U.S. government cyber officials warned on Thursday of a significant increase in hackers targeting technology used to control water and wastewater systems, urging operators to remove internet-exposed control equipment 'as soon as possible.'

The alert from the Cybersecurity and Infrastructure Security Agency (CISA) came two days after Minnesota's state IT agency said more than 30 community water systems were targeted in a 'coordinated cyberattack' on July 26 and 27. The FBI said utilities in at least seven states have reported incidents, some of which 'degraded water operations,' including loss of pressure and flooding. In some cases hackers changed passwords to lock out operators, forcing boil-water notices and sustained manual operation.

U.S. officials reviewing the matter say it is likely Iranian-linked hackers are behind the Minnesota attacks, according to the New York Times — an escalation of activity that predates but has intensified amid the U.S.-Iran war. Former FBI official Cynthia Kaiser called the campaign 'highly likely' a continuation of Iranian-affiliated targeting of programmable logic controllers (PLCs) and other critical-infrastructure technology flagged in an April advisory, updated July 22.

State and local officials said the Minnesota attacks did not threaten water safety; most confirmed cases involved PLCs and the operator screens used to manage them. The FBI did not immediately respond to a request for comment about alleged Iranian involvement.