Skip to content

Illustration by iStock

OT Cybersecurity Experts Call for More Controls, Grants in Response to U.S. Water Facility Cyberattacks

Cyberattacks hit water systems in at least seven U.S. states in the past week. Hackers remotely accessed Internet-connected controls, changed administrator passwords and device IP addresses, and disrupted operations, threatening to contaminate pipes with untreated ground water, according to a joint statement from the FBI and the Environmental Protection Agency on 30 July.

IT teams at the water plants swiftly responded to the intrusions, isolating affected systems and preventing major public health risks.

The FBI and EPA statement said that the attackers targeted operational technology (OT) devices, including programmable logic controllers (PLCs). To reduce the risk of compromise, the FBI and EPA strongly recommended removing PLCs from direct Internet exposure using secure gateways and firewalls; setting up strong, unique passwords; and using an access control list to allow only authorized communication between expected control system devices.

On 22 July, the FBI, EPA, and the Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian-affiliated cyber actors were exploiting PLCs in U.S. infrastructure. The agencies had originally published this warning in April 2026 but updated it in light of the latest attacks and device vulnerabilities.

“Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting, and imposing costs on those responsible,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division in a news release. “Sharing timely, actionable intelligence is a critical part of that work. This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on.”

Investigators have not yet publicly linked the latest attacks to Tehran, but the timing of the incidents—aligned with recent U.S. missile strikes in Iran—has raised notable concerns. In addition, Iranian hackers have targeted U.S. water infrastructure before, including a 2015 cyberattack targeting a New York dam.

At least 30 Minnesota municipal water facilities were targeted in a coordinated cyberattack in July, the state’s IT Services department said. In Braham, Minnesota, public works personnel noticed that the well supplying the city’s water tower was malfunctioning. They isolated the affected system, restored a backup, and restarted the plant in 90 minutes, CBS News reported. Residents had no loss of water service, since the tower usually holds enough drinking water for two days. In Plymouth, Minnesota, officials also detected compromised PLCs at two water towers and 14 sewer lift stations before disconnecting the devices from the cellular network, moving operations to manual mode until the breach was resolved.

Michigan reported cyberattack on nine of its water systems, but officials said all systems were operating “safely.” Officials have not confirmed which other states were also affected.

Local water plants have become popular targets in digital and asymmetric warfare, especially because those facilities often lack the funds and resources to keep up with software patches and other security measures, the Associated Press (AP) reported. OT vulnerabilities have also been on defenders’ radar for years.

In response to the recent attacks, the Operational Technology Cybersecurity Coalition’s Executive Director Tatyana Bolton published a call for congressional action on OT cybersecurity in critical infrastructure.

“This week we are facing a reckoning of the consequences of ignoring the importance of investing in our nation’s cybersecurity for our critical infrastructure,” Bolton wrote.

She strongly recommended the U.S. government move beyond threat bulletins and information-sharing and toward solid action, including issuing a Binding Operational Directive on OT security that requires fundamental security controls; congressional reauthorization and funding of the State and Local Cybersecurity Grant Program to help small towns protect themselves from nation-state attacks; and passing long-term (rather than just minor extensions) authority for the Cybersecurity Information Sharing Act of 2015, which allows the U.S. government to identify widespread cyber campaigns and trends across sectors. The information-sharing act is set to expire on 30 September.

In an opinion piece for The New York Times, former CISA Director Jen Easterly wrote that the attacks “expose a dangerous mismatch at the heart of American cybersecurity: The threat is geopolitical, while the defense is municipal. We are asking small towns—many with no dedicated cybersecurity staff members and little money to spare—to protect essential infrastructure against attackers linked to other nations.”

“Nation-state hackers do not respect the jurisdictional lines separating federal, state, and local responsibility,” she continued. “They search for the most vulnerable way to disrupt American life, and too often they find it in small communities that lack the resources to defend themselves.”

Easterly recommended that the federal government rebuild CISA’s personnel and capabilities—which were cut in the first few months of the Trump administration in 2025 and have been downsized more since—and reaffirm that defending critical infrastructure is “a nonpartisan national security mission.”

“Congress should restore federal support for the multistate information sharing center and commit at least $3 billion in new multiyear funding to the State and Local Cybersecurity Grant Program,” she wrote. “Some of that money should be dedicated to replacing aging controls in water facilities and strengthening their ability to operate safely when digital systems fail—including through manual controls, physical safety mechanisms, and regularly exercised response plans. Manufacturers and systems designers must also build equipment with secure settings, modern authentication, effective record keeping, and safe remote-access controls from the outset. Small-town operators should not have to be cybersecurity experts merely to use essential equipment safely.”

 

arrow_upward