Locked Out of Their Own Pumps: Why US Water Utilities Just Got a National Warning
The federal government issued a nationwide alert Thursday about water system cyberattacks, warning that intrusions against drinking water and wastewater utilities have increased sharply and that operators of every size are being targeted.
The warning from the Cybersecurity and Infrastructure Security Agency followed an incident in Minnesota, where more than 30 community water systems were hit in what the state described as a coordinated attack over two days.
What Happened in Minnesota
The activity took place on July 26 and 27, when equipment that is normally monitored and controlled remotely was interfered with.
Minnesota IT Services confirmed that investigators had verified malicious activity involving a system’s technology, while noting that not every affected community experienced a disruption to service.
South St. Paul offered one of the clearer accounts. A city spokesperson said the problem was identified early Monday and contingency procedures were implemented immediately, with public works employees switching to manual operation. Water and wastewater services continued without interruption, and the city said drinking water treatment, quality, pressure and delivery were unaffected — the incident was confined to technology supporting portions of the utility.
Elsewhere the impact was reportedly more substantial, with at least one municipal well and treatment plant taken offline.
John Israel, Minnesota’s chief information security officer, said the state has passed relevant information to federal authorities, who are assessing the activity in a broader national context and leading efforts to determine whether it can be attributed to a specific actor.
What CISA Is Warning About
The agency’s alert describes a consistent pattern. Attackers are going after programmable logic controllers — the small industrial computers that automate physical processes like pumps and valves — and changing passwords to lock legitimate operators out of their own equipment. In some cases systems have been disconnected by altering their network addresses.
The practical consequences described in the advisory are the ones utilities dread: boil water notices, and plants forced to run manually.
CISA’s central recommendation is blunt and not new: get these devices off the public internet as quickly as possible. Where remote access is genuinely necessary, route it through a VPN or a gateway device rather than exposing the controller directly.
The agency added a warning that even organisations with mature security programmes should re-examine their external connections, because the targeting includes cellular modems installed by operators, vendors or integrators that may never have been documented and therefore never appear in routine reviews of what is exposed.
That detail is worth dwelling on. Many utilities do not have a complete inventory of what is reachable from the outside, often because equipment was connected years ago by a contractor for convenience and simply left in place.
The Attribution Question
This is where care is required, because the reporting and the official position are not the same thing.
Multiple outlets report that US investigators are examining whether Iran or actors associated with it were responsible. Those same reports stress that any such assessment is preliminary and could change as more data is gathered. The FBI is investigating and has not publicly named anyone. CISA declined to confirm reports of an Iranian connection. Minnesota and municipal officials have described the responsible party only as unknown.
What is documented is the surrounding context. Federal agencies including CISA, the FBI, the NSA, the EPA, the Department of Energy and US Cyber Command have jointly warned since April that Iranian-affiliated actors have been exploiting internet-facing industrial controllers across American critical infrastructure. That advisory was updated on July 22 — four days before the Minnesota incident — to expand the list of affected equipment manufacturers beyond Rockwell Automation to include Schneider Electric and Siemens devices.
Private researchers have offered their own suspicions about which group was involved, based on the operational pattern and the timing. Those are analytic judgments by outside firms, not government findings, and at least one detailed public assessment explicitly rated its own confidence in the link as low to moderate.
The honest summary: the timing is conspicuous, the pattern resembles a known campaign, and nobody official has said so.
Why Water Utilities
The vulnerability here is structural rather than exotic.
The United States has roughly 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities. The overwhelming majority are small, municipal and rural, operating on budgets that do not support a dedicated security staff.
That combination makes them attractive for two separate reasons. They are comparatively easy to reach, and disrupting them produces visible public alarm out of proportion to the technical effort involved. A boil water notice reaches every household in a town within hours.
Local water plants and healthcare facilities have become recurring targets globally for exactly this reason — they frequently lack the funding and expertise to keep software patched and configurations tightened.
The Wider Pattern
Digital operations have become a standard component of modern conflict rather than an exotic add-on, and infrastructure that sits outside military control is increasingly on the receiving end.
Cynthia Kaiser, formerly deputy assistant director of the FBI’s cyber division and now tracking threats to critical infrastructure, has pointed to both the geopolitical motivation and the documented history of water sector targeting associated with Iran-linked actors.
None of that establishes responsibility for this particular incident. It does explain why federal agencies moved so quickly to issue a general warning rather than waiting for attribution.
What Residents Should Take From This
The reassuring part of the Minnesota case is that manual operation worked. Where systems were compromised, staff switched to running plants by hand and water kept flowing at normal quality.
That is the design philosophy that matters most in this sector: keeping a functioning analogue fallback so that losing the automation layer is an inconvenience rather than a crisis.
The less reassuring part is that more than 30 systems were affected simultaneously in a single state, which suggests the underlying exposure is widespread rather than isolated.
For utility operators, the immediate action items from the advisory are unglamorous — inventory what is reachable from the internet, remove control devices from direct exposure, replace default credentials, and account for remote-access equipment nobody remembers installing.
For everyone else, the practical guidance is the ordinary kind: follow local utility notices, and take boil water advisories seriously if one arrives.
Author
-
Lucienne Albrecht is Luxe Chronicle’s wealth and lifestyle editor, celebrated for her elegant perspective on finance, legacy, and global luxury culture. With a flair for blending sophistication with insight, she brings a distinctly feminine voice to the world of high society and wealth.






