DATANEWS

U.S. Warns Hackers Are Increasingly Targeting Water-Control Systems

Associated Press · 2026-07-31

More than 30 Minnesota water systems were targeted in cyberattacks, underscoring the risk of internet-exposed industrial control technology at small utilities.

Why it matters: Critical infrastructure operators remain exposed when industrial-control systems are connected directly to the internet.

U.S. officials are warning water and wastewater operators to remove exposed control technology from the public internet after a wave of attacks against utility systems.

More than 30 Minnesota community water systems were targeted during coordinated attacks in late July. Officials said confirmed incidents did not compromise drinking-water safety, but some systems faced operational disruption and had to rely on manual workarounds.

Attackers targeted technology used to monitor and operate equipment, including programmable logic controllers and operator-management interfaces.

Investigators have suspected Iranian-linked hackers in some incidents, but public attribution remains limited and should be treated carefully until federal agencies make a definitive statement.

The incidents demonstrate why industrial equipment should not be directly reachable from the internet. Water operators need segmented networks, restricted remote access, multifactor authentication, asset inventories and tested manual operating procedures.

Small utilities are often attractive targets because they may rely on older equipment, limited staffing and vendors for remote support. That makes basic cyber hygiene and emergency playbooks just as important as advanced tooling.

Source and attribution →