Forgot your password?
typodupeerror
United States Government Security

Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says (nbcnews.com) 47

An anonymous reader quotes a report from NBC News: Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.

The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation. A spokesperson for Minnesota's information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had "resulted in boil water notices and sustained manual operations," though it did not say where.

[...] The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions. [...] The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.

Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says

Comments Filter:
  • by Revek ( 133289 ) on Friday July 31, 2026 @04:14PM (#66266762)
    I seem to recall a exploit designed to trash process controllers that was made to destroy Iranian infrastructure. I'm just STUX about the detail. Maybe someone on the NET can find the details.
    • From US, or from the Israelis? You are correct about stuxnet deliberately targeting the industrial controller they were using for (checks notes)... uranium enrichment? Sounds like we're both right: "On 1 June 2012, an article in The New York Times reported that Stuxnet was part of a US and Israeli intelligence operation named Operation Olympic Games, devised by the NSA under President George W. Bush and executed under President Barack Obama."
    • by gtall ( 79522 )

      Ya, those dumb Iranians would NEVER have thought of this idea by themselves.

    • by Slayer ( 6656 )

      STUXNET attack was aimed at a nuclear "research" facility, not at a municipal water supply.

  • Apparently, Trump thinks that the governor did it. Why he should do such a thing is beyond me.
  • by fahrbot-bot ( 874524 ) on Friday July 31, 2026 @04:38PM (#66266792)

    ... an attack that had hallmarks of Iranian meddling, according to a law enforcement official.

    Trump puts the blame on Minnesota Gov. Tim Walz. From Trump blames governor, not Iran, for Minnesota cyberattack [usatoday.com]

    "They blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent," Trump said [w/o presenting any evidence] at a July 31 Cabinet meeting at the Camp David presidential retreat in Maryland. "I would blame it on Minnesota and the governor, the corrupt governor of Minnesota."

    Governor Walz has a different theory (also from that article):

    "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," Walz said in a statement in response to the president's remarks. "This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran."

    Walz blamed Trump's Department of Government Efficiency, the former government-slashing agency once led by tech executive Elon Musk, for gutting the U.S. Cybersecurity and Infrastructure Security Agency. "DOGE took an axe to CISA and left the U.S. exposed to cyberattacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it," Walz said.

    As seven states have been impacted, either Iran or Governor Walz has been very busy ... :-)

    • by Locke2005 ( 849178 ) on Friday July 31, 2026 @04:47PM (#66266806)
      Well, if the Governor is responsible for network security in his state, then isn't the president ultimately responsible for network security in all states? Did Trump just admit his administration is incompetent again?
    • "They blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent," Trump said [w/o presenting any evidence] at a July 31 Cabinet meeting at the Camp David presidential retreat in Maryland. "I would blame it on Minnesota and the governor, the corrupt governor of Minnesota."

      Governor Walz has a different theory (also from that article):

      "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," Walz said in a statement in response to the president's remarks. "This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran."

      How about just don't connect critical infrastructure to the internet in the first place?! It's not rocket surgery.

      • How about rather than trying to be a smart ass, or the president trying to blame a Democratic governor for an Iranian state-sponsored attack, the president actually does his job?

        Is that too much to ask?

        Ask like a president - be a leader, not a whiner. Take charge. Tell your cyber-Tsar to have a meeting with the state governors, or appropriate representatives, and get appropriate protection measures in place for all critical infrastructure (not just water treatment plants).

        Yeah, it's not rocket science, unle

      • by _merlin ( 160982 )

        I read that at least some of the attacks involved attacking wireless communication. You could avoid that by just wiring your SCADA system.

      • Does the Colonial Pipeline attack ring a bell? Stop putting this crap on the Internet.
    • by abulafia ( 7826 ) on Friday July 31, 2026 @07:00PM (#66267010)
      This is Piggie leaving Americans exposed to foreign attack during a war.

      He's already been denying [politico.com] emergency funds to states that didn't vote for him.

      Now he's literally spreading propaganda about the source of a foreign attack against US citizens. Blue states are on their own, without the tools they'd need to actually act like a sovereign being attacked.

      MAGAts need to remember this when President AOC forcibly desegregates the South again. Motherfuckers are going to be lucky we still let them be part of the country - I'm increasingly OK with building a wall at the northern Texas border at this point. (You're such big bad he-men? Enjoy negotiating with Mexico as a tiny neighbor.)

      • by HiThere ( 15173 )

        I don't think a woman can be elected. This isn't a statement that one shouldn't be, it's and estimation of the voters.

        • I don't think a woman can be elected. This isn't a statement that one shouldn't be, it's an estimation of the voters.

          Adding that 49.8% of voters did re-elect a man found liable of sexual assault, who undeniably, obviously, constantly lies, over the 48.3% who wanted a black woman and 36% (90 million) of eligible voters who did not vote at all. I'll add that the first and third stats are pretty sad. On the upside, we didn't get those sky-high prices and new Middle-East wars Trump promised Harris would give us - hooray! /s (*heavy-sigh*)

          • by HiThere ( 15173 )

            It's not clear that "48.3% who wanted a black woman". It's quite plausible that a reasonable fraction of those just didn't want Trump.

            • It's not clear that "48.3% who wanted a black woman". It's quite plausible that a reasonable fraction of those just didn't want Trump.

              That's fair; I should have worded that bit better. There can be different reasons people vote for/against someone or some thing.

          • I don't think a woman can be elected. This isn't a statement that one shouldn't be, it's an estimation of the voters.

            Adding that 49.8% of voters did re-elect a man found liable of sexual assault, who undeniably, obviously, constantly lies, over the 48.3% who wanted a black woman and 36% (90 million) of eligible voters who did not vote at all. I'll add that the first and third stats are pretty sad. On the upside, we didn't get those sky-high prices and new Middle-East wars Trump promised Harris would give us - hooray! /s (*heavy-sigh*)

            Which oddly enough it almost exactly the same percent that voted the same way in 1996. And while gas has come up, it's still 25% cheaper than it was 3 years ago, high prices which have a lot more to do with the inability of Congress to balance a checkbook than who is in the White House - because as Congress loves to remind everyone - they control the purse. But same old crap, just a different day, and different people complaining about it / doing it. We really need a viable third party (or more), cause a

  • They prompted to "test controlling my water supply."

    -nothing to see here
  • by Locke2005 ( 849178 ) on Friday July 31, 2026 @04:46PM (#66266804)
    Trumpers: "Those Iranian goatfuckers will never be able to hack our 21st century American data centers!" Iranian IT experts who have been fighting against Israeli hackers for years: "This should be pretty easy by comparison! They're nowhere near as secure as the Israelis!"
  • Are we sure it wasn't Claude or chatgpt?
    • Are we sure it wasn't Claude or chatgpt?

      It was Al-Clauda, a Claude based AI with some supplemental training materials.

  • by Arrogant-Bastard ( 141720 ) on Friday July 31, 2026 @05:37PM (#66266878)
    The attackers are assessing defenses: what are they, what are their response times, what do the responses look like, etc. The real attack(s) will come somewhere else and will be much more thorough, because they'll be informed by the intelligence gathered from these probes. Given the state of US infrastructure security ("miserable") any competent attacker should be able to do a great deal of physical, economic, and societal damage rather quickly...

    ...which is one of many, many reasons why starting a war with a capable adversary without any kind of plan was a profoundly stupid and reckless idea.
    • It's a good thing we don't have a bunch of privatized water systems consolidated to just a handful of large companies. Because it would be really bad if they were targeted next.

  • It is not obvious to me why a water system needs to be on the net. I understand having remote controls of various valves and pumps and so forth, but can't all of that be on a private local network?
    • Yes, you can. If you want full physical separation, it gets pricey. Back in late 1960s, early 1970s, the Bell System did it for their switches. They were a regulated monopoly, so they earned 12% on whatever money they spent on network infrastructure. So far as I know, no private company has done the full separation thing since.
  • by laughingskeptic ( 1004414 ) on Friday July 31, 2026 @06:30PM (#66266956)
    These attacks prove that leaving individual cities to fend for themselves on the open commercial internet is a complete failure of public governance. The fact that small towns in these states are actively fighting off what U.S. officials believe are foreign, state-sponsored adversaries like Iranian hackers highlights the sheer absurdity of our decentralized approach. Cybersecurity inherently scales; while Fortune 100 companies protect thousands of endpoints for pennies per user using enterprise-grade automation, resource-starved municipalities are forced to survive with tiny budgets and skeleton IT crews.

    South Dakota is the only state that endeavors to give a protected network to its municipalities. Five years after Oldsmar Florida exposed this exact vulnerability, we are watching the exact same script play out as utility operators across the country are forced to switch to manual workarounds to keep their treatment plants online. For a fraction of the millions spent reacting to these disruptions, states could easily pool their buying power to build a single, hardened network infrastructure for every municipal utility. The refusal of almost all of our states or the federal government to implement a sane, centralized defense model like South Dakota's means American critical infrastructure remains an open, fragmented playground for cybercriminals.

    And an "I told you so": I stated in the first post on this when Minnesota was the only state named that the rest of the states were simply incapable of noticing. Now we have 7 states -- the attacks are likely against all.
  • Seven out of 50 is remarkably small. I am shocked they did not get more.

    Now, I guarantee you, those affected will realize that the cybersecurity are not joking around. They will improve security.

    And about a year later their new security protocalls will spread to the other 53 states. By the time the next group tries this crap, it will be much harder to do.

    • "...their new security protocalls will spread to the other 53 states." Whoa, by then we'll ten new states? Let's see, Canada has ten provinces. So as a requirement for becoming part of the US, they'll require that each individual province become a separate state.

      (No, I don't really think this--Canada is doing fine on its own, and Trump has--fortunately--zero chance of annexing Canada. Most likely you hit the 5 key when you intended to hit the 4 key. :), since you gave the correct current number of state

      • Yes. That's exactly what I meant. I definitely did not misspell 43 as 53 because I was touch typing.

  • I seem to remember a well-documented SCADA hacking break-in somewhere in Australia where they reversed sewage pumps. Years ago, if not decades now. Complacency?

  • It was also morally evil and a war crime, but it turns out to have been a really dumb move too. Who’d have thought?

    https://www.middleeasteye.net/... [middleeasteye.net]

    https://en.wikipedia.org/wiki/... [wikipedia.org]

    Sure, sure Iran lies. But there’s independent reports showing both incidents happened. The question of deliberateness is separate. But given Trump and Hegseth’s proclivities, I think it would be odd if they *did* hold back.

  • 2009: Hot or Not: SCADA security is hot [archive.org]

    “Theoretically, SCADA systems should not be exposed to the internet, but I fear they increasingly are being connected to IP networks. In most industries, SCADA systems should be completely air-gapped from data networks, thus significantly mitigating the risk of attack. However, more installations are using SCADA to manage their systems remotely, or even connect the systems to an internet-enabled corporate network to collect and analyze data. As this trend con
  • President Trump Accuses Minnesota Governor Tim Waltz Of Domestic Terrorism!

Try `stty 0' -- it works much better.

Working...