Federal and state authorities are investigating a series of coordinated cyberattacks targeting drinking and wastewater treatment facilities across the U.S. Threat groups with suspected links to Iran have targeted vulnerable programmable logic controllers, the devices used to monitor and control various industrial systems, including those of water utilities.
Utilities in at least 12 states were impacted by the attacks, including Minnesota, Michigan, Georgia, South Dakota and New Jersey.
The first public discovery of the threat began in Minnesota, where more than 30 community water systems were targeted in a “coordinated attack” from July 26-27. Hackers hit PLCs as well as human machine interfaces, the dashboards for monitoring water levels or temperatures.
Officials in South St. Paul, Plymouth, Maple Plain and Braham have confirmed they were attacked, but stated that water safety was not affected.
In Georgia, the Clayton County Water Authority said an attack on July 27 briefly disrupted its OT systems. Officials issued a boil water advisory and restored service within a few hours after testing confirmed the water supply was safe.
Authorities in New Jersey responded to two confirmed cyber incidents in July and have been working with the affected utilities, along with the FBI and CISA. Both of the incidents involved vulnerable internet-exposed devices, which temporarily prevented operators from monitoring or managing them remotely.
“In both cases, staff shifted quickly to manual operations, and there was no disruption to service,” a spokesperson for the NJ Office of Homeland Security and Preparedness told Cybersecurity Dive. “Customers had uninterrupted access to safe drinking water throughout.”
Vulnerable PLC devices
The attacks began days after CISA and the FBI issued a July warning about expanded targeting of vulnerable PLCs in the water and energy sectors. Hackers originally began targeting PLCs made by Rockwell Automation in the early weeks of the Iran war, and in recent months expanded their attacks to Schneider Electric and Siemens PLCs.
Rockwell Automation in March issued an updated warning about a legacy authentication bypass vulnerability tracked as CVE-2021-22681 in its Studio 5000 Logix Designer software. If exploited, the flaw could allow an attacker to use an unauthorized third-party tool to alter the configuration of a Logix controller.
Among these newly targeted devices were the Schneider Electric BMX P34/Modicon M340 PLCs, as well as the Siemens S7-1200 series PLCs. U.S. authorities on Wednesday warned of a wider campaign of AI-enabled hackers targeting internet-exposed and out-of-service Siemens S7 series devices across multiple industries, including water.
Hacktivist attacks
The threat against water systems is not a new phenomenon. Iran-nexus adversaries, for example, have been targeting water systems in Israel and the U.S. since the launch of the Gaza war in 2023. CyberAv3ngers, a group backed by the Islamic Revolutionary Guard Corps, targeted vulnerable Unitronics PLCs in multiple cyberattacks across the U.S.
The Biden administration engaged with state and local officials in an attempt to strengthen water utility security. A 2024 investigation by the EPA’s Office of Inspector General uncovered vulnerabilities in hundreds of water utilities across the country.
Multiple initiatives were made to provide assistance to rural water systems, including DEF CON Franklin, which was supported by the National Rural Water Association and the University of Chicago.
Iran-linked attacks against water and energy systems ramped up earlier this year following the U.S. and Israeli bombing campaign in February. The FBI and CISA warned that the attacks led to operational disruption and financial losses.
Authorities suspect Iran-nexus groups are behind the July attacks. However, questions emerged whether more than one group was involved: Minnesota officials called the attacks “coordinated” and said it was not clear whether all of the attacks were carried out by the same actor.
Earlier this month, a group called APT Iran claimed credit for the Minnesota attacks, saying it was working with CyberAv3ngers, according to Check Point Research. The hackers made additional claims, saying they had access to power grids and telecommunications systems as well.
Calls for cyber oversight
Federal authorities and industry groups now are collectively pushing for greater oversight and additional resources to help prevent additional attacks against water utilities. The EPA held a conference call with hundreds of stakeholders in the water industry in late July, and key industry groups are pushing for new legislation.
The National Association of Water Companies is urging Congress to pass bipartisan legislation to create a water risk and resilience organization that would advise the EPA on developing uniform cybersecurity standards. NAWC officials said such an organization should operate similar to the North American Electric Reliability Corp., which helps regulate the power industry.
“We need to be collaborating more than ever,” Robert Powelson, president and CEO of NAWC, told Cybersecurity Dive. “None of us should be exempt from meeting compliance standards.”
The American Water Works Association sent a letter to House and Senate leaders urging similar support, including additional funding, additional eligibility for cybersecurity training and improved information sharing.
None of us should be exempt from meeting compliance standards.

Robert Powelson
President and CEO of the National Association of Water Companies
Various states have taken immediate action to address the heightened risks to community water systems. Earlier this month, New York Gov. Kathy Hochul announced $9 million in grants to better protect water facilities. The grants would be available for Tier 1 improvements like penetration testing and risk assessments or Tier 2 improvements, including firewalls, network segmentation and incident response plans.
A source familiar with the grant program said New York was not among states impacted by the recent cyberattacks.
Defense in Depth
As federal authorities continue to investigate and industry leaders push Congress on new legislation, frontline water system operators have to make real-time decisions about how to protect their systems from immediate threats.
The July attacks led to temporary disruptions at many of the impacted utilities, leading to the loss of water pressure and flooding in certain cases. Thus far, operators were able to avoid more catastrophic impacts.
“Some of what I think the adversaries are trying to achieve here is just a fear factor,” Ryan Whelan, managing director and head of cyber intelligence at Accenture.
Some of what I think the adversaries are trying to achieve is just a fear factor.

Ryan Whelan
Managing director and head of cyber intelligence at Accenture
Federal officials and PLC vendors have been urging water utility companies to harden their environments with multifactor authentication, remove devices from the open internet, change complex passwords and replace end-of-life software to supported versions.
Firewalls should be configured to limit access to PLCs and device switches should remain in the “run” position and only switched to “remote” or “program” positions when downloading software or updating existing applications, according to the CISA and FBI advisory.
OT experts, meanwhile, advise utilities to take a hard look at their entire network and secure every potential entry point.
“That means approaching the environment like an attacker would,” said Harry Thomas, CTO and co-founder of OT security firm Frenos. “Identifying every path into the control system, determining which paths lead to PLCs and other operational crown jewels, and finding the places where one compromised credential, vendor connection or cellular modem could bypass multiple layers of defense.”