A July 30 advisory from the FBI, EPA, and the two lead cyber agencies, CISA and NSA, documents a known control system exposure — industrial controllers water utilities have placed directly on the public internet — and ties it to a seven state
Hackers have reached the industrial control hardware at US water and wastewater utilities from across the internet and reconfigured it, the FBI and EPA warned in a joint public service announcement dated July 30, 2026. The attacks, which began on July 27, have hit at least seven utility companies in seven states. Victims have reported flooding and loss of water pressure.
The FBI's July 30 PSA (PDF) describes a short attack chain. Attackers reach the utility's network, locate an internet-facing Programmable Logic Controller (PLC), the ruggedized industrial computer that runs a pump, valve, or chemical treatment step, and then remotely change the device's IP address and reset its password. The operator is locked out. The PLC keeps acting on whatever instructions the attacker left behind.
In the prior week, more than 30 municipal water facilities in Minnesota were infiltrated in a coordinated run. The state fusion center's memo on that wave, obtained by Wired, aligns the activity with a hacking campaign CISA previously attributed to "Iran-affiliated" actors. NBC News has reported that the Minnesota incidents carry hallmarks of Iranian meddling. Law enforcement has not formally attributed either the Minnesota wave or the current seven-state wave to any nation-state.
The federal advisory backing the warning, CISA AA26-097A, extends a position the agencies have held since April 2026, when they warned that "Iran-affiliated" hackers were targeting water infrastructure alongside other critical-infrastructure sectors. The underlying exposure, a control device reachable from the public internet, is older than that advisory. The July 30 PSA is the federal response to a documented pattern, not a new disclosure.
Operationally, a utility takes a PLC at a pump station or a treatment train and connects it to the public internet, often through a cellular or broadband link put in for remote access. The default credential, or a weak one, stays in place. The PLC accepts a remote login. The attacker changes the address and password. The operator loses visibility. The damage is the result of a controller doing what its last instruction told it to do, with no one able to correct it: flooding, pressure loss, the loss of chemical-treatment setpoints.
The FBI's PSA warns that loss of water pressure can let untreated groundwater seep into the distribution system, a larger operational and health problem than low pressure alone. GovTech's reporting on the seven-state incidents catalogs the same downstream effects: service disruption, recovery cost, and the loss of public trust that comes with a treatment plant that, for some hours, cannot tell its operators what it is doing.
The fix the FBI, EPA, CISA, and NSA are asking for is decades-old network hygiene, restated for this wave. Utilities should remove direct internet exposure from PLCs and put them behind a secure gateway or firewall; enforce stronger passwords and credential management; and apply access control lists so a compromised device cannot talk to the rest of the network without restriction. The advisory is not asking the sector to invent anything. It is asking utilities to stop running the exposed configuration the current attackers are using.
The question any reader can carry out the door is the same one the advisory is built around: whether the water utility serving a given home or business runs its control systems on a network segment reachable from the public internet, and whether anyone at the utility can answer that in writing. Federal guidance, the state fusion centers, and the current set of incidents all point at the same gap. The local utility is the entity that closes it.