Crosswords Sudoku and Comics
Science

Hackers Hit Water Facilities in Seven States, FBI Warns of Flooding Risk

Cyberattacks since July 27 have disrupted water pressure and caused flooding, with investigators examining possible ties to Iran.

Ilham Aliyev has attended the opening ceremony of the Shamкirchay water treatment facility
Ilham Aliyev has attended the opening ceremony of…      Water Treatment Facility    Press Service of the President of the Republic of Azerbaijan / Wikimedia Commons (CC BY 4.0)
By Free News Press Editorial Team
Published August 1, 2026 at 1:31 PM PDT

Seven water and wastewater utility companies across the United States have been hit by cyberattacks since July 27, 2026, according to a public service announcement from the FBI and the Environmental Protection Agency. The attacks have caused degraded water operations, including loss of water pressure and flooding.

According to Engadget, the FBI has identified how the hackers are getting in. They are targeting Programmable Logic Controllers, which are devices that manage automated systems inside water facilities. Once inside, the attackers remotely access internet-facing devices and then change IP addresses and passwords, cutting off utility operators from their ability to monitor and control their own systems.

The consequences go beyond inconvenience. The FBI warned that pressure loss in water systems could allow untreated groundwater to seep into pipes. That kind of contamination represents a much larger threat to public health than simple low water pressure alone.

The FBI and EPA are now advising utility companies to take immediate steps to protect their systems. Those steps include installing secure gateways and firewalls to prevent direct internet exposure, setting stronger passwords, and using access control lists to limit which devices can communicate with each other inside their networks.

The seven-state attacks come alongside a separate but related wave of intrusions. More than 30 municipal water facilities in Minnesota were infiltrated by bad actors over the past week. According to NBC News, those attacks carried characteristics consistent with Iranian involvement. Law enforcement has not confirmed that finding, but the reporting adds weight to earlier federal warnings.

A memo reportedly sent to members of the Water Information Sharing and Analysis Center, an industry group for water utilities, described the situation in sharper terms. WaterISAC reportedly said that the Minnesota Fusion Center, a state-level intelligence-sharing entity, issued a warning that the ongoing malicious cyber activity targeting public drinking water systems in Minnesota was consistent with a hacking campaign previously described by the U.S. Cybersecurity and Infrastructure Security Agency. CISA had issued its own warning in April that Iran-affiliated hackers were targeting water infrastructure, among other sectors.

The FBI has confirmed it received reports of both flooding and pressure loss directly from victim utilities. Investigators are still working to confirm whether Iran is behind the Minnesota attacks, and whether those incidents are connected to the broader seven-state campaign.

The Broken Bow (fresh) Water Treatment Facility in Broken Bow, OK on Thursday, Apr. 9, 2015.
The Broken Bow (fresh) Water Treatment Facility i…      Water Treatment Facility    Lance Cheung / Wikimedia Commons (Public domain)