This isn't a data theft operation — it's hackers reaching directly into the valves. In a fresh public safety advisory, the FBI and EPA report that since July 27, 2026, water treatment and wastewater facilities across seven US states have been breached, with operator-level systems thrown into disarray. Some affected utilities gave the FBI blunt accounts of what happened: water pressure dropped, and flooding started on-site.

The attack's entry point was the Programmable Logic Controller (PLC) — the industrial controller that actually runs water plant operations. The FBI's advisory lays out the method in detail: hackers remotely accessed devices exposed to the internet, then went in and changed the IP addresses and passwords, effectively locking the original operators out of their own systems — unable to monitor or control their own plants. The FBI specifically flagged that dropping water pressure isn't just "weaker flow" — it can allow untreated groundwater to seep into the pipes, meaning the operational impact runs far deeper than the numbers suggest on the surface.

The official response guidance is heavily engineering-focused: set up secure gateways and firewalls so control systems aren't directly exposed to the open internet, and replace weak passwords while using access control lists to restrict which devices can communicate with each other. In other words, this wave of attacks largely succeeded because these PLCs were already sitting open on the internet — the door was left unlocked.

Before this seven-state incident broke, Minnesota had already sounded the alarm — over the past week, more than 30 municipal water utilities in the state were breached. NBC News reports that the attack signatures resemble tactics previously used by Iran-linked actors, though law enforcement has not confirmed state-level involvement. Wired says it has seen a memo directly linking the Minnesota attacks to Iran; the memo, circulated to members by the water industry group WaterISAC, cites the Minnesota Fusion Center describing this "ongoing malicious cyber activity affecting drinking water systems statewide" as matching a hacking pattern previously described by the US Cybersecurity and Infrastructure Security Agency (CISA) — which warned back in April that Iran-linked hackers were targeting critical infrastructure sectors, including water systems.

Whether Iran is directly involved remains under investigation. For full details, refer to the original advisories from the FBI and EPA, along with reporting from Wired and NBC News.