A coordinated wave of cyberattacks has struck drinking water systems across the United States, targeting facilities in at least 12 states and prompting an urgent FBI warning about vulnerabilities in critical infrastructure.

The Attacks

Dozens of water utilities have reported cyberattacks since the beginning of summer 2026. The attacks targeted internet-facing programmable logic controllers (PLCs) — the industrial computer systems that manage water treatment, distribution, and monitoring operations.

The FBI issued a formal advisory warning that malicious cyber actors were actively targeting water and wastewater sector PLCs, causing operational disruptions. The advisory specifically noted that the attackers were exploiting devices that remained connected to the internet without adequate security protections.

Minnesota was among the hardest hit, with more than 30 water utilities in the state targeted in a coordinated campaign. Other affected states include California, Texas, and several others across the Midwest and Northeast.

Who Is Behind It?

While the FBI has not officially attributed the attacks to a specific nation-state, multiple reports point to Iran as the likely sponsor. One hacker group claimed to have breached a water facility in California in retaliation for a US cyberattack on Iranian water infrastructure.

The attacks represent a significant escalation in state-sponsored cyber warfare targeting civilian infrastructure — a line that had been relatively respected in previous conflicts.

The Vulnerability

The water sector has long been identified as one of the most vulnerable parts of US critical infrastructure:

- Legacy systems: Many water utilities operate industrial control systems that were designed decades ago, before cybersecurity was a consideration - Internet exposure: PLCs that should be isolated on internal networks are sometimes directly accessible from the internet - Limited resources: Small and mid-sized water utilities often lack dedicated cybersecurity staff or budgets - No federal mandate: Unlike the power sector, water utilities face no mandatory cybersecurity standards

Arizona State University researchers noted that the attacks exposed fundamental vulnerabilities in the technology controlling critical water infrastructure, calling for immediate upgrades.

Why This Matters

Water is the most fundamental of all critical infrastructure services. Unlike a power outage that can be resolved in hours, a compromise of water treatment operations could:

- Contaminate drinking water supplies affecting millions of people - Disrupt water pressure needed for firefighting - Cause chemical imbalances that damage pipes and distribution systems

The attacks come at a time of heightened geopolitical tension, with the US and Iran engaged in ongoing cyber operations against each other's infrastructure. The targeting of civilian water systems marks a dangerous new frontier in state-sponsored cyber warfare.

Federal authorities are urging all water utilities to immediately audit their internet-facing systems, disconnect any PLCs accessible from the public internet, and implement network segmentation to limit the blast radius of future attacks.