- Utilities in at least seven states reported cyberattacks since July 27, 2026.
- Attackers changed passwords and internet addresses to lock out operators.
- Federal agencies urged utilities to disconnect key control devices from the internet.
Friday, July 31, 2026 — Yesterday the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) issued a public warning
that hackers are attacking the computers that run water and wastewater systems. Since July 27, 2026, water utilities in at least seven states have reported break-ins to the FBI. Some of those attacks degraded water operations.
The machines under attack.
Water plants rely on small industrial computers called programmable logic controllers (PLCs). These devices do jobs like opening and closing valves, running pumps, and tracking water pressure. The FBI reported that the attackers went after certain models made by Rockwell Automation under the Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 series. The agency added that operators of other brands should take the same precautions.
The intruders reached devices that were connected directly to the internet. Once inside, they changed the devices’ internet addresses and set new passwords. That locked out the utilities and caused a “loss of monitoring and control functionality,” according to the FBI. At least one utility discovered that its control programs had been altered after staff noticed differences in the logic running across several of its sites.
What went wrong at the tap.
The FBI reported that some utilities lost water pressure and others experienced flooding. A drop in pressure is more than an inconvenience. The agency warned that low pressure could allow untreated groundwater to seep into pipes. How serious the damage became depended on the job the device was doing, whether it was watching equipment or controlling it, which model it was, and whether the utility could switch to running things by hand.
A coordinated strike in Minnesota.
The BBC
reports that a United States cyber defense agency, the Cybersecurity and Infrastructure Security Agency (CISA), warned of a sharp rise in hackers targeting water and wastewater systems, with some operators forced to issue boil-water notices and run their equipment manually. According to the BBC, Minnesota’s state technology agency said more than 30 community water systems there faced a coordinated cyberattack on July 26 and 27, 2026, and United States investigators were examining a possible link to Iran, a preliminary assessment that could change as more information is gathered.
This has happened before.
A joint guide published in January 2024 by CISA, the FBI, and the EPA
shows the water sector has faced repeated cyber trouble. In July 2021, criminals used ransomware known as ZuCaNo to break into a control computer at a Maine water utility, which forced staff to run key processes by hand. A month later, in August 2021, a California water utility was hit by a strain called Ghost that sat hidden in the system for about a month before it was found. In November 2023, a group called CyberAv3ngers, tied to the Iranian government’s Islamic Revolutionary Guard Corps, broke into Israeli-made Unitronics control devices used at United States water utilities, likely by taking advantage of weak passwords and equipment left open to the internet.
Who handles these cases.
The same guide explains how the federal government divides the work. CISA serves as the lead for coordinating the response, the EPA is the agency responsible for managing risk in the water sector, and the FBI leads the threat investigation and any law enforcement action.
Steps the agencies recommend.
The FBI and EPA laid out steps water utilities can take to lower their risk
. The main one is to keep control devices off the public internet and route any remote access through a secure gateway, sometimes called a jump host. The agencies also urged utilities to set long, unique passwords, to limit which computers are allowed to communicate with the control devices, and to secure and monitor the cellular modems used for remote access.
Beyond that, the guidance recommended keeping physical or software “key switches” in the run position to block unauthorized changes, reviewing control programs for tampering before restoring them, and practicing the ability to operate systems manually. The agencies further advised replacing older equipment that manufacturers no longer support with security updates, since such devices are often targeted.
Where to report an attack.
The FBI asked any utility with similar problems to contact its local FBI field office and file a report with the Internet Crime Complaint Center at ic3.gov. Utilities can also reach CISA’s round-the-clock operations center at 1-844-729-2472, also listed as 1-844-Say-CISA. Questions about the affected equipment can go to Rockwell Automation’s product security team.




