Cyberattacks on US water systems expand to at least seven states, officials say
Cyberattacks on US water systems have spread to at least seven states, U.S. officials say. Investigations remain in early stages and attribution is unconfirmed.
Federal officials and industry sources warned on Saturday that a series of cyberattacks on US water systems has widened to involve systems in at least seven states, according to reporting by The New York Times and statements from U.S. officials. The incidents, which targeted operational technology and control systems used by utilities, are under active federal and state investigation. Investigators said they have not yet identified a responsible party and have not confirmed any linkage to foreign governments.
Scope of the incidents
U.S. officials described the attacks as affecting a range of water facilities, including treatment plants and distribution control systems. The reported expansion across multiple states prompted concern about the resilience of municipal and regional water networks.
Officials emphasized that the investigation is in its early phase and that the list of affected locations could change as authorities gather logs and forensic data. Utility operators in some jurisdictions reported irregularities in monitoring systems but, in many cases, normal service continued while controls were isolated for inspection.
Federal and state investigations
The Department of Homeland Security, the Federal Bureau of Investigation and state cybersecurity teams have opened coordinated inquiries into the intrusions. Agencies are collecting digital evidence, issuing mitigation guidance and coordinating with water utilities to limit further exposure.
Investigators are focusing on intrusion vectors, the extent of lateral movement inside networks and whether attackers accessed operational controls. Authorities declined to disclose specific forensic findings publicly, citing the sensitivity of ongoing efforts and the risk of tipping off perpetrators.
Possible threat actors and attribution challenges
While the incidents follow a pattern seen in prior campaigns targeting critical infrastructure, officials cautioned that attribution remains unresolved. Some public reporting notes that Tehran has conducted similar operations in the past, but investigators said there is no definitive proof linking Iran to the current attacks.
Attribution in cyber incidents is complex and requires corroboration from technical indicators, intelligence sources and motive analysis. Security analysts noted that a variety of actor types — from criminal groups seeking ransom to state-sponsored teams pursuing strategic objectives — can target water systems for disruption or espionage.
Impact on water operations and public safety
To date, officials and utility operators reported limited direct impacts on water quality and public health, and there were no confirmed reports of contaminated supplies. Many operators moved to manual controls, isolated affected systems and implemented emergency procedures to maintain service continuity.
Despite those precautions, the incidents underscore the potential risks to essential services if adversaries were to gain deeper access. Experts stressed that even temporary manipulation of control parameters can pose safety risks and undermine public confidence in essential infrastructure.
Responses from utilities and regulators
Water utilities across the affected states said they are working closely with federal and state cybersecurity teams and following recommended containment and remediation steps. Some operators reported increased monitoring, patching of known vulnerabilities and temporary segmentation of networks to reduce the chance of further compromise.
Regulatory bodies urged utilities to report anomalies immediately and to review incident response plans. Several industry associations reiterated guidance for rapid detection, multi-factor authentication for control system access, and regular backups of configuration data.
Calls for accelerated cybersecurity upgrades
Lawmakers and industry leaders reacted by calling for expedited investments to modernize and secure water infrastructure. Proposals included increased federal grants for cybersecurity, mandatory reporting standards for critical system breaches, and support for workforce training in industrial control system defense.
Security professionals also recommended that utilities adopt zero-trust principles, enhance network segregation between corporate and operational environments, and perform regular third-party penetration testing. The events have renewed debate over the pace of upgrades for aging control systems across municipalities.
The expanding incidents have prompted a pronounced focus on water-sector cyber resilience, even as investigators work to piece together the full picture. Federal and state authorities said they will continue to provide technical assistance to affected utilities while seeking to determine the origin and objectives of the attackers.