2 Remove Virus

FBI says cyberattacks on water utilities have spread across at least seven US states

The FBI has warned that cyberattacks targeting public water and wastewater utilities are affecting communities in at least seven US states, indicating that a recent wave of incidents extends well beyond the coordinated attacks reported in Minnesota. Federal authorities say the campaign has disrupted operations at multiple facilities and is focused on internet-connected industrial control equipment.

 

 

The alert, issued jointly with the US Environmental Protection Agency (EPA), follows reports that more than 30 water utilities in Minnesota experienced cyber incidents beginning in late July. While the FBI did not identify the affected states or formally attribute the activity to a specific threat actor, the warning aligns with recent guidance from the Cybersecurity and Infrastructure Security Agency (CISA), which links similar attacks to CyberAv3ngers, a hacking group that US authorities have previously associated with Iran’s Islamic Revolutionary Guard Corps (IRGC).

According to the FBI, utilities began reporting incidents on 27 July, with several organisations experiencing disruptions after attackers targeted internet-facing programmable logic controllers (PLCs). These devices automate industrial processes and are widely used to control water treatment and distribution systems.

Federal investigators said some attackers changed PLC passwords and network settings, preventing operators from remotely managing equipment and forcing utilities to switch to manual operations. In at least one reported case, investigators found unauthorised modifications to PLC project files after identifying discrepancies in ladder logic, the programming language commonly used to control industrial automation systems.

The operational impact varied between utilities. In Minnesota, local officials reported temporary communication failures, pressure loss and flooding at some facilities after the attacks. In Braham, municipal officials said attackers remotely disabled controls connected to a city well, temporarily interrupting normal operations until staff restored the system. The FBI warned that pressure loss in water distribution systems can increase the risk of untreated groundwater entering pipelines.

The advisory emphasises that smaller utilities remain particularly vulnerable because many continue to operate older industrial control systems that are directly accessible from the internet and often have limited cybersecurity resources.

To reduce the risk of compromise, the FBI and EPA urged operators to disconnect internet-facing PLCs whenever possible, replace default passwords, restrict network access to control systems, maintain the ability to operate facilities manually, and regularly review PLC programming for unauthorised changes. The agencies also recommend planning for the replacement of ageing equipment that no longer receives security updates.

The warning follows an updated CISA advisory issued in July, which expanded the list of industrial control devices believed to be targeted in recent campaigns. In addition to previously identified Unitronics controllers, the agency said attackers have also shown interest in equipment manufactured by Rockwell Automation, Schneider Electric and Siemens. CISA has stated that the observed intrusions primarily exploit internet-exposed devices and weak security configurations rather than newly discovered software vulnerabilities.

The FBI said the investigation into the multi-state campaign remains ongoing as federal authorities continue working with affected utilities to assess the full scope of the attacks and strengthen protections for critical water infrastructure.