U.S. water utilities are facing a widening cyber campaign that now spans up to 12 states, according to new reporting that builds on an earlier FBI/EPA warning centered on seven states. The latest ABC News report, citing multiple sources, says possible intrusions have now been reported in at least a dozen states, making this the broadest known coordinated cyber campaign against municipal water systems in recent memory.
Officials have not publicly confirmed the total number of states affected or any attribution (remaining at seven), but the timing, targeting and scale have pushed the story well beyond the initial single-state incident.
The treatment plants and utilities involved have, so far, largely held the line. Reporting indicates some sites were forced to operate manually or deal with temporary disruptions to monitoring and control, but there has been no public evidence of widespread contamination, sustained loss of water service, or a systemic failure of treatment processes. Minnesota officials, the first state reportedly affected in this wave of attacks, have said affected systems were operating safely, and federal warnings have focused on tightening exposure rather than responding to a collapse in water quality.
That suggests the operational impact has been real enough to trigger emergency response, but not yet severe enough to cause the kind of public-health crisis that would turn this into a full-blown infrastructure emergency.
The technical picture of the attacks seems like a story set on repeat.
The same playbook, three years running
The reported targets are exposed operational technology assets: PLCs, SCADA-linked devices, remote-access systems and other internet-facing control equipment that often sit at the awkward intersection of IT convenience and OT risk. In several reports, attackers appear to have used basic access methods rather than sophisticated tradecraft, changing passwords or tampering with device settings to lock operators out or disrupt local control. That is enough to force a switch to manual operations and to shake confidence in the integrity of a utility’s control environment.
It also shows the precarious state of security at the nation's thousands of water treatment plants. Marcus Tommy, founder of Toronto cybersecurity and compliance firm MALTO, said, “The target set is thousands of small water utilities running control gear that get instructions from the open internet. These systems, depending on their age and hygiene, can often have default or weak credentials, and that exposure does not end when a single incident does,” he said.
Related:


James Turgal, VP of global cyber risk and board relations at Optiv, agreed that the attackers appear to be directly exploiting those exposed programmable logic controllers and remote-management interfaces rather than launching highly sophisticated, utility-specific malware. “That makes the model scalable, wherein the threat actors are utilizing AI to scan the Internet to identify vulnerable devices, reuse proven access techniques, and create physical disruption at utilities that often have limited cybersecurity resources,” Turgal said.
Turgal adds that the attacks highlight how baseline OT hygiene remains uneven and, in some utilities, dangerously inadequate. “A PLC that can be discovered and administered directly from the public Internet is not merely an IT vulnerability; it can provide a pathway to pumps, pressure controls, alarms and treatment processes,” Turgal said.
Tommy commented that he and others in the field see these attacks as having the same shape that showed up in the Unitronics PLC attacks on US water systems in late 2023, and in the earlier Oldsmar incident. “Whether this wave is one actor or several running the same playbook, the opportunity will continue to be there until the underlying exposure gets fixed,” he said.
While many suspect the attacks are a continuation of earlier Iranian attacks on PLCs and water treatment plants, authorities are not yet providing attribution. “The human want is to blame someone and to do it quickly, but we must be careful here. Pinning this on a specific group in the first few days is usually a guess, and that guess often changes as more evidence comes in,” Tommy said.
“What the FBI and CISA are saying about the exposure itself is much more relevant and urgent, and it lines up with years of warnings about control systems being left on the internet. The powers that be must act on the exposure now. A foreign government and an opportunist scanning the internet for exposed systems reach the same open controller, and the fix is the same either way,” Tommy added.
For critical-infrastructure defenders, the story is not just that water systems were hit. It is that the attack surface remains overly exposed, the response still varies widely by utility, and a campaign that started as a regional alarm is now being described as national. And it’s also a warning to other critical infrastructure sectors.
“Municipal water utilities have become a frequent target because of their limited cybersecurity resources; they are not unique. Similar vulnerabilities exist across multiple critical infrastructure sectors, including manufacturing, oil and gas, transportation, and building automation,” said Raed Albuliwi, chief product officer at Xona.

