Federal agencies are warning that malicious cyber actors are actively disrupting water and wastewater systems across multiple U.S. states by seizing control of the industrial computers that run pumps, valves, and pressure systems. These devices, often old, internet-exposed, and no longer supported by their manufacturers, represent a classic Achilles’ heel in critical infrastructure. While the FBI and CISA have not publicly named a culprit, the technical pattern closely matches prior Iranian-affiliated campaigns. That said, China, Russia, and state-sponsored and criminal groups remain fully capable of the same tactics. Those responsible for public infrastructure should treat every internet-facing controller as a potential point of failure and follow the concrete steps the FBI has outlined.

Water systems in Seven states affected

Most modern water systems still rely on programmable logic controllers (PLCs), which are small industrial computers that open and close valves, run pumps, monitor pressure, and keep water moving safely. Think of them as the “nervous system” of a treatment plant or distribution network. When those controllers are reachable from the public internet, an attacker can gain access and change settings, lock operators out, or force the system into unsafe conditions.

In this current wave of incidents, described by the FBI in their notice, actors have been altering IP addresses and passwords on specific models of these devices. The result has been loss of monitoring, pressure drops, flooding in some cases, and a forced shift to manual operations. Pressure loss is especially concerning as it can allow untreated groundwater to enter pipes.

Utilities in at least seven states have reported the activity to the FBI since late July, with Minnesota seeing more than 30 community systems affected in a single coordinated burst.

The Achilles’ Heel

This vulnerability didn’t just sneak up on the national infrastructure. As noted above, these systems frequently have legacy equipment online and operational. Unfortunately, many of these devices that have reached end-of-life and no longer receive security updates from the manufacturer. Many were installed under the operational assumption that the systems would be isolated and thus remotely inaccessible. Once they are exposed online, or connected through poorly secured cellular modems or remote-access tools, they become soft targets. That combination of aging hardware, direct internet exposure, and limited ability to patch is precisely the vulnerability that has long been described as critical infrastructure’s Achilles’ heel.

These acts described by the FBI appear to be exploiting exactly that weakness. Attackers are not necessarily deploying sophisticated malware; they are walking through the technical doors that were assumed to have been close and should never have been left open.

Attribution: Official Silence, Industry Consensus

The FBI and CISA have deliberately avoided naming a perpetrator in their public alerts. They describe “malicious cyber actors” and focus on defensive actions.

That said, the technical footprint, targeting of specific Rockwell Automation/Allen-Bradley MicroLogix controllers, the method of changing IP addresses and passwords to lock out operators, the absence of ransom demands, and the focus on disruption aligns closely with campaigns previously attributed to Iranian-affiliated groups such as CyberAv3ngers (IRGC-linked) and related actors. Industry researchers and multiple U.S. officials speaking on background have pointed in that direction, lines up with advisories issued earlier in 2026 that explicitly warned of Iranian-affiliated PLC targeting across water, energy, and government facilities.

At the same time, China (through groups such as Volt Typhoon), Russia, and criminal organizations have all demonstrated the capability and interest to target similar industrial systems. The targeting of water infrastructure is not new, we have seen probes and disruptions caused by individual insiders, as well as multiple nation-state and non-state actors in recent years. The current activity does not require unique Iranian tooling; it requires only the ability to find exposed devices and the intent to cause operational disruption. Formal attribution remains open while technical forensics continue.

Given that the tradecraft on display here isn’t unique to any single actor, the possibility of a false flag needs to be considered. An adversary, or even a domestic actor, with a motive to inflame tensions amid the ongoing U.S.-Iran conflict could deliberately mimic the IP/password-lockout playbook publicly associated with Iranian-affiliated groups, knowing investigators and the press would be primed to draw that connection. Until forensics tie the intrusions to a specific toolset or infrastructure, an Iranian-style pattern should be read as circumstantial, not proof.

President Trump has publicly and forcefully rejected the Iran theory, instead pointing at the state of Minnesota itself. At a July 31 Cabinet meeting, he said: “I don’t think there was an Iranian cyberattack. I think Minnesota is behind it … They’re grossly incompetent …. Iran’s got bigger problems than worrying about Minnesota.” The U.S. and state officials seem to view Iranian involvement as the working theory, and underscore that no public consensus on responsibility currently exists.

What the FBI Advises Operators and Security Teams to Watch For – and Why

The FBI and EPA recommendations are practical and urgent:

  • Disconnect PLCs from the public internet. Route any necessary remote access through a secure gateway or jump host. Direct exposure is the primary enabler of these attacks.
  • Enforce strong, unique passwords and access-control lists. Default or weak credentials remain a common entry point.
  • Place physical and software key switches into the “run” position after any legitimate updates so unauthorized changes to logic or firmware are blocked.
  • Validate project files and ladder logic against known-good baselines. Unauthorized modifications have been observed.
  • Maintain and practice the ability to operate systems manually. Facilities that can fall back to manual control recover faster and limit secondary effects such as pressure loss.
  • Track end-of-life equipment and plan replacements or compensating controls with firm timelines. Unsupported devices will continue to be targeted.
  • Report anomalies immediately to the local FBI field office and the Internet Crime Complaint Center (IC3). Early reporting improves both attribution and sector-wide defense.

Related News

Christopher Burgess (@burgessct) is an author and speaker on the topic of security strategy. Christopher, served 30+ years within the Central Intelligence Agency. He lived and worked in South Asia, Southeast Asia, the Middle East, Central Europe, and Latin America. Upon his retirement, the CIA awarded him the Career Distinguished Intelligence Medal, the highest level of career recognition. Christopher co-authored the book, “Secrets Stolen, Fortunes Lost, Preventing Intellectual Property Theft and Economic Espionage in the 21st Century” (Syngress, March 2008).