Cyberattacks on US water systems
Analysis based on 6 articles · First reported Aug 11, 2026 · Last updated Aug 11, 2026
The cyberattacks on US water infrastructure highlight vulnerabilities in critical public services, potentially increasing cybersecurity spending and insurance costs for utilities. While no direct financial losses have been reported, the incidents could affect public confidence and lead to regulatory changes.
In late July, United States — Minnesota reported that at least 30 municipal water systems suffered a coordinated cyberattack. The FBI subsequently warned that malicious cyber actors had gained access to water and wastewater systems in at least seven US states, causing operational disruptions. Similar incidents were reported in Georgia, United States — New Jersey, and United States — South Dakota, though it remains unclear if they are connected. Hackers targeted internet-facing programmable logic controllers (PLCs) that manage water pressure, chemical dosing, and other processes, often exploiting default or stolen passwords. US officials are investigating possible links to Iranian hackers, but no formal attribution has been made. President Donald Trump dismissed the Iran theory, saying Iran had bigger problems. The attacks forced some facilities to switch to manual controls and issue precautionary boil-water advisories, though no contamination has been reported. Experts warn the attacks undermine public trust in government services. The United States — Cybersecurity and Infrastructure Security Agency urged utilities to improve security measures, such as placing controllers behind firewalls and using VPNs.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard