Cybersecurity · Critical infrastructure · Analysis

On Thursday, the FBI gave the water-sector cyberattack story its first national count. Utilities in at least seven states had reported incidents since July 27, and some had suffered operational problems.
SecurityWeek’s latest reporting identifies Minnesota, Michigan, South Dakota, and Georgia; three states remain unnamed. Minnesota officials said malicious activity touched technology at more than 30 water and wastewater systems. Michigan reported nine. Rapid City disclosed an incident at a wastewater lift station. ABC News reported Georgia’s inclusion, although federal officials have yet to publish a state-by-state list.
Most coverage has treated this as an Iran story, understandably so. Iranian-affiliated actors have targeted industrial controllers and water systems before, and the current geopolitical motive is plain. Iran may well be responsible here.
The public evidence has not caught up with that level of certainty. Meanwhile, the FBI warning contains a less dramatic finding with more practical value: similar third-party network setups may have allowed the attacker to repeat the same move across multiple utilities.
Seven states, but no public attribution
The FBI and EPA’s July 30 notice gives a fairly detailed account of the mechanics. Attackers reached internet-facing Rockwell Automation MicroLogix 1100 and 1400 programmable logic controllers. They changed IP addresses and passwords, leaving operators without monitoring and, in some cases, control. Reported effects included lost pressure and flooding. One organization found that the controller logic differed across several sites.
The notice calls them “malicious cyber actors.” Iran is not named.
A separate federal advisory first issued in April and updated July 22 attributes a broader campaign to an Iranian-affiliated group. It covers other Rockwell controller families, including CompactLogix and Micro850 devices, along with possible targeting of Siemens equipment and other manufacturers. The advisory is relevant background, but it does not publicly connect the Minnesota incidents or the full seven-state group to those operators.
Reporting about a nonpublic Fusion Center alert shared through WaterISAC supplied the Minnesota link. The alert reportedly said the activity was “aligned” with an earlier Iran-linked campaign. Investigators will take that seriously, but alignment is a broad description. The public has not seen shared infrastructure, matching session records, a common tool set, or controller forensics tying the cases together. WaterISAC has also said that it did not assess attribution.
The leak may also have a cost. Restricted sharing channels depend on utilities trusting that an early, incomplete incident report will stay with the people authorized to act on it. Public disclosure can warn peers, but mishandling TLP:AMBER material may make the next operator slower to report. That tradeoff has received little attention.
There are two separate claims here: Iran has targeted this class of system before, and Iran carried out these particular incidents. Only the first is established in the public record.
My reading of the public record: Iranian involvement is plausible and deserves active investigation. Attribution remains open until a competent authority publishes an event-specific assessment or reviewable technical evidence ties the affected sites to one Iranian operation. The evidence permits suspicion, not a public attribution.
The third-party connection
The FBI offers a possible explanation for how one actor moved quickly across many utilities: similarities in third-party network setups may have created a repeatable opening.
There is no public evidence that an integrator was compromised or that every affected utility shared a vendor. The concern is more basic. An integrator can reuse the same remote-access pattern, cellular template, or support arrangement across customers. A configuration mistake that looks local then appears in several states.
Small water utilities rarely design and operate every layer of their control environment. They depend on integrators, equipment vendors, managed service providers, telecom carriers, and remote specialists to keep pumps, wells, treatment systems, and lift stations running. For many utilities, there is no practical alternative.
Trouble starts when the provider becomes the only party that understands the connection. The utility should know who approved the route, which people can use it, whether sessions are logged, and how access can be revoked without losing operational support. It also needs its own copy of the last approved controller program. Those details tend to surface only after a provider changes hands, a technician leaves, or an incident forces everyone to reconstruct the design.
Those details are harder to illustrate than a foreign flag. They are also where the size of an incident is determined.
The technical path, as described by the FBI, was ordinary. The account mentions no zero-day exploit, custom malware, or leap across a segmented network. It describes internet-facing controllers, remote configuration changes, altered passwords, and lost visibility. The Bureau’s first recommendation is straightforward: take the controllers off the public internet and place remote access behind a monitored gateway.
A state-linked group does not need a novel exploit to be dangerous. Reachable controllers and weak access controls are enough to create local disruption, national anxiety, and days of concern about water safety.
The operational effects are serious. Loss of pressure can create a contamination pathway. Flooding can damage equipment and the surrounding environment. A changed controller program can outlive the first response if operators restore communications but never compare the running logic with an approved baseline.
“At least seven states” describes geographic spread, not operational consequence. The public record mixes attempted targeting, confirmed access, configuration changes, service disruption, and public-health effects. Coverage that rolls them into one count makes it difficult to tell what happened at each site.
Manual operation limited the damage
Operators kept many of these systems running by hand.
Michigan said all nine reported systems continued to operate safely. Minnesota communities used contingency procedures. Rapid City said its water and wastewater systems were not placed in jeopardy. Manual capability, local process knowledge, and practiced fallbacks helped contain the incidents after attackers reached operational technology.
Safe operation and full recovery are different findings. Normal pressure says little about whether an attacker still has valid credentials or whether the running controller logic matches the last approved program. A city can accurately report that drinking water remained safe while the forensic work continues.
A sound recovery preserves the current state as evidence, compares it with an approved baseline, revokes exposed credentials, and validates process safety before remote access returns. Reconnecting too early can recreate the condition that caused the incident.
What the 2018 law actually required
Congress did act. The America’s Water Infrastructure Act of 2018 amended Section 1433 of the Safe Drinking Water Act. Community drinking-water systems serving more than 3,300 people must assess risk and resilience, including the security of electronic and automated systems. They must build an emergency response plan that addresses cybersecurity, certify completion to EPA, and repeat the review every five years.
The mandate governs planning and certification. It sets no federal minimum for the controls running at a plant or remote site.
EPA prescribes no standard, method, or tool for these assessments and plans. Compliance does not require proof that controllers are off the public internet, cellular modems appear in the asset inventory, vendors use named accounts, or remote sessions pass through a monitored gateway. Community systems serving 3,300 people or fewer are exempt from certification. Non-community drinking-water systems and wastewater systems fall outside Section 1433 as well.
EPA receives a certification statement, while the utility retains the assessment and response plan. The agency can inspect and enforce afterward, but it does not routinely approve the analysis during certification. The statute also supplies no fixed deadline for correcting every weakness and no dedicated funding for every capital need. The result is better visibility into whether a process exists than into the current condition of the OT network.
Minnesota closed part of the gap in 2024. Every community public water system using operational technology must now complete an annual cybersecurity assessment and certify it to the Minnesota Department of Health. The utility may assess itself, and MDH does not require a copy of the findings. Significant issues can be discussed during sanitary surveys and assigned remediation timelines. The state reviews more frequently than the federal program, but the assessment remains a point-in-time exercise.
Some systems have also failed the requirements that do exist. In a May 2024 enforcement alert, EPA said more than 70 percent of the systems it had inspected since September 2023 violated basic Section 1433 requirements. That was an enforcement-inspection sample, not a representative national survey. Inspectors found default passwords, shared staff logins, former employees who retained access, and incomplete risk assessments or response plans. EPA reported more than 100 enforcement actions since 2020.
EPA tried to extend cybersecurity review to routine sanitary surveys in March 2023, then withdrew the interpretation seven months later during litigation. Today, larger community drinking-water systems face federal planning requirements, some states go further, and much of the remaining sector works from voluntary guidance. There is no single enforceable federal technical baseline for water and wastewater OT.
An assessment can document risk without proving that every cellular route is known or every remote session is mediated and logged. That gap between documentation and the live network is central to these incidents.
Nothing in the public record shows that a named victim violated the law. Reporting does not map each facility to its population, system classification, assessment result, or remediation status. It does explain how a formally assessed risk can remain exposed in operation.
Cellular links belong on the external boundary map

At least one Minnesota city said its incident was limited to equipment connected through cellular communications. The statement establishes cellular involvement at that site. It tells us nothing about whether the modem was compromised or whether other victims used the same route.
A cellular modem is easy to treat as a private field connection, closer to telemetry radio than internet service. At the IP layer, though, it is a routed data path run by a mobile carrier. External reachability depends on the access-point configuration, assigned address, carrier route, firewall rules, port mappings, VPNs, and any vendor tunnel.
Some deployments receive a public or statically mapped address and can be reached directly. Others sit behind carrier-grade NAT, which ordinarily blocks unsolicited inbound traffic. A private APN offers stronger separation, provided someone governs its gateways, allowed peers, credentials, and logs. Vendor appliances can also open outbound tunnels to cloud brokers. In that design, the important controls sit in the vendor portal rather than at the field IP address.
In a July 30 snapshot, Censys found 4,148 internet-exposed Rockwell/Allen-Bradley hosts. Fifty-nine percent were on networks operated by Verizon Business, AT&T Mobility, or T-Mobile USA. The data does not identify water utilities, vulnerable devices, victims, or the last-mile connection type. It does confirm that thousands of industrial devices in carrier-operated address space answered public internet scans.
An annual assessment can miss a live route when the documentation is split between organizations. The control-system diagram includes the PLC and SCADA workstation. The IT inventory ends at the city firewall. A carrier provisioned the modem years earlier, an integrator manages it, and its SIM and address never made it into either inventory. Staff may describe the device as “not on the internet” even when it answers a scan from outside.
The FBI and EPA recommend strong authentication and logging on cellular modems, along with private APNs, site-to-site VPNs, Zero Trust Network Access, or other mediated designs. Whatever the product, unsolicited remote connections should terminate at a controlled gateway rather than the PLC.
Small utilities need more than another checklist
Calling this a patching failure puts too much responsibility on the plant operator.
The Government Accountability Office counts close to 170,000 water and wastewater systems in the United States. Many operate with small staffs, aging equipment, and budgets already committed to water-quality work. GAO has also documented gaps in federal authority over parts of the sector.
States and federal agencies need to help utilities find exposed operational assets, replace or isolate unsupported controllers, and share monitoring and response capacity. Procurement and service contracts should require named accounts, time-limited access, utility approval for live sessions, usable logs, tested backups, configuration handoff, and an emergency access path the utility controls.
That work can begin before the attribution question is settled.
Questions the public record still cannot answer
Officials and reporters can help establish whether these incidents form one technical campaign by answering a few specific questions:
Which sites had the MicroLogix 1100 or 1400 controllers named by the FBI, and what did those controllers operate?
How was each controller reached: a public or mapped cellular address, private APN, VPN gateway, vendor tunnel, or another support path?
Were the SIM, modem, carrier account, APN, gateway, and cloud broker present in the utility’s asset and boundary inventories?
Did victims share an integrator, network template, carrier, remote-access product, credential pattern, or controller project?
For each event, what was confirmed: targeting, access, a configuration change, operational disruption, or a public-health effect?
Do synchronized logs tie the sites to common infrastructure? Did the latest required assessment identify the route and assign a remediation deadline? After recovery, did the utility compare its running controller logic with the approved baseline?
The answers may establish an Iranian operation, a shared third-party design weakness, or several unrelated causes. Each result calls for a different response.
What remains after attribution
Iran poses a real threat to industrial systems. The mistake is treating attribution as the last question rather than the first finding in a longer investigation.
The FBI has described a repeatable path to exposed operational equipment and warned that similar third-party setups may increase an attacker’s success. The path will remain after this campaign ends unless utilities and their providers close it.
The larger unresolved issue is money. The United States has nearly 170,000 water and wastewater systems. Many small operators cannot replace unsupported controllers, redesign remote access, add continuous monitoring, and retain trained security staff from existing rates. Those costs compete with pipes, treatment equipment, lead service lines, PFAS compliance, and the daily work of delivering safe water.
Washington has been willing to require assessments and publish guidance. It has not fully funded the controls, architecture changes, and system replacements that those assessments may identify. If government expects a minimum security baseline, federal and state budgets will have to cover much more of the cost. Local ratepayers cannot carry a national critical-infrastructure program on their own.
Utilities still need to know every remote route and vendor account, retain approved controller baselines, and prove that recovery was safe. But a plant manager cannot replace old hardware or build a monitored access gateway with another checklist.
This is the part of the water-cybersecurity debate that receives the least attention because the price is politically uncomfortable. The country can fund the required controls, or it can continue accepting uneven protection across thousands of small systems. Until that choice is made honestly, whoever found this path will not be the last.
Sources and evidence note
This article distinguishes confirmed public statements from reported attribution and analytic inference. Public-source cutoff: August 3, 2026.
SecurityWeek: U.S. water cyberattacks extend beyond Minnesota, August 3, 2026.
FBI/EPA: malicious actors targeting internet-facing water-sector PLCs, July 30, 2026.
Associated Press: Michigan joins Minnesota in reporting incidents, August 1, 2026.
Joint Cybersecurity Advisory AA26-097A, issued April 7 and updated July 22, 2026.
WaterISAC statement on leaked information, July 30, 2026.
GAO: persistent cybersecurity threats to the water and wastewater sector, May 21, 2026.
EPA: AWIA Section 2013 and SDWA Section 1433 requirements, updated May 14, 2026.
EPA: how utilities certify risk-and-resilience assessments and emergency response plans.
EPA: enforcement alert on drinking-water cybersecurity vulnerabilities, May 2024.
EPA: withdrawal of the sanitary-survey cybersecurity memorandum, October 11, 2023.
Minnesota Department of Health: annual OT cybersecurity assessments.
Censys: cellular concentration in exposed industrial-controller hosts, July 30, 2026.
About the author
Tim McAllister is a Regional Field CTO in DigiCert’s Office of the CTO. He works with enterprises and manufacturers on digital trust, device identity, PKI, and the operational problems that appear where cybersecurity policy meets real infrastructure.