AT LEAST SEVEN STATES, SIX (OR MORE) MISSING NAMES

What the government is—and is not—telling Americans about the cyberattacks on U.S. water systems


By Jonathan Brown

The Federal Bureau of Investigation disclosed something extraordinary on July 30. Since July 27, water and wastewater utilities in “at least seven states” had reported cyber incidents involving internet-accessible industrial controllers. Some of those incidents had degraded water operations. Reported consequences included lost pressure and flooding.

The FBI has yet to identify all of the states currently affected by the cyber attacks.

It did not say how many utilities were involved nationally, whether the incidents were all part of one coordinated campaign, which communities experienced pressure loss or flooding, or where boil-water notices had been issued. It did not identify an attacker.

As of July 31, only one of those seven states has been publicly confirmed: Minnesota. Even there, state officials have acknowledged that more than 30 community water systems were targeted, while only four municipalities—Braham, Plymouth, South St. Paul, and Maple Plain—have publicly identified themselves.

The resulting picture is simultaneously alarming and strangely incomplete. The United States has experienced confirmed malicious access to physical water-control equipment across at least seven states. Operators have been locked out of controllers. Device addresses and passwords have been changed. At least one victim discovered discrepancies in the ladder logic used to control physical processes. Yet an American trying to determine whether any of this occurred in his or her own state cannot do so from the federal notice.

That information gap deserves examination. There are legitimate operational, investigative, and legal reasons not to identify critical-infrastructure victims in the first days of an active campaign. There are also understandable concerns about unnecessary public alarm. But secrecy has costs of its own. It can deprive neighboring utilities of geographic warning, complicate public-health risk assessment, and leave a vacuum that rumor, exaggeration, and foreign propaganda are happy to fill.

The central question is not whether the federal government should publish a map of vulnerable controllers or expose the architecture of individual water plants. It plainly should not.

The question is narrower: when the government tells the public that water operations have been disrupted in seven states, should it identify those states?

WHAT IS ACTUALLY CONFIRMED

The national facts come from a July 30 public-service announcement issued by the FBI and Environmental Protection Agency.

According to that notice, malicious actors have been remotely accessing internet-facing Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers. These are small industrial computers that can monitor or control pumps, valves, tanks, lift stations, treatment processes, and other physical equipment.

The actors changed device internet addresses and activated or altered passwords. That caused operators to lose visibility into the affected equipment and, in some cases, lose control of its functions. At least one organization reported altered PLC project files after discovering discrepancies in ladder logic across several sites.

That last detail deserves more attention than it has received. Ladder logic is not merely a configuration screen. It is executable process logic: the instructions that determine what equipment does when sensors report particular conditions. A changed password can lock out an operator. Changed logic can change the process itself.

The FBI also warned that multiple victims shared similar network arrangements supplied by third parties. That could explain how an attacker moved from one success to many—not necessarily by breaching one vast national system, which does not exist, but by finding a repeatable weakness deployed across numerous utility customers.

The documented physical consequences include pressure loss and flooding. The FBI explicitly warned that loss of pressure can allow untreated groundwater to enter pipes. The severity at each facility depended on what the compromised controller did, whether it merely monitored equipment or actively controlled it, and whether the utility could continue through manual operation.

These are not hypothetical vulnerability claims. They are reported operational effects from actual intrusions.

CISA issued a parallel warning saying attackers had changed passwords to lock out operators and changed device addresses to disconnect controllers. It said the activity had led to boil-water notices and sustained manual operation, and emphasized that utilities of all sizes were being targeted.

The wording matters. The FBI said utilities in seven states had “reported incidents.” It did not say that one actor had conducted one coordinated attack across all seven. It did not say that every report involved the same access path, the same controller configuration, or the same operational result. Minnesota has described its activity as a coordinated cyberattack, but that state-level conclusion cannot automatically be extended to the six unnamed states.

Nor has the federal government formally attributed the current incidents to Iran.

U.S. officials told several national outlets that investigators were examining a possible Iranian connection. CBS reported that investigators were also considering whether someone might be imitating Iranian activity to intensify tensions during the U.S.–Iran conflict. That is an especially important caveat. Similar tools, targets, and timing can support an attribution assessment, but they do not prove identity.

A Water Information Sharing and Analysis Center communication obtained by WIRED reportedly said the Minnesota Fusion Center regarded the Minnesota incidents as aligned with an earlier Iran-affiliated campaign. WaterISAC later stressed that it had not itself made an attribution assessment.

Iranian-affiliated actors are a credible leading possibility. CyberAv3ngers and related Islamic Revolutionary Guard Corps activity have previously targeted exposed industrial controllers, including water-sector devices. Another Iranian-linked persona, Handala, has conducted destructive and influence-oriented operations and recently made claims concerning American water infrastructure.

But capability, intent, and precedent are not forensic proof of responsibility for this particular attack. The current public position remains: suspected, not confirmed.

THE FOUR CITIES THAT SPOKE

The clearest public descriptions came not from Washington but from four Minnesota municipalities.

In Braham, a city of roughly 1,700 people, malicious activity disabled computerized operating controls and temporarily shut down the city’s well and treatment plant. The city relied on water stored in its tower while public-works employees restored operations. The plant was reportedly back online in less than two hours, and the city briefly asked residents to conserve water.

That is a contained incident, but not a trivial one. A community’s active source and treatment capability went offline because someone reached its operating technology. The water tower provided a physical reserve; local personnel provided the recovery capability. Had the outage continued, occurred during high demand, coincided with fire response, or affected a system with less stored capacity, the consequences could have been considerably more serious.

Plymouth reported the loss of communications with two water towers and multiple wastewater lift stations. The affected equipment used cellular connectivity. Crews continued operating through manual procedures, and the city said water levels and quality were not affected. Communications were subsequently restored.

South St. Paul said a cybersecurity incident affected automated controls supporting portions of its water utility. Established contingency procedures allowed public-works staff to maintain normal water and wastewater operations.

Maple Plain also reported an incident involving automated water-control functions. The city declared a local state of emergency to accelerate its response, maintained service through contingency procedures, and later terminated the emergency after stabilizing the system.

All four cities said their drinking water remained safe.

These municipal statements illustrate what resilience looks like in practice. Cybersecurity products did not single-handedly save the water supply. Stored water, manual operating procedures, experienced staff, local emergency authority, physical failsafes, and the ability to disconnect or reconfigure equipment kept cyber interference from becoming a public-health disaster.

They also illustrate the limits of the phrase “more than 30 systems were impacted.” Minnesota IT Services clarified that “impacted” meant investigators had confirmed malicious activity involving a system’s technology. It did not mean that every community lost water service or experienced a dangerous physical event.

That distinction should be retained. Thirty confirmed intrusions are serious enough without turning them into thirty drinking-water emergencies.

WHAT COULD HAVE HAPPENED

Water systems contain layers of physical, chemical, mechanical, and procedural protection. Compromising one controller does not grant magical dominion over an entire regional water supply. Many controllers perform limited functions, and treatment plants generally employ alarms, local controls, testing, storage, and human oversight.

But it would be equally misleading to dismiss these attacks as the digital equivalent of graffiti.

Water pressure is a public-health control. Distribution systems are designed to maintain positive pressure so that water flows outward through leaks rather than allowing contaminated groundwater or sewage to enter. A pressure collapse can reverse that relationship. Even after pressure is restored, a utility may need to flush lines, disinfect affected sections, collect samples, and issue a precautionary boil-water advisory.

Unauthorized pump operation can drain tanks, overflow basins, flood equipment rooms, damage pumps through unsuitable operating conditions, or create pressure transients capable of stressing aging pipes. Wastewater lift-station interference can produce overflows, environmental releases, and exposure to untreated sewage.

Manipulation of treatment controls presents a different class of risk. Chemical feed rates, filtration, disinfection, turbidity management, and source selection are not functions that should ever be described casually. An attacker who can modify actual controller logic, falsify what appears on an operator’s screen, or disable alarms has moved beyond knocking a device offline. That attacker may be able to conceal developing process conditions from the people responsible for stopping them.

A July 22 update to the broader joint federal advisory on Iranian-affiliated PLC activity described previous cases in which attackers manipulated project files and human-machine-interface displays. In some incidents, changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without warning operators.

There is no public evidence that the current seven-state incidents contaminated drinking water. There is no confirmed report of illness, poisoning, or a successful attempt to manipulate chemical treatment in this wave.

The seriousness lies in the demonstrated path toward physical consequence: remote access to exposed control equipment, changes to configuration and logic, loss of operator control, pressure loss, flooding, and the need for manual intervention. The campaign has already crossed the boundary from accessing computers to affecting engineered processes.

WHY THE OTHER STATES MAY BE WITHHELD

The most defensible reason for withholding victim locations is operational security.

An active investigation is still underway. Naming a state can help researchers, journalists, and the public identify likely utilities through local notices, procurement records, internet-exposure databases, controller fingerprints, meeting minutes, and social-media posts. That process could reveal facilities still engaged in containment or using similar vulnerable arrangements.

Attackers often know which systems they accessed, but they may not know which accesses were detected, which victims reported them, or how much investigators have connected. Publicly naming every affected jurisdiction can provide adversaries with a free damage assessment.

It can also expose relationships among victims. The FBI’s warning that several organizations used similar third-party network configurations suggests that investigators may be examining a common integrator, telecommunications provider, remote-access design, or equipment template. Premature disclosure could alert an attacker that this shared dependency has been recognized.

There is also a strong victim-cooperation argument.

The federal government depends heavily on voluntary reporting from critical-infrastructure operators. Small utilities may hesitate to contact the FBI or CISA if doing so means immediate national publicity, political blame, insurance complications, regulatory scrutiny, or a permanent association between the community’s name and “unsafe water”—even when the water was never unsafe.

Confidentiality encourages reporting. Reporting helps the government discover patterns across victims that no single municipality could see.

Federal law reflects that policy. The Critical Infrastructure Information Act protects qualifying critical-infrastructure information voluntarily submitted to covered federal agencies, including the identity of the submitting entity, when the statutory requirements are met. It permits the government to issue public warnings while protecting the source and entity-specific information.

That statute should not be treated as a blanket explanation for every withheld name. Not every FBI incident report is necessarily submitted or designated under that program. But it demonstrates that Congress deliberately created a system in which the government can aggregate infrastructure warnings without exposing the organizations that supplied the underlying information.

Justice Department media policy also weighs public access against privacy, public safety, and the government’s ability to administer justice. An unresolved counterintelligence or criminal investigation will naturally disclose less than a completed prosecution supported by affidavits and forensic exhibits.

A further possibility is simple uncertainty. Some of the seven-state reports may still be under validation. A utility may have lost communications and discovered a changed controller address without yet proving who changed it or whether the event belongs to the same campaign. Naming a state too early could imply a level of coordination or attribution the evidence does not support.

All of these are legitimate reasons for restraint.

None of them completely answers why the states themselves cannot be identified after affected utilities have isolated their equipment and public-health agencies have assessed local conditions. There is a meaningful difference between naming a state and naming a particular unmanned pump station, controller model, cellular provider, and exposed internet address.

A state-level disclosure could improve defensive awareness without publishing an attacker’s targeting guide. Utilities in an affected region may share integrators, procurement programs, telecommunications services, watershed relationships, and mutual-aid arrangements. Knowing that confirmed activity has occurred nearby can change how urgently an operator reviews alarms, staffing, remote connections, and physical measurements.

THE “PREVENT PANIC” QUESTION

Governments plainly consider public reaction when communicating about drinking water. They should. Water warnings can produce immediate behavior: hoarding bottled water, emptying store shelves, overwhelming municipal phone lines, closing schools or businesses, and placing sudden demand on alternative supplies.

A loosely worded national warning that “hackers compromised water systems in your state” could cause residents to assume their tap water is contaminated when the actual event involved a communications outage at a wastewater lift station hundreds of miles away.

From that perspective, the federal communication follows a recognizable public-safety principle: tell people what they need to do. The FBI notice was directed primarily at operators. Where residents did not need to boil water, conserve, or stop using the system, local officials repeatedly said so. Where a cyber incident creates a condition with significant potential for serious short-term health effects, federal drinking-water regulations allow a Tier 1 public notice, generally within 24 hours, as determined by the responsible drinking-water authority.

A cyber intrusion by itself does not automatically make drinking water unsafe. Public notification should be based on the resulting health condition, not merely the presence of an unauthorized login.

But “preventing panic” should not become a convenient substitute for evidence-based public communication.

There is no public statement from the FBI, EPA, or CISA saying the states were withheld to prevent panic. It would therefore be irresponsible to present panic control as the established motive. It is better understood as a plausible secondary consideration within a larger response strategy dominated by victim confidentiality, investigative integrity, and infrastructure security.

There is also a paradox. Excessive vagueness can increase anxiety.

“Seven states, but we will not say which ones” invites fifty states to wonder whether they are included. It encourages speculative lists, recycled reports of unrelated incidents, misidentification of utilities, and claims that the government is concealing a nationwide poisoning event. An Iranian influence operation could exploit exactly that uncertainty, exaggerating the reach or physical consequences of an intrusion without providing proof.

Trust is itself a critical infrastructure. Once the government releases a number as specific as seven, it assumes some responsibility for explaining what that number means.

Were there seven states with confirmed malicious access, or seven containing utilities that reported suspicious events? Did all seven experience operational effects, or only some? Were the pressure loss, flooding, and boil-water notices part of the July 27–30 incidents, or were some drawn from a broader period of observed activity? Do investigators assess a common actor, a common configuration, or merely a common class of exposed devices?

Those distinctions could be published without identifying individual plants.

IS THE PRESS IGNORING THE STORY?

No. But the coverage remains shallower than the event warrants.

Reuters, the Associated Press, CBS News, ABC News, The New York Times, WIRED, local Minnesota outlets, and numerous cybersecurity publications have reported the attacks. Reuters prominently reported the FBI’s seven-state disclosure and the physical consequences of pressure loss and flooding. CBS specifically noted that the bureau had not identified the states. WIRED obtained the restricted WaterISAC communication connecting the Minnesota investigation to previously reported Iran-aligned activity.

This is not a press blackout.

It is, however, a story with severe reportability constraints. National reporters can quote the FBI’s “at least seven states,” but the FBI will not name six of them. Local reporters cannot find a municipality that has not issued a notice, placed an emergency declaration on an agenda, spoken to residents, or produced another public record. Industry organizations may possess more detail but operate under information-sharing rules designed specifically to keep victim reports within trusted circles.

There is also no single national water operator to question. American drinking-water infrastructure is radically decentralized. Thousands of municipal, regional, private, and special-district systems operate under different state authorities, public-record laws, staffing levels, and communication practices. A reporter cannot call one headquarters and obtain a national incident list.

The open press is therefore repeating the outer boundary of what federal officials have released. That repetition can create the appearance of broad corroboration when many articles ultimately trace back to the same FBI statement.

BCG searched national coverage, state and local reporting, water-industry reporting, cybersecurity publications, municipal notices, and publicly indexed utility alerts for credible identification of another affected state. As of publication on July 31, that search found no independently verified identification of any state beyond Minnesota in connection with this specific wave.

It did find earlier and unrelated water-sector incidents, including the June claims against California Water Service and prior incidents elsewhere. Those cannot responsibly be folded into the FBI’s seven-state count without evidence. Similar timing, Iranian branding, or a water-sector target is not enough.

The result of the search is therefore negative but meaningful: Minnesota is confirmed; six states remain publicly unidentified. Anyone publishing a list of those six should be required to show a utility notice, state statement, public-health advisory, named official, or other primary evidence.

WHAT WATER OPERATORS SHOULD DO NOW

The immediate response is not simply “patch the PLC.”

The affected MicroLogix equipment includes aging and end-of-life technology for which ordinary patch assumptions may not apply. The demonstrated access also involves exposure and configuration failures that cannot be solved by firmware alone.

First, utilities should identify every PLC, human-machine interface, cellular modem, engineering workstation, and remote-access gateway that is reachable from an external network. Internet-facing controllers should be removed from direct exposure. Required remote access should pass through a controlled gateway or jump host with strong authentication, logging, restricted source access, and a documented operational purpose.

Cellular connections require particular attention. “Not connected to the office internet” does not mean isolated. A modem with a publicly reachable address can create a direct path to field equipment while remaining invisible to conventional enterprise-security inventories.

Second, operators should preserve evidence before rebuilding. Export running logic, configurations, event logs, modem records, firewall data, and human-machine-interface records. Record device modes, controller addresses, password state, firmware, serial numbers, and physical switch positions. Photograph screens and panels where necessary.

Third, running controller logic must be compared with a known-good engineering baseline. The FBI specifically warned of ladder-logic discrepancies. A clean-looking device and a restored password do not prove the process logic is trustworthy. Backups must also be checked before restoration; an old but already modified project file can reintroduce the problem.

Fourth, facilities should verify the physical process independently of the display. Tank levels, pressure, flow, valve position, pump state, chemical residuals, turbidity, and other safety-relevant values should be checked through local instrumentation, portable measurement, or redundant channels. If attackers can manipulate operator displays or alarms, the screen cannot be accepted as ground truth.

Fifth, utilities should be ready to operate manually—but should not improvise manual control during an emergency. Manual procedures must be written, practiced, staffed, and bounded by safe operating limits. The Minnesota response succeeded because local personnel could use established contingency procedures. A binder that has not been tested on the current equipment is not resilience.

Finally, potentially affected organizations should contact the FBI, CISA, their state drinking-water authority, EPA support channels, WaterISAC, and the equipment manufacturer. A report that seems insignificant locally may contain the one address, timestamp, or configuration detail that connects several victims.

WHAT THE PUBLIC SHOULD DO

Residents should follow instructions from their own water utility and public-health authority.

The national cyber warning is not a national boil-water advisory. Boiling water unnecessarily does not assist an investigation and can create avoidable burdens for households, medical facilities, restaurants, and emergency services.

If a utility issues a boil-water, do-not-drink, conservation, or service-interruption notice, residents should follow the exact local instruction. “Boil,” “do not drink,” and “do not use” notices are not interchangeable.

Residents can also subscribe to municipal emergency alerts now rather than waiting for a crisis. Water utilities should make their official notification channels easy to locate, and local governments should clearly distinguish operational cyber incidents from actual water-quality hazards.

The absence of a public notice does not prove that no cyber incident occurred. It generally means officials have not identified a condition requiring action by customers. That is a meaningful distinction, though it does not answer the broader policy question about transparency.

WHAT SHOULD BE DISCLOSED NEXT

The government does not need to choose between total secrecy and publishing an adversary’s reconnaissance package.

A tiered disclosure would be more credible.

During active containment, federal agencies can protect utility identities, technical configurations, indicators tied to individual victims, and investigative methods. They can still say which states contain confirmed incidents, how many reports have been technically validated, how many caused operational effects, whether public-health notices remain active, and whether the events are assessed as one campaign or several.

After containment, the government should publish an anonymized technical account explaining the access path, repeated third-party configuration, controller state, operational consequences, and successful safeguards. State and local authorities should disclose affected communities once doing so no longer creates a material response risk, unless a specific legal or safety concern justifies continued withholding.

Eventually, the public deserves an after-action accounting. How many utilities were compromised? How many lost control rather than visibility? Where did pressure loss and flooding occur? Were any treatment or safety functions altered? How long did manual operations continue? What common architecture allowed the activity to scale? Were earlier federal warnings delivered to the affected systems, and did those systems have the resources to act on them?

Those are accountability questions, not requests for offensive detail.

For now, the most accurate conclusion is narrower and more troubling than many headlines.

Attackers remotely accessed water-control technology in at least seven states. They changed controller configurations, locked out operators, and caused physical operational effects including pressure loss and flooding. More than 30 Minnesota systems were affected, but only four Minnesota communities have publicly identified themselves. Six other states remain unnamed. Iran-affiliated actors are under investigation, but no formal attribution has been announced. No contamination or injury has been confirmed.

The systems held because operators detected problems, switched to manual procedures, relied on stored water and physical safeguards, and restored control before limited disruptions became emergencies.

That is good news.

It is not evidence that the attacks were harmless. It is evidence that the last defensive layers worked.

The public can tolerate that truth. It can understand that an intrusion occurred without assuming every faucet is poisoned. It can understand that some technical information must remain protected while an investigation continues.

What it should not be asked to accept indefinitely is a map containing seven affected states and six blank spaces.

Principal sources consulted:

FBI and EPA, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions,” July 30, 2026.

CISA, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” July 30, 2026.

CISA and federal partners, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure,” AA26-097A, updated July 22, 2026.

Minnesota IT Services, statements on the coordinated attack against community water systems, July 28–30, 2026.

City of Plymouth, “Communications Restored at Plymouth Water Facilities,” July 27, 2026, subsequently updated.

City of Maple Plain, cybersecurity incident and emergency-termination notices, July 27–29, 2026.

City of South St. Paul, statement concerning automated water-utility controls, July 27, 2026.

City of Braham public statements and local reporting concerning the temporary plant outage, July 27, 2026.

Reuters, “U.S. Cyber Defense Agency Warns Hackers Are Increasingly Targeting Water Systems,” July 30, 2026.

Associated Press, “Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers,” July 30, 2026.

CBS News, “U.S. Investigating if Iran Was Behind Cyberattack on Water Systems in Seven States,” updated July 31, 2026.

WIRED, “A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran,” updated July 31, 2026.

United States Code, 6 U.S.C. § 673, protection of voluntarily shared critical-infrastructure information.

Code of Federal Regulations, 40 C.F.R. §§ 141.201–141.202, drinking-water public-notification requirements.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.