Recent attacks on water systems in seven states expose vulnerabilities.
Cyberattacks targeting water systems in seven states interfered with the technology used to control wells, treatment plants and communications; no public-health impacts were reported.
New Jersey requires public community water systems with more than 500 connections to maintain cybersecurity programs, report incidents and carry cyber insurance.
Utilities also need secure equipment, tested emergency procedures and operators capable of keeping water systems running manually.
For several hours in late July, Braham, Minnesota could not draw or treat new drinking water. The city’s well and water treatment plant had gone offline, leaving the community of roughly 1,700 people dependent on the water already stored in its tower. Residents were asked to minimize water use while workers investigated the outage. The problem was not a broken pump, an electrical failure or a damaged water main; hackers had gained access to the technology used to control the system and shut down its operations.
Thankfully, water quality was not affected; operators restored the plant before the city exhausted its stored supply. However, the incident demonstrated how quickly an invisible threat can become a physical infrastructure problem. Had the outage continued, the city could have lost the ability to maintain adequate water pressure and meet demand.
Braham was not alone. More than 30 Minnesota water systems were targeted during a coordinated series of cyberattacks. In Plymouth, a city of approximately 80,000 people, the attack interrupted communications within the water system before service was restored. Other affected utilities switched to manual operations or relied on local workers to isolate compromised equipment.
Days later, Michigan reported similar activity affecting nine water systems. State officials said the systems continued operating safely and that operators addressed the problems without creating a public-health risk.
The FBI is investigating recent attacks on water systems in seven states and has not publicly identified who was responsible. The incidents occurred amid federal warnings that Iran-affiliated hackers were targeting operational technology used by water, wastewater and other critical infrastructure systems. An internal water-industry memo obtained by WIRED reportedly linked the Minnesota incidents to that campaign, although federal authorities have not formally attributed the attacks to Iran.
The attacks exposed a vulnerability; much of the equipment that collects, treats and distributes drinking water is now monitored or controlled through computer networks. And those networks can be hacked.
For New Jersey’s mix of large utilities, municipal departments and smaller community water systems, the question is no longer whether a cyberattack could reach water infrastructure. It is whether utilities have the technology, staffing and emergency plans needed to stop an intrusion from becoming a threat to the water supply.
When software controls physical infrastructure
Cyberattacks are commonly associated with stolen passwords or exposed personal information. Water utilities face those risks, but they also face another threat. An attacker who gains access to operational technology may be able to interfere with the machinery that treats and distributes drinking water.
Water systems increasingly rely on computers to monitor wells, pumps, tanks, valves, pressure and treatment equipment. Supervisory control and data acquisition systems, commonly known as SCADA systems, allow operators to observe conditions throughout a water network and make adjustments from a central location.
That technology makes complicated systems easier and more efficient to operate. It can also create an entry point if equipment is connected to the internet, protected by weak passwords or accessed through outdated remote-management software.
An attacker does not need to poison a water supply to create an emergency. Shutting down a pump could reduce pressure or leave a storage tank unable to refill. Disabling alarms could prevent operators from immediately recognizing that something is wrong. In a more serious incident, an attacker could attempt to change the amount of disinfectant or another chemical used during treatment. The U.S. Environmental Protection Agency has warned that a successful attack could disrupt water treatment, storage and distribution.
Physical safeguards, water-quality monitoring and trained operators make those outcomes more difficult to achieve. The Minnesota attacks nevertheless show that even a limited intrusion can force a utility to operate manually, depend on stored water or ask residents to conserve while the problem is investigated.
The lesson of Stuxnet
The ability of malicious software to damage physical infrastructure is not new. One of the earliest and most significant examples was Stuxnet, a sophisticated computer worm discovered in 2010 after it targeted industrial control systems associated with Iran’s nuclear program.
Stuxnet was designed to manipulate the operation of centrifuges used to enrich uranium while sending normal-looking information back to the people monitoring them. The malware reportedly caused centrifuges to operate at damaging speeds without immediately revealing that the equipment had been compromised.
Stuxnet demonstrated that malware could reach beyond files and computer screens to manipulate machinery in the physical world. Modern water plants use many of the same broad categories of industrial technology found in power plants, manufacturing facilities and other critical infrastructure. Systems originally designed to keep machinery operating reliably are now connected to networks that expose them to threats their designers may never have anticipated.
Water systems present a difficult target to defend
Protecting water infrastructure is particularly difficult because the sector is highly decentralized. Large investor-owned utilities may have dedicated cybersecurity teams and substantial technology budgets. A small municipal system may have only a handful of employees responsible for treatment, maintenance, testing, regulatory compliance and emergency response.
Many utilities also operate equipment that remains in service for decades. Replacing a working industrial controller is more complicated than updating a laptop. New equipment must be compatible with pumps, sensors and treatment processes. The installation may require temporarily taking part of a water system out of service.
Some of the most dangerous weaknesses are also among the simplest. EPA inspectors have found water systems using unchanged default passwords, shared logins and accounts belonging to former employees. Other systems lacked complete inventories of the technology connected to their networks.
More than 70 percent of the water systems inspected by EPA beginning in September 2023 were not fully complying with federal risk-assessment and emergency-response planning requirements.
Bottled water and drinks also at risk

According to the U.S. Geological Survey, approximately 50% of the water in bottled water comes from the public water supply. In New Jersey, that percentage is even higher. Aquafina (Piscataway), Dasani (Carlstadt), Pure Life (Stanhope) and others have bottling facilities that draw from public water for not only their bottled water but other bottled drinks. Coca-Cola, Molson Coors, and Arizona Beverages, and others have been the target of cybersecurity attacks as well.
New Jersey has established cybersecurity requirements
New Jersey has taken steps to address the threat. Amendments to the state Water Quality Accountability Act require public community water systems with more than 500 service connections to develop cybersecurity programs based on recognized industry standards. Systems must also report cybersecurity incidents promptly to the New Jersey Cybersecurity and Communications Integration Cell and maintain cybersecurity insurance.
The 2021 amendments removed an earlier exemption for systems that did not have internet-connected control equipment. All public community water systems exceeding the 500-connection threshold must maintain a cybersecurity program, regardless of whether their operational controls are connected to the internet. Responsible officials must certify compliance annually, and those certifications must include the cybersecurity program. NJDEP is required to audit a portion of the certifications submitted each year.
These requirements give New Jersey a framework for identifying risks and preparing for an incident, but they do not make the systems invulnerable. A written cybersecurity plan is only as effective as the practices behind it. Utilities must know what equipment is connected to their networks, remove unnecessary internet access, change default passwords, control vendor accounts, back up critical systems and practice operating without normal automated controls. Cybersecurity must also be incorporated into capital planning because some risks cannot be corrected without replacing outdated equipment.
The 500-connection threshold raises additional questions about the state’s smallest systems. Small utilities may have fewer customers, but they often have the least money and technical support available for cybersecurity. Their size also does not make them uninteresting to attackers; poorly protected systems can be attractive precisely because they are easier to reach.
Operators remain the final line of defense
Automation has changed how drinking water systems operate, but it has not eliminated the need for experienced people who understand the physical system. When technology fails, operators must be able to recognize abnormal conditions, isolate compromised equipment and keep water moving safely.
Cybersecurity therefore cannot remain solely the responsibility of an information-technology department. Engineers, operators, maintenance workers, equipment vendors and public officials all have a role in protecting the system. The Minnesota and Michigan attacks did not produce widespread water outages or contamination. Local operators and existing safeguards limited the consequences, but the incidents exposed what can happen when attackers reach the systems controlling physical infrastructure. When a computer intrusion can shut down a well or treatment plant, protecting the digital system becomes inseparable from protecting the water itself.
Sources:
American Water Works Company, Inc. (2024, October 7). Current report (Form 8-K). U.S. Securities and Exchange Commission. https://www.sec.gov/Archives/edgar/data/1410636/000119312524233300/d869346d8k.htm
Associated Press. (2026, August 1). FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems. https://apnews.com/article/77d52a1d7356e608500a1ddb0ec373a6
Cybersecurity and Infrastructure Security Agency. (n.d.). Stuxnet malware mitigation (Update B). https://www.cisa.gov/news-events/ics-advisories/icsa-10-238-01b
Greenberg, A. (2026, July 30). A leaked memo ties cyberattacks on Minnesota water utilities to Iran. WIRED. https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/
New Jersey Department of Environmental Protection. (2021). Water Quality Accountability Act amendments guidance. https://www.nj.gov/dep/watersupply/pdf/wqaa-amendments-guidance-2021.pdf
U.S. Environmental Protection Agency. (2024, May). Enforcement alert: Drinking water systems to address cybersecurity vulnerabilities. https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities
U.S. Government Accountability Office. (2024). Critical infrastructure: EPA urgently needs a strategy to address cybersecurity risks to water and wastewater systems (GAO-24-106744). https://www.gao.gov/products/gao-24-106744
U.S. Geological Survey. (2023, November). Proportions of bottled water facilities using different water sources in U.S. states and selected territories. https://www.usgs.gov/media/images/proportions-bottled-water-facilities-using-different-water-sources-us-states-and
Just-Drinks.com. (2024, September). Modern supply chains open up cybersecurity weak spots. https://www.just-drinks.com/features/drinks-industry-modern-supply-chains-open-up-cybersecurity-weak-spots/



