Cyberattacks on U.S. Water Systems Raise Alarm, Attribution Questions

Federal and state investigators in the United States are examining a wave of cyberattacks that have struck water and wastewater systems in at least seven states this week, forcing some communities to issue boil water notices and raising...

Jul 31, 2026 - 21:22
Updated: 1 month ago
0 5
Cyberattacks on U.S. Water Systems Raise Alarm, Attribution Questions
Cyberattacks on U.S. Water Systems Raise Alarm, Attribution Questions

Federal and state investigators in the United States are examining a wave of cyberattacks that have struck water and wastewater systems in at least seven states this week, forcing some communities to issue boil water notices and raising urgent questions about the security of internet-connected industrial controls on both sides of the border.

The FBI said Thursday that "some of that activity has degraded water operations," a development the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said has led affected communities to issue boil water notices and switch to manual operations. The agencies, alongside state authorities, are urging water utilities to disconnect vulnerable equipment from the internet without delay.


Water treatment purifiers at a municipal filtration plant — the type of internet-connected infrastructure under scrutiny

Attacks begin in Minnesota, spread across the Midwest

The attacks appear to have begun in Minnesota on Sunday and Monday, according to a statement from the state's IT services department (MNIT) on Tuesday. By Thursday, MNIT reported that more than 30 community water systems across the state had been targeted, though it stressed that "impacted" does not necessarily mean disrupted.

"In this situation, 'impacted' means investigators confirmed malicious activity involving a system's technology," the MNIT statement said. "It does not mean every affected community experienced a disruption to water service."

There have been no requests from affected communities for residents to modify their drinking water use, MNIT said. Officials in neighbouring Wisconsin also detected malicious cyber activity at water facilities on Monday, according to a memo from the state's Department of Natural Resources obtained by CNN. The FBI advisory did not name the seven states that have reported attacks since the start of the week.

According to the FBI, the attacks involved changing IP addresses and passwords for water systems' programmable logic controllers (PLCs), "resulting in a loss of monitoring and control functionality." The bureau warned that operational effects reported so far have "included loss of pressure and flooding."

"Pressure loss in water systems could potentially allow untreated ground water to seep into pipes," the advisory said.

Attribution remains unresolved

Despite widespread media reports, officials have not yet publicly linked this week's attacks to a specific threat actor. Minnesota "has not attributed the activity to a specific actor," MNIT said Thursday, noting investigators have yet to confirm every incident is connected but have identified "similarities."

"We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor," John Israel, Minnesota's chief information security officer, said in the statement.

Multiple U.S. news outlets, including the New York Times, CNN and CBS News, reported Thursday and Friday, citing federal and state sources familiar with the investigation, that Iran is believed to be involved. The Water Information Sharing and Analysis Center (WaterISAC), which co-ordinates cybersecurity information for the U.S. water utility industry, confirmed the existence of a memo linking the Minnesota attacks to "Iran-affiliated" hackers. That memo, according to Wired, cited information from the Minnesota Fusion Center, a state intelligence-sharing agency, saying the attacks were "aligned" with methods outlined in a CISA advisory first published in April and updated this month.

The CISA advisory, updated and recirculated last week, warned that "Iranian-affiliated cyber actors" were exploiting PLCs across U.S. critical infrastructure, including water systems. Warnings about Iranian cyber threats have increased since the U.S. and Israel launched the war on Iran in late February 2026.

President Donald Trump, however, dismissed the possibility of Iranian involvement on Friday, pinning the blame on Minnesota's government instead.

"You know who's behind it? Minnesota, because they're grossly incompetent," Trump said during a cabinet meeting. "I think the governor's behind it. I don't think there was an Iranian cyberattack. I think that Minnesota ought to get its act together. They like to say, 'Oh, it was Iran.' Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."

Minnesota Gov. Tim Walz fired back on X, writing that "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran." Walz also alleged that federal funding cuts to CISA have "left the U.S. exposed to cyber attacks," while his state's authorities were able to mitigate the water system attacks.

PLCs: small devices, enormous consequences

At the centre of the investigation are programmable logic controllers — internet-connected computer devices used to remotely control and monitor industrial operations. The devices allow geographically dispersed systems to be managed from a central office, which is particularly useful for large urban communities. In water systems, PLCs can be integrated into dams, pumping stations, treatment facilities and other critical infrastructure.

CISA's advisory describes a sophisticated method of attack: Iranian-affiliated cyber actors have been using third-party programming software to gain remote access to specific PLCs, extract program data, and manipulate it to allow water systems to "enter unsafe conditions" without notifying operators, bypassing critical shutdown and alarm procedures.

A loss of pressure in a drinking water system can allow untreated groundwater to seep into pipes. Flooding damage can disable treatment equipment for extended periods, and even a temporary loss of monitoring and control forces operators to fall back on manual overrides — a slower, more labour-intensive way of managing water supplies.

CISA's advisory warned that the threat actors are "targeting water entities of all sizes," adding: "Even water organizations with mature cybersecurity processes should validate their external connections."

Canadian utilities face the same threat surface

The attacks have direct relevance for Canadian water systems, which rely on similar industrial control technologies and share a border with an increasingly contested cyber environment.

A November report from the Canadian Centre for Cyber Security — part of the Communications Security Establishment — on the threat to water systems warns that "the more internet-connected assets an organization has, the larger the threat surface" that can be exploited by criminal hackers. The report, circulated to Canadian critical infrastructure operators, outlines mitigation measures for securing PLC systems, including disconnecting unnecessary internet exposure, strengthening authentication, and maintaining manual override procedures.

Canadian water utilities face a complex jurisdictional patchwork. Municipalities own and operate most drinking water and wastewater systems, while provincial governments regulate them, and the federal government has limited but real responsibilities through agencies like the Canadian Centre for Cyber Security and Public Safety Canada. That diffusion of responsibility can complicate co-ordinated cybersecurity responses — a challenge the United States is now confronting in real time.

The U.S. attacks also carry cross-border implications. Many Canadian utilities share supply chains, software platforms and even data networks with U.S. counterparts. A sophisticated threat actor able to compromise PLCs in Minnesota may well probe similar systems in Ontario, Manitoba, or Quebec. The Canadian Cyber Centre has consistently advised critical infrastructure operators to assume that techniques demonstrated abroad will eventually be directed at Canadian targets.

Mitigation and unanswered questions

The FBI and CISA are urging all organisations that use PLCs to disconnect them from the public-facing internet and ensure remote modems connected to the systems are secured. Passwords should be changed and strengthened, with additional access safeguards, such as firewalls, installed. The agencies say manual overrides should also be maintained and practised in the event of an incident.

The Canadian Cyber Centre report echoes those recommendations, and Canadian water utilities would be wise to review their exposure in light of this week's events. The attacks are putting renewed pressure on operators to act quickly, but the attribution question remains open.

What is clear is that the threat is real and growing. What remains unclear — pending a formal federal determination — is precisely who is responsible, how far the attacks have reached, and whether the seven affected states represent the full scope of the intrusion. Investigators have yet to confirm whether all incidents are the work of a single actor, though Minnesota officials have pointed to "similarities" across the cases.

For Canadians, the episode is a reminder that critical infrastructure security is not a purely domestic concern. Water systems in North American communities are increasingly controlled by internet-connected devices, and the consequences of failure are measured in public health and public safety. The Canadian Centre for Cyber Security's guidance, issued well before this week's headlines, now looks prescient — and urgent. The lesson for utilities on both sides of the border is straightforward: the technology that makes modern water systems efficient also makes them vulnerable, and the time to secure them is before an attack arrives, not after.

Tags: cyberattacks, water systems, PLC, Iran, FBI, CISA, Minnesota, critical infrastructure, cybersecurity, Canadian Centre for Cyber Security, boil water advisory, programmable logic controllers

By Alex Thompson, Staff Writer

This article was produced with AI-assisted research and editorial support. Reporting is based on sources cited in the article.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Alex Thompson

Canada Correspondent at Global1.News. Based in Toronto, covering Canadian politics, energy, trade, and US-Canada relations. Provides the Canadian perspective on North American and global affairs.

Comments (0)

User