate that logging and alerting cover the OT-to-network boundary where intrusion attempts may occur.
  • Align with sector guidance: Follow CISA and other trusted guidance for OT isolation and incident response preparation.

It’s also important to remember the communication pattern described by cities: many reported no immediate operational impact, yet they still confirmed malicious activity or targeted OT systems. That combination makes incident response discipline essential—attackers can still seek persistent footholds even when operations appear stable.

What the expanding footprint means for public safety

The reassuring messages from cities—such as statements that water systems were not jeopardized—matter for communities. At the same time, the broader geographic spread underscores that cybersecurity events in utilities can be regional in nature and may follow a repeatable access method.

When multiple jurisdictions report similar categories of malicious activity, it becomes harder to dismiss the incidents as isolated events. Operators should use these developments to reassess assumptions about how attacks begin, which systems are most exposed, and how quickly they can validate that safety-critical processes remain unaffected.

Conclusion

The US water cyberattacks are no longer limited to a single state. With Minnesota reporting extensive targeting of OT systems and other states such as Michigan, South Dakota (Rapid City), and Georgia confirming incidents or malicious activity, the pattern signals a broader campaign.

While the full technical picture has not been publicly shared, the guidance highlighted in reporting—especially around protecting PLCs and scrutinizing OT exposure paths like cellular connectivity—offers actionable direction for OT defenders. For water and wastewater operators, the key takeaway is clear: even when impacts appear limited, OT security must be treated as a critical, continuous responsibility.

Source: https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/