in

FBI and EPA Warn Hackers Breached Water Systems in 7 States

Federal agencies this week warned that municipal water systems in at least seven states were hit by cyber intruders who accessed internet‑facing control equipment and in some cases degraded operations. The FBI and the Environmental Protection Agency put out a public service alert telling water utilities to act now to stop more damage. This is not a rehearsal — it is a real wake‑up call for every town that still has critical controls on the public internet.

FBI and EPA: What the alert says about the water system cyberattacks

The joint FBI/EPA public service announcement says hackers targeted programmable logic controllers — the little computers that run pumps, valves and monitors at water plants. Utilities in multiple states reported intruders changing device settings, locking operators out, and in some cases causing loss of pressure or forcing plants to run in manual mode. The notice repeats a simple point: don’t expose industrial control gear to the open internet.

Why Minnesota matters — and why this could be bigger

Officials in Minnesota reported a spike of attacks that affected more than 30 community water systems. Those local incidents drew national attention and helped push the FBI/EPA alert. While not every attack caused a boil‑water order or contamination, losing automated control of pumps and monitors creates real safety risks. The agencies warned operators to assume internet‑facing controllers are high risk and to follow basic steps to isolate and secure them.

Attribution and the politics — Iran, federal guidance, and a blame game

Cybersecurity agencies, led by CISA, have pointed to Iranian‑affiliated threat actors in a related advisory that described similar tactics. That technical analysis found attackers probing and changing PLC project files and passwords. President Donald Trump pushed back publicly, saying Iran “should be so lucky” and blaming Minnesota’s leadership instead. The tug between technical attribution and political sound bites won’t help the towns that need stronger defenses right now.

What should be done — practical fixes and who should pay

The good news is the fixes are not magic — remove direct internet access, lock down remote modems, use unique strong passwords, enable logging, and practice manual operations. The bad news is some local governments have ignored basic cyber hygiene for years. Federal agencies can hand out guidance and tools, but local leaders must fund and enforce the basics. If a small town values its water supply, it should stop treating cybersecurity like a luxury line item.

We need action, not noise. City managers, governors and Congress must stop pointing fingers long enough to inventory controllers, isolate them from the internet, and invest in real resilience. Otherwise the next cyberattack won’t just throw pumps into manual mode — it will throw voters into panic, and that will be on the officials who had the chance to fix this and didn’t. Fancy advisories are helpful, but lockable hardware and accountable leadership win the day. Lock the door — and stop pretending a public IP address is plumbing.

Written by Staff Reports

Leave a Reply

Your email address will not be published. Required fields are marked *

Mullin's DHS rule will drive away STEM talent and cost billions

Mullin’s DHS rule will drive away STEM talent and cost billions

IEA: Emergency Oil Stocks Near Collapse After Biden Reserve Use

IEA: Emergency Oil Stocks Near Collapse After Biden Reserve Use