Cyberattacks against municipal water and wastewater systems have been reported in at least seven states this week, leading the FBI and the Environmental Protection Agency to issue a nationwide alert urging utilities to harden their defenses. In a public service announcement released Thursday, the agencies said operators had reported incidents to the FBI, with some of the activity degrading water operations. The announcement did not identify the states involved.
The warning follows attacks on more than 30 municipal water facilities in Minnesota that a law enforcement official said showed hallmarks of Iranian involvement. The incidents remain under investigation. A spokesperson for Minnesota’s information technology services agency said Thursday there was no evidence the breaches contaminated any municipal water supplies. In a separate alert, the Cybersecurity and Infrastructure Security Agency noted that some larger attacks on water infrastructure had “resulted in boil water notices and sustained manual operations,” though it did not specify locations.
Neither Minnesota officials nor the U.S. government has publicly attributed the activity in the state to a specific actor. The FBI and EPA likewise declined to name a culprit behind the breaches reported in other states.
President Donald Trump, speaking to reporters Friday at Camp David, blamed Minnesota’s leaders and Gov. Tim Walz, the 2024 Democratic vice presidential nominee. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
In a statement provided in response to a request for comment, Walz said in part: “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
The FBI and EPA advisory focused primarily on tactics rather than attribution. It said the malicious cyber actors targeted specific brands of industrial control systems used by municipal water utilities, while urging operators of all systems to take protective steps.
Earlier this week, the Wisconsin Department of Natural Resources issued a bulletin to water contacts stating that intelligence officials believed “systems within Wisconsin may be susceptible to connections from malicious cyber actors.” The bulletin added: “This leads us to believe that the cyber threat is ongoing in Wisconsin and requires immediate action to prevent potentially serious impacts to our systems.”
A Wisconsin DNR spokesperson emphasized that officials “had not yet confirmed that systems in Wisconsin have had connections but are concerned that they might be susceptible.” The bulletin also stated that Minnesota had reported hackers dropping system pressures in several incidents, triggering alarms and prompting law-enforcement responses.
Minnesota’s information technology agency disputed those characterizations. “Minnesota has not reported that threat actors lowered pressure across multiple water systems or that pressure changes prompted a law enforcement response,” spokesperson Emily Zimmer said in an email.
According to the federal advisory, the attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The agencies recommended that operators remove programmable logic controllers from direct internet exposure by placing them behind secure gateways and firewalls, enforce strong passwords, and restrict communications between authorized control-system devices through access control lists.
The Minnesota breaches occurred days after U.S. officials publicly warned that Iran-backed hackers were targeting the nation’s critical infrastructure amid escalating military tensions between Washington and Tehran. In a July 22 advisory, CISA, the FBI, and other federal agencies urged companies to strengthen defenses, noting that Tehran-linked actors were attempting to breach online automated devices used to manage infrastructure systems. U.S. intelligence agencies have previously cautioned that Iran is increasingly capable and willing to conduct aggressive cyber operations and that it attempted to target water systems in 2023.
Bryson Bort, founder of the cybersecurity firm Scythe and an expert in industrial control system security, said the latest disclosures highlight the need for greater public awareness of infrastructure risks. “We need to be prepared,” Bort said. “Attacks like this illustrate that there are folks who mean the U.S. harm today.”
