Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure.
In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.
The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation.
A spokesperson for Minnesota’s information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had “resulted in boil water notices and sustained manual operations,” though it did not say where.
Minnesota officials and the U.S. government have not publicly attributed the malicious activity in the state to a specific actor. Likewise, the FBI and the EPA did not identify a culprit behind the breaches in the other states.

President Donald Trump, speaking to reporters Friday at Camp David, blamed Minnesota’s leaders and Gov. Tim Walz, who was the Democratic vice presidential nominee in the 2024 election.
“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
In response to a request for comment, Walz said in part: “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”
The FBI and EPA advisory focused less on attribution than on the tactics used in the attacks.
The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions.
Earlier this week, the Wisconsin Department of Natural Resources issued a bulletin to water contacts in the state, saying intelligence officials believed that “systems within Wisconsin may be susceptible to connections from malicious cyber actors.”
“This leads us to believe that the cyber threat is ongoing in Wisconsin and requires immediate action to prevent potentially serious impacts to our systems,” the bulletin said.
A Wisconsin Department of Natural Resources spokesperson emphasized that intelligence officials in the state “had not yet confirmed that systems in Wisconsin have had connections but are concerned that they might be susceptible to connections from malicious cyber actors.”
In the warning, Wisconsin said that Minnesota had reported that hackers managed to drop system pressures, which in “several incidents triggered alarms and prompted a response from law enforcement.” The warning noted that if pressure dropped far enough, “it could result in a full system shutdown” or contamination.
Minnesota’s public statements on the breach did not contain those details, and the information technology agency spokesperson did not immediately respond to a request for comment on Wisconsin’s bulletin.

The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities.
The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.
“Attribution requires careful analysis of technical evidence alongside broader national and international threat intelligence, and our federal partners are best positioned to lead that work,” said Emily Zimmer, a spokesperson for Minnesota’s information technology agency.
The breach in Minnesota happened just days after U.S. officials publicly warned that Iran-backed hackers were targeting the nation’s critical infrastructure amid the escalating military conflict between Washington and Tehran.
In a public advisory July 22, the Cybersecurity and Infrastructure Security Agency, as well as the FBI and other federal agencies, urged companies to boost their defenses, saying Tehran-linked hackers were trying to breach online automated devices used to manage infrastructure systems.
U.S. intelligence agencies have also cautioned that Iran is increasingly able and willing to carry out aggressive cyber operations and that it tried to target water systems in 2023.
Bryson Bort, the founder of the cybersecurity company Scythe and an expert in industrial control system security, said the FBI’s disclosures this week underscore the need for more public awareness of the risks posed by infrastructure breaches.
“We need to be prepared,” Bort said. “Attacks like this illustrate that there are folks who mean the U.S. harm today.”



