Water Sector Cyberattacks Reportedly Hit at Least 12 States
At least 12 US states targeted in cyberattacks on water and wastewater facilities.
Summary
A growing cyberattack campaign has impacted at least 12 US states, targeting water and wastewater facilities. The FBI confirmed attacks on Rockwell Automation PLCs, leading to disruptions like loss of pressure and flooding. While no drinking water safety issues have been reported, Iran has emerged as the primary suspect due to its history of targeting industrial control systems.
Full text
The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. At least 12 states have been hit, according to ABC News, but the names of only a handful of the affected states are currently known. States affected by water system cyberattacks Minnesota was the first to report attacks, with more than 30 community water systems targeted on July 26 and 27. Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity. At least one city in South Dakota has also reported a cyberattack that appears to be part of the same campaign. The latest to provide official confirmation of attacks is the Clayton County Water Authority in Georgia, which said it “experienced a temporary disruption affecting a portion of its operational systems and water service”. The incident resulted in reduced water pressure in some areas, but water service was restored within hours. Wisconsin has also been in the news, but it has yet to confirm any intrusions. Representatives of several major water utilities said they have not been impacted by cyberattacks. New York has not said whether it has been affected by the campaign, but officials this week announced more than $9 million in grants to help 153 water systems boost their cybersecurity.Advertisement. Scroll to continue reading. Utah has also reported a hacker attack aimed at industrial control systems in an oilfield saltwater disposal facility, but that intrusion was detected in March and it does not appear to be part of the recent campaign. There are currently no reports of new attacks in Utah. FBI shares details on hackers’ actions and impact As of July 30, the FBI had officially confirmed that at least seven states had been affected. The agency said in a cyber alert that the attackers had targeted Micrologix programmable logic controllers (PLCs) made by Rockwell Automation. There have been no official reports of significant disruption, and drinking water has remained safe. However, the FBI has shared some details on the attackers’ actions and the potential impact. The agency explained: “MCAs [malicious cyber actors] are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities. At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers. Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.” The US has yet to officially say who is behind the attacks, but Iran immediately emerged as the primary suspect as its hackers have been known to target ICS/OT, including in the water sector. Federal investigators have been reportedly looking into Iran’s potential involvement, and a non-public report from WaterISAC, which serves as the information-sharing organization for the water sector, reportedly cited evidence that the attacks were “aligned” with hacking campaigns previously linked to Iran. Information for defenders CISA urged the water sector to protect OT systems, specifically PLCs. In addition, federal agencies have updated an April advisory on Iranian attacks aimed at OT devices, warning that ICS devices made by Siemens, Schneider Electric, and Rockwell Automation have been targeted. SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, but it’s unclear how many are actually vulnerable to attacks. Infracritical has made available a report that summarizes all of the currently known technical information for the OT security community and defenders. Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Microsoft Bug Bounty Program: $20 Million Paid to 500 ResearchersN‑able Patches Vulnerability Exploited to Hack N-central ServersUS Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsSemiconductor Firm Analog Devices Discloses Data Breach1 in 5 Data Center Assets Are Within Easy Reach of AttackersCisco Secure FMC Zero-Day Exploited in the WildThreatLocker Raises $190 Million in Series F Funding Latest News Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware LayerOligo Raises $60 Million for Runtime SecurityCISO Conversations: Russ Kirby – Passion Is the Antidote to BurnoutWeaponized Email AI Assistants Could Help Attackers Hijack AccountsZenity Raises $125 Million in Series C FundingObsidian Security Raises $85 Million at $1.1 Billion ValuationTP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Nea
Indicators of Compromise
- malware — Micrologix
- mitre_attack — T0872