Home / Uncategorized / Cyberattacks on water utilities in the US now reach seven states and New York responds with $9 million

Cyberattacks on water utilities in the US now reach seven states and New York responds with $9 million

What started as a local incident in Minnesota has become the most serious coordinated campaign against critical infrastructure of the year in the United States. Attacks on drinking water and sanitation systems no longer affect a single state: at least seven are involved, and the first political response with money on the table has just arrived from New York, with more than $9 million distributed among 153 water systems.

Thirty treatment plants attacked in forty-eight hours

The starting point is dated: on July 26 and 27, attackers struck the operational technology (OT) of more than 30 community water systems in Minnesota. The state’s IT Services activated the statewide incident response protocol, something that is not done for just any failure.

Among the affected localities are Braham, Plymouth, South St. Paul and Maple Plain. The most serious case was Braham: the attackers turned off the operational controls, which stopped the well and the treatment plant, and the municipality had to take the facility out of service temporarily. In the rest, the automatic control functions were interrupted and contingency manual procedures had to be used.

The official message has been insistent on one point: the drinkability of the water was never compromised. That is true, and it is worth repeating. But it is also true that that nuance does not comfort too much when a remote third party is capable of stopping a treatment plant from the other side of the world.

From one state to seven

The campaign did not stay in Minnesota, as was to be expected. Michigan has officially confirmed malicious activity in “a small number” of communities, insisting that all systems continued to operate safely. Rapid City, in South Dakota, reported an incident in one of its wastewater pumping stations. And according to ABC News, Georgia is also on the list. The names of the other affected states remain undisclosed.

Why all fingers point to Iran

The US government has not formally attributed the attacks, but suspicion is unanimous in the sector. Federal investigators have spent days examining the possible Iranian involvement, and a report from the Minnesota Fusion Center — distributed by WaterISAC with the TLP:Amber marking, that is, not intended for public dissemination — concludes that the activity is “aligned” with campaigns previously linked by Washington to Iran.

It would not be the first time. Iranian groups have a long history of attacks against industrial control systems, including water facilities in Israel compromised through vulnerable cellular routers. And there is the most revealing technical clue of this campaign: one of the Minnesota municipalities specified that the incident was limited to “equipment connected through cellular communications”.

The hole: controllers hanging directly off the internet

On July 30, CISA published an alert that describes the pattern bluntly. The agency observes “a significant increase” in actors attacking programmable logic controllers (PLCs) in the water sector. The method is not sophisticated: they change the passwords to lock out operators and disconnect the PLCs by modifying their IP address. The result has been boil water advisories and sustained manual operation for days.

The firm Censys calculates that there are about 10,000 Rockwell, Siemens and Schneider controllers exposed to the internet. And CISA adds an uncomfortable detail for organizations that believe they are safe: a large part of those connections are cellular modems installed by operators, providers or integrators that never reached the asset inventory nor appear in routine attack surface scans.

The three measures CISA asks for

  • Disconnect the PLC from the internet. Remote access must go through VPN or gateway, never directly to the controller.
  • Enable passwords and change the factory ones. It remains, in 2026, the most repeated and most ignored piece of advice.
  • Limit access through an IP allowlist, restricted to known engineering laptops and other critical OT assets.

The agency also recommends making sure you have a clean copy of the PLC image before disconnecting it, precisely in case someone has already changed the password.

New York pays in advance

Governor Kathy Hochul announced on Monday the distribution of more than $9 million through the SECURE program, aimed at cybersecurity assessments and implementing improvements in 153 drinking water and sanitation systems. The amounts reach up to $50,000 per assessment and $100,000 per implementation, with free technical assistance added.

The money serves to make municipal companies comply with the minimum standards the state introduced in March: mandatory training for certified operators, incident notification, risk-based protections and the designation of a cybersecurity officer in the largest systems. “These threats are real and growing,” said Hochul. No New York facility has been publicly linked to the campaign; the spending is preventive.

The takeaway for this side of the Atlantic

It is worth not reading this as a US problem. The victim profile — a small municipal company, with OT managed through consumer remote access tools or exposed controller interfaces — is repeated all over Europe, and certainly in Spain, where thousands of supplies depend on town councils with tight budgets and no dedicated security staff.

The NIS2 directive already obliges these entities to raise their level, but paper compliance does not disconnect a controller from the internet. Minnesota’s lesson is that a soft target can have enormous public consequences, and that the asset inventory — knowing which modem an external integrator installed six years ago — is today a first-class security measure.