Cyberattacks Target Water Systems in 12 States, FBI Investigates
At least a dozen states report cyber intrusions targeting water systems, with the FBI urging enhanced security measures.
TheDigitalArtist/Pixabay
At least 12 states across the U.S. are currently experiencing cyber intrusions targeting their water and wastewater utilities, multiple sources confirmed on August 4, 2026. These attacks, suspected to be linked to Iranian hackers, aim to disrupt water operations by manipulating passwords and disabling alarms, raising alarm among federal and state authorities.
Scope and Nature of the Cyberattacks
Water and wastewater utilities in a dozen states have reported suspicious cyber activity involving attempts to compromise critical control systems. The intrusions reportedly include changing system passwords and disabling key safety alarms, which could potentially blind operators to ongoing issues. Despite the severity of these attempts, there have been no widespread disruptions to water supplies or wastewater processing as local operators have managed to address the incidents swiftly.
Suspected Source and Government Response
Officials point to Iran as the primary suspect in these cyberattacks, although no official confirmation has been released. The FBI is spearheading the investigation and is coordinating closely with affected states to mitigate risks. Authorities have urged water utilities to disconnect their control systems from the internet where feasible and to implement manual control procedures to maintain safety if automated systems are compromised.
Michigan’s Role and Preparedness
Michigan, one of the states affected, has been actively monitoring the situation. The Michigan State Police, in partnership with the Department of Environment, Great Lakes, and Energy, are communicating with municipal water systems statewide. They are advising facilities using vulnerable software to strengthen cybersecurity measures and adhere to federal guidance. So far, Michigan reports no public health threats and confirms that all water systems continue to operate safely under local oversight.
Preventive Measures for Water Utilities
Given the evolving cyber threat landscape, the FBI has recommended several precautionary steps for water utilities, including:
- Disconnecting control systems from the internet when possible
- Using break systems to segment networks and limit access
- Training staff to revert to manual operational controls if automated systems fail
- Regularly updating and patching software to close vulnerabilities
These measures are critical to protecting the nation’s water infrastructure from cyber threats that could jeopardize public safety.
Outlook and Ongoing Investigation
While no immediate harm has come from the cyberattacks, the incidents underscore the growing risk to essential infrastructure from state-sponsored hackers and cybercriminals. Federal and state agencies continue to collaborate on enhancing defenses and sharing intelligence. Water utilities across the country are urged to remain vigilant and proactive in their cybersecurity efforts to prevent potential future attacks.
As investigations proceed, officials emphasize that residents can continue to trust the safety and reliability of their water services. The situation remains under close watch, with updates expected as more information becomes available.


