Hundreds of drinking water providers in Washington state have been advised to protect themselves against suspected hacking that disrupted utilities in Minnesota and Michigan.
So far, there have been no known similar attacks in Washington or water-quality problems, spokesperson Karina Shagren of the state Department of Emergency Management said Saturday morning.
At least seven states reported tampering or attempted tampering, according to the FBI, whose statements suggest water systems are vulnerable elsewhere.
The FBI says “malicious cyber actors” have targeted internet-connected programmable logic controllers, leading to pressure loss and flooding in some systems. Pressure loss could cause untreated ground water to seep into pipes, the FBI alert said.
The FBI and Cybersecurity and Infrastructure Security Agency warned that Iranian hackers have been targeting water, wastewater and other infrastructure systems. The U.S. and Iran have been at war five months. The FBI had not publicly identified a culprit as of Thursday, The Associated Press reported.
The Washington State Department of Health forwarded federal alerts to drinking water providers on Thursday, said Shagren.
Public water systems serve more than 6.2 million Washingtonians, but the state hasn’t rigorously tracked their security measures. A 2024 plan aims to tighten Department of Health support and oversight.
National reports say the tampering hasn’t harmed public health, despite attempted attacks on at least 30 Minnesota systems and nine in Michigan.
Hackers remotely accessed the utilities’ internet-using devices and changed IP addresses and passwords, resulting in a loss of monitoring and function, the FBI said.
The bureau identified devices by Rockwell Automation and recommends removing the controllers from internet exposure and strengthening firewalls and user restrictions. Utilities are also encouraged to contact Rockwell’s security response team and the Environmental Protection Agency for technical support.
Public works infrastructure has long been identified as a potential target for cyberattacks, as warfare widens beyond physical battlefields.
“Driven by geopolitical conflicts, foreign threat actors recognize the vulnerability present in water and wastewater infrastructure and are motivated by the potential consequences of disrupting these critical systems,” a Washington state report says.
The state Department of Health has filed a “Cybersecurity Action Plan,” required by federal law and approved by the National Security Council two years ago.
The plan applies to the largest 249 water suppliers that have at least 3,330 customers, as well as 100 wastewater departments that carry more than 1 million gallons per day.
“Washington State does not currently regulate drinking water systems or wastewater treatment plants for cybersecurity vulnerabilities, nor does it review the incident response plans from these utilities for cybersecurity considerations,” the 2024 plan says.
As the plan unfolds, utilities will become eligible for cybersecurity improvement grants, additional training and help from outside specialists, the plan says. They’ll be required to file incident response plans.
State auditors already conduct occasional probes seeking vulnerabilities in water-utility software, which would intensify.

The opinions expressed in reader comments are those of the author only and do not reflect the opinions of The Seattle Times.