Hackers targeted water and wastewater utilities across at least seven U.S. states, disrupting operations at some sites.
Water and wastewater utilities across at least seven U.S. states have reported cyber incidents since late July, raising fresh concerns about the security of critical infrastructure.
According to reports, the attackers targeted internet-exposed control systems used to remotely monitor and manage water facilities. In some cases, operators lost access to parts of their systems after passwords or network settings were changed.
Minnesota was among the most affected states, with more than 30 community water systems targeted in a coordinated attack on July 26 and 27.
State officials said cybersecurity response teams were activated to support affected communities, share threat intelligence and help utilities contain and recover from the incidents. Some operators reportedly shifted to manual processes to maintain service.
There has been no confirmed indication of drinking water contamination.
The attacks appear to have focused on operational technology, including programmable logic controllers and related interfaces. Authorities have not officially named a perpetrator, although investigators have reportedly examined possible links to Iran-backed actors and groups previously associated with attacks on exposed industrial systems.
The incidents highlight a long-running weakness for smaller utilities: remote access tools, reused credentials and limited network segmentation can turn basic access failures into operational disruptions.
U.S. agencies have urged water operators to remove internet-exposed industrial control systems, secure remote access through VPNs and multi-factor authentication, disable unnecessary accounts and separate IT networks from operational technology.
The attacks show that critical infrastructure does not need a highly complex vulnerability to be at risk. For utilities in the U.S., Europe and beyond, the priority is now clear: test exposure, harden access and treat operational technology as a frontline cybersecurity concern.