Water-system cyberattacks have now hit seven US states, and the FBI is looking at Iran
Michigan joined Minnesota in reporting hacks on its water systems, with federal officials citing at least seven states. The FBI is investigating a coordinated campaign.
There is one thing almost nobody thinks about protecting and everybody uses before breakfast: the water in the tap. In the United States, that blind spot has just become expensive. Michigan reported cyberattacks on nine of its water systems on Saturday, days after Minnesota counted more than thirty. Federal officials say the problem now spans at least seven states.
The FBI is investigating what it calls a coordinated campaign against one of the most basic categories of American infrastructure. Nobody has been publicly blamed, but the context is hard to ignore: the FBI, CISA and other agencies had issued an advisory the week before warning that Iranian hackers were focused on exactly this — water and wastewater systems.
How do you actually attack a water system?
Not through the website. According to CISA’s alert, attackers go after programmable logic controllers — the small industrial boxes that open valves, start pumps and dose chemicals — and change their passwords to lock operators out of their own equipment. It is unglamorous and highly effective: you do not need to break anything, you just take control away from whoever had it.
In the reported cases, every system kept running safely. That is the good news, and it is also why attacks like these tend to go unnoticed until somebody counts them up.
Could this happen in Portugal?
The useful question is not whether it could, but how ready anyone is. The same industrial controllers sit in treatment plants across Europe, often decades old and running software nobody patches any more. The regulatory difference is that Europe has the NIS2 directive forcing essential-service operators — water included — to report incidents and demonstrate a security floor, the same legislative push that brought new AI transparency obligations into force this weekend.
Technical advisories and guidance for critical infrastructure operators are published by CISA.
If it helps: the likeliest attack on a water utility is not the disaster movie. It is a factory-default password that nobody changed for fifteen years.
By Oliver Grant
Image: Sdkb / Wikimedia Commons (CC BY-SA 4.0)