Tech · Water attacks double
U.S. Water Attacks Doubled to 12 States as Hackers Hit Exposed Controllers
From 7 states to 12 in five days, intruders reached exposed water controllers — but formal attribution and the full forensic picture are still missing.
Transcript · loading player
12 is the number that changed everything. In five days, the count of states reporting intrusions into U.S. water and wastewater systems jumped from seven to at least 12, roughly doubling a campaign that had already forced small towns onto manual operations 6 9 2 5. That is not a statistical quirk or a recount. It is a widening map of places where the pumps, valves and chemical feeds that deliver drinking water were reached from the outside.
The starting point was Minnesota. On July 26-27, 2026, a coordinated attack struck more than 30 municipal water systems across the state, forcing operators to run plants by hand and triggering a multi-agency federal-state response 7 9. Investigators described access through Rockwell Automation MicroLogix programmable logic controllers reached via cellular modems installed by third-party integrators, with changes to IP addresses and passwords 7. The available reporting text breaks off just as it begins to describe what happened next inside at least one controller — “in at least one case al...” — leaving the most consequential technical detail unconfirmed in the file provided 7.
How Minnesota became the warning
By July 31, the FBI and the Environmental Protection Agency were warning utilities nationwide after attacks on municipal systems in at least seven states, following the breaches of the 30-plus Minnesota facilities 9. NBC News reported that warning as the first federal acknowledgement of scale, and it set the baseline against which everything after would be measured 9. Seven states was already an unusual federal alert for the water sector, a sprawling patchwork of thousands of locally run systems with uneven staffing and security budgets.
Five days later, that baseline broke. On Aug. 4-5, officials confirmed water and wastewater systems in at least 12 states had reported intrusions, up from the seven the FBI had disclosed five days earlier 6 2. SecurityWeek reported on Aug. 5 that Georgia was confirmed as an attacked state after Clayton County reported a pump station disruption, citing an ABC News count of at least 12 states with only a handful named 5. The Record also reported the expansion to 12 states with South Dakota and Georgia announcing incidents 2. A Metro Atlanta boil advisory was under investigation in the same window, a reminder that even a pump-station disruption can quickly become a public-health question at the tap 6.
National coverage followed the expansion. On Aug. 6, CNN and CBS News covered the dozen-state attacks, with CBS reporting officials warning that hackers are exploiting a “particularly vulnerable industrial computer” 3 4. The phrase matters because it points away from exotic zero-days and toward known, exposed control hardware. Four days later, Dark Reading reported the attacks had reached at least a dozen states via “ill-secured, Internet-exposed PLCs,” describing low-complexity attacks on industrial controllers 10. In plain language: machines built to open and close valves and run pumps were reachable from the internet, and intruders walked in.
Attribution without an attribution
Who ordered that walk-in remains unresolved, and the language in the reporting file is deliberately hedged. The Record described the campaign as “allegedly linked to Iranian hackers” 2. Dark Reading said the intrusions were “possibly linked to the Iranian government” 10. Cybersecurity Dive, writing on Aug. 20, called the spree “suspected to be the work of Iran-linked threat groups” 8. None of the provided source texts contains a formal U.S. government attribution to Iran or any other state 2 10 8.
That gap between suspicion and formal blame is structural, not just cautious lawyering. Small water utilities often lack the forensic logging and network monitoring needed to preserve evidence across thousands of systems, which makes high-confidence attribution difficult without additional intelligence. The result is a campaign that looks coordinated from the victim count — Minnesota’s cluster, then a coast-to-coast add-on of states — but remains unattributed in the public record. The sources do not agree on a single formulation because there is not yet a single finding to agree on, only three different ways of saying the investigation points toward, but has not proven, an Iranian link 2 10 8.
The stakes of that ambiguity were already driving a policy argument by mid-August. The Independent on Aug. 7 framed the attacks as a “wake up call” after years of warnings, quoting analysts on unprepared states 11. By Aug. 20, Cybersecurity Dive reported growing support for stricter oversight and funding, with the attack spree still described only as suspected Iran-linked work 8. The sequence tells its own story: first manual operations in Minnesota, then a federal warning, then a doubling of affected states, then the familiar Washington turn toward money and mandates 7 9 6 8.
Readers should also understand what this article does not claim. The provided reporting texts do not verify several dramatic details that circulated alongside the early coverage. They contain no mention of a group claiming responsibility under any name, no verbatim FBI statement about modified controller project files governing chemical dosing, pump timing or pressure regulation, and no statistic about visibility into any foreign hacking targets 2 3 4 5 6 7 8 9 10 11. The Minnesota file hints at controller tampering before it is cut off mid-sentence, but the full claim is not visible 7. A slug reference to New Jersey appears in one URL, but the visible snippet text does not confirm that state’s status 6. The truncated texts also contain no quotable official statements that can be reproduced 2 3 4 5 6 7 8 9 10 11.
Known
Unknown
- No formal U.S. government attribution has been shown in the provided reporting.
- No verified account of which controller files were changed or whether changes were meant to cause harm.
Next
- Whether federal funding and oversight proposals advance after the Aug. 20 push.
- Whether full forensic detail from Minnesota clarifies what intruders did inside the controllers.
Where
- 1Minnesota
- 2Clayton County, Georgia
- 3South Dakota
- 4Metro Atlanta
Sources
- U.S. Water Cyber Attacks Double in a Week; FBI Finds Altered Control Logic
- Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents | The Record from Recorded Future News
- Why US water systems are vulnerable to foreign cyberattacks | CNN Politics
- America's water systems are getting hacked amid security gaps: "No one guarding these systems" - CBS News
- Water Sector Cyberattacks Reportedly Hit at Least 12 States - SecurityWeek
- Water Cyberattack Campaign Expands to 12 States — Metro Atlanta Boil Advisory Now Under Investigation | WaterVerge
- Minnesota Cyberattack Hits Over 30 Water Systems; Cellular… | DeafNews
- What we know so far about the hacking campaign against US water systems | Cybersecurity Dive
- Hackers targeted municipal water systems in 7 states this week, FBI says
- Multistate Water System Attacks Widen, Iran Suspected
- Attacks on America’s ‘super vulnerable’ water systems should be a wake up call after years of warnings, cybersecurity experts say | The Independent
Revision log
- r1First published.