Full story
FBI-EPA water system hacks
The FBI and the Environmental Protection Agency warned that hackers targeted water and wastewater utilities in at least seven states, with incidents beginning July 27 and some activity degrading water operations.
“causing 'loss of pressure and flooding,' the FBI says.”
PCMag reported the FBI said hackers targeted internet-exposed programmable logic controllers, causing “loss of pressure and flooding,” and the agency warned that pressure loss could allow untreated groundwater to seep into pipes.

Cybersecurity Dive said CISA was seeing a “significant escalation” of attacks targeting programmable logic controllers and that operators had been locked out of their operational technology networks.
The attacks involved PLCs used to automate and monitor pumps and other functions for drinking water and wastewater treatment, and the FBI said hackers modified passwords and changed IP addresses to block monitoring and control functions.
In Minnesota, the initial series of attacks impacted more than 30 water systems, and operators in some cases were forced to issue boil-water notices and revert to manual operations.
Attribution fight and warnings
As federal agencies investigated whether Iran-linked threat groups were involved, President Donald Trump blamed Minnesota authorities during a Cabinet meeting, saying, “I think I blame it on Minnesota because they’re grossly incompetent.”
Gov. Tim Walz responded in a Facebook post that the attack “further illustrates there’s no plan to win a war with Iran,” while CBS News reported investigators were probing whether the activity was the work of Iranian hackers.
NBC News said the FBI and EPA advisory focused less on attribution than on the tactics used, noting that the agencies urged operators nationwide to take precautions after hackers remotely accessed internet-facing devices and changed IP addresses and passwords.
ABC7 New York reported CISA said the targeting of programmable logic controllers and modifying passwords “to lock out operators,” and it said the alert came two days after Minnesota officials revealed state water systems were hit on Sunday and Monday.
CBS News also quoted CISA’s acting director Nick Anderson warning that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.”
Operational disruption and next steps
Federal agencies urged water utilities to disconnect PLCs from direct internet exposure and strengthen defenses, with PCMag reporting the FBI and EPA urged affected companies to disconnect their PLCs from the public-facing internet and implement firewall rules.
“disconnect their PLCs from the public-facing internet, implement firewall rules”
Cybersecurity Dive said operators had been locked out of their operational technology networks and that in some cases they were forced to issue boil-water notices and revert to manual operations.
The advisory described operational effects including pressure loss and flooding, and it warned that loss of pressure can lead to untreated water seeping into pipes under certain conditions.
ABC7 New York reported Minnesota IT Services said there were no active requests from Minnesota localities for residents to change their water use, and it stressed that “impacted” meant investigators confirmed malicious activity involving a system’s technology.
CBS News said some utilities transitioned to manual operations and that in South St. Paul public works employees transitioned to manual operations so water and wastewater services continued without any interruption to service.




