The FBI and Environmental Protection Agency are warning U.S. water and wastewater operators that malicious actors are targeting internet-connected control devices after utilities in at least seven states reported incidents since July 27, 2026.

The warning matters beyond the affected towns because the targeted equipment helps operators monitor and control pumps, pressure, treatment and other industrial functions. Federal officials said some activity degraded water operations, though separate reporting from Minnesota and national outlets has not identified confirmed drinking-water contamination.

The practical takeaway is narrow but important: water systems should not leave operational technology directly exposed to the public internet, and communities should expect more attention on whether small utilities have the staff, funding and backup plans to run manually during cyber incidents.

What changed

In a July 30 public service announcement, the FBI and EPA said attackers were targeting operational technology devices, including Rockwell Automation Allen-Bradley MicroLogix 1400 and MicroLogix 1100 programmable logic controllers. Programmable logic controllers, or PLCs, are industrial computers that can help run equipment in water and wastewater facilities.

Federal officials said attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused a loss of monitoring and control functionality. The FBI said reported operational effects have included pressure loss and flooding. Pressure loss can matter because it may create conditions where untreated groundwater could seep into pipes, depending on the system and local conditions.

The agencies did not publicly name the affected states in the alert. The FBI said water and wastewater utilities in at least seven states had reported incidents, and it said the impact depended on what function the compromised device supported and whether the utility could move quickly to manual operations.

Why Minnesota became the clearest example

Minnesota has become the public example of the broader warning. The Associated Press reported that more than 30 Minnesota water systems were recently targeted and that state officials and the FBI were investigating the source. Some affected communities asked residents to limit water use temporarily, and officials said there were no major disruptions to water supply or quality.

The Guardian reported Tuesday that problems in Minnesota ranged from low-pressure water flow to boil-water notices, while also reporting that there had been no reports of drinking-water contamination. That distinction is important: the cyber risk is serious because it touches essential infrastructure, but the confirmed public impact so far appears to be operational disruption rather than a verified contamination event.

What officials say utilities should do now

The FBI and EPA guidance is aimed mainly at system owners and operators, not ordinary household water customers. The agencies recommend removing PLCs from direct internet exposure and putting remote access behind secure gateways, firewalls and monitored access controls.

They also recommend strong and unique passwords, strict access-control lists that allow only expected communications, logging on connected modems, review of PLC project files for unauthorized changes, and planning to replace or isolate end-of-life hardware that no longer receives security updates.

A cropped utility-control scene shows a MicroLogix-style controller near a valve wheel and blank manual-operations checklist.
Federal guidance tells water utilities to preserve the ability to operate manually if automation is disrupted.

One recommendation may be the most practical for small towns: practice manual operations. The FBI and EPA said utilities should maintain business-continuity and disaster-recovery plans, test fail-safe mechanisms and backups, and make sure staff can restore safe operations if a digital system is locked, altered or taken offline.

What remains unconfirmed

The agencies have not publicly attributed the recent activity to a specific government, group or criminal operation. Some news organizations, citing unnamed officials or outside cybersecurity experts, have pointed to possible Iranian-linked activity, and CISA had previously warned about Iranian-affiliated targeting of internet-connected operational technology. But the FBI and EPA alert itself uses the broader term malicious cyber actors.

That matters because attribution can be slower and more uncertain than incident response. For readers, the confirmed story is not who gets blamed first. It is that water utilities reported incidents across multiple states, that attackers were able to reach devices that should not have been exposed, and that federal agencies are telling operators to reduce internet exposure immediately.

What residents can watch

Most residents do not manage the equipment named in the alert, so the next useful step is local awareness rather than panic. If a town or utility issues a boil-water notice, pressure advisory or water-use request, residents should follow the local notice and the utility's official updates. If there is no local notice, the federal alert alone does not mean a household's water is unsafe.

For local officials and utility boards, the question is more direct: whether the water system knows which PLCs and modems are online, whether remote access is mediated and logged, whether default or reused passwords have been eliminated, and whether operators can run safely by hand if automation becomes unavailable.

The broader policy issue is likely to keep growing. Many small water systems have limited cybersecurity staff, older equipment and tight budgets. The latest warning shows how a technical configuration problem can become a public-service problem when the device controls water pressure, treatment or wastewater operations.

The bottom line: the confirmed risk is not a nationwide water-safety order. It is a federal warning that attackers are probing a weak point in local infrastructure, and that utilities have immediate steps to reduce exposure before the next incident turns a digital intrusion into a longer service disruption.