
CISA Warns of Rising Water System Cyberattacks
PHOTO CAPTION: FILE PHOTO: A view of Coolidge Dam at San Carlos Reservoir near Peridot, Arizona, U.S. July 3, 2026. REUTERS/Rebecca Noble/File Photo
July 30 — The U.S. government’s civilian cyber defense agency warned Thursday of a significant increase in hackers targeting technology used to operate water and wastewater systems.
The Cybersecurity and Infrastructure Security Agency, known as CISA, urged operators to remove vulnerable systems from the internet as soon as possible.
The warning came two days after Minnesota’s state information technology agency said more than 30 community water systems were targeted in a “coordinated cyberattack” on July 26 and 27.
The FBI said late Thursday that water and wastewater utilities in at least seven states had reported incidents and that some of the activity had degraded water operations.
U.S. officials and investigators reviewing the attacks believe Iranian-linked hackers were likely responsible for the Minnesota incidents, the New York Times reported Thursday.
The Iranian government did not immediately respond to a request for comment.
The FBI also did not immediately respond when asked about possible Iranian involvement.
The attacks occurred as the war between the United States and Iran intensified, with both sides exchanging missile attacks and threatening further action.
Iranian-linked hackers had targeted U.S. water facilities before the war. Other groups have also carried out prominent cyberattacks against American organizations, including medical technology company Stryker and the Los Angeles County Metropolitan Transportation Authority in March.
The White House referred questions about the Minnesota incidents to the FBI.
Minnesota officials said the attacks did not threaten water safety. In some cases, however, systems were taken offline and had to be reset manually.
CISA said hackers had sometimes changed passwords to lock out operators and disconnected devices from networks.
The agency said those actions had resulted in boil-water notices and extended periods of manual operation.
The FBI said unidentified victims reported operational effects that included lost water pressure and flooding in some locations.
Minnesota IT Services said its investigation remained underway.
Most confirmed incidents involved systems used to remotely monitor and control water equipment, including programmable logic controllers and the computer interfaces used by operators.
John Israel, Minnesota’s chief information security officer, said the state had provided relevant information to the federal government.
Federal officials were reviewing the activity in a broader national context and working to determine whether it could be attributed to a particular threat actor, Israel said.
Iranian-linked activity suspected
Cynthia Kaiser, a former senior FBI cybersecurity official, said the Minnesota campaign was highly likely to be a continuation of earlier Iranian-affiliated attacks targeting programmable logic controllers and other critical infrastructure technology.
CISA, the FBI, the National Security Agency and other federal agencies warned about that activity in an April advisory.
The advisory was updated July 22 to include additional targeted devices and more recent hacking techniques and activity.
“The fact that a new advisory came out is really indicative of either a broadening of the campaign, new technical details or a renewal of the activity, and probably a combination of all those things,” said Kaiser, now an executive at cybersecurity company Halcyon.
Chris Day, public-sector chief technology officer at cybersecurity company Tenable, said the Minnesota incidents were consistent with previously identified Iranian-linked activity.
He said reports that some systems were temporarily taken offline represented an escalation from earlier incidents.
(Source: Reuters)










