Full Breakdown
Coordinated Cyber Intrusions Hit U.S. Water Utilities Across Dozens of States
8/7/2026, 10:31:19 PM
Core Event
In late July 2026 a wave of cyber intrusions targeted control systems of municipal water and wastewater utilities in the United States. Federal agencies reported that “malicious cyber actors” accessed programmable logic controllers (PLCs) in at least seven states (FBI) and 12 states — including Minnesota, Michigan, New Jersey, Georgia and South Dakota. The attacks altered IP addresses, locked out operators and caused temporary pressure loss, prompting a boil-water advisory in Clayton County, Georgia, and manual-mode operation at several sites. No contamination of drinking water has been confirmed.
Background & Context
PLCs automate pumps, valves and chemical dosing in treatment plants. CISA’s July 30 notice warned that many PLCs are directly exposed to the internet, often without passwords or firewalls, creating “low-hanging fruit” for threat actors. The tactics resemble a 2023 campaign attributed to the Iran-linked “CyberAv3ngers” group, which exploited default credentials on industrial controllers. While the FBI and CISA have not issued a formal attribution, officials repeatedly cite Iran-backed hackers as the most likely source.
Data & Statistics
- States affected: 7 (FBI) vs 12 (other reports).
- Minnesota: >30 municipal systems hit July 26-27.
- Georgia: Clayton County Water Authority serves 300,000 customers; pressure drop and boil-water advisory on July 27.
- National scope: ?152,000 public drinking-water systems and >16,000 wastewater facilities (EPA).
Official Statements & Responses
- CISA issued an advisory urging utilities to remove internet-exposed controllers, reset passwords and deploy firewalls.
- State officials confirmed that utilities shifted to manual control and that water remained safe to drink.
- President Donald Trump blamed “grossly incompetent” Minnesota officials and dismissed Iranian involvement at a July 31 cabinet meeting.
- Governor Tim Walz said the attacks illustrate “what modern warfare looks like.”
- John Martinelli, former CISA incident-response instructor, noted the absence of mandatory reporting requirements in most states.
Criticism & Opposition
Critics argue that the federal response is hampered by chronic under-funding of local cybersecurity programs. The Operational Technology Cybersecurity Coalition warns that the pending expiration of a $1 billion grant program in September will leave small towns without needed defenses. Trump’s attribution to Minnesota rather than Iran has been described by experts as “baseless” and politically motivated.
On-the-Ground Reports
Clayton County Water Authority spokesperson Erin Thomas said, “We are still investigating what happened, but something happened,” after the July 27 pressure loss forced a temporary boil-water notice. Local operators in Minnesota reported manual pump operation restored service within hours.
Conflicting Reports & Gaps
- State count: FBI cites seven states, while other sources report 12.
- Attribution: Federal agencies suspect Iran-linked actors but have not formally assigned blame.
- Reporting: No federal mandate requires utilities to disclose cyber incidents, creating uncertainty about the full scale of the campaign.
Verbatim Quotes
- “There's nothing that requires [utilities] to say, 'Here's all the information that we have. Here's how it happened,'” — Michael Garcia, Operational Technology Cybersecurity Coalition
- “From what we know about this campaign right now, it’s really about targeting the low-hanging fruit … systems or organizations that lack basic security practices,” — Lennart Maschmeyer, Georgia Institute of Technology
- “They like to say, ‘Oh, it was Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” — Donald Trump
What’s Next
CISA’s latest guidance (July 22) advises utilities to isolate PLCs from the internet, enforce multi-factor authentication and apply vendor patches. State and local agencies are expected to conduct manual-mode drills and upgrade network segmentation in the coming months.
