The Federal Bureau of Investigation (FBI) and the U.S. Environmental Protection Agency (EPA) have issued a joint warning after a series of cyberattacks targeted water utilities across seven U.S. states. The advisory urges water and wastewater operators to strengthen their cybersecurity defenses as attackers continue to target critical infrastructure.
According to the agencies, the incidents involved attempts to compromise operational technology (OT) and information technology (IT) systems that support water treatment and distribution services. While the impact varied between affected organizations, the attacks underscore the growing interest of cybercriminals and nation-state actors in disrupting essential public services.
The FBI and EPA recommend that utilities immediately implement Multi-Factor Authentication (MFA), patch internet-facing systems, disable unused remote access services, segment IT and OT networks, and continuously monitor for suspicious activity. Organizations are also encouraged to maintain offline backups and develop well-tested incident response and recovery plans.
Why It Matters
Water utilities are part of a nation's critical infrastructure, making them attractive targets for cyberattacks that could disrupt essential services or threaten public safety. Strengthening cybersecurity across operational environments is essential to reducing the risk of service interruptions and protecting critical infrastructure.
Conclusion
The latest FBI and EPA advisory serves as a reminder that critical infrastructure operators must remain vigilant against evolving cyber threats. Proactive security measures, continuous monitoring, and strong incident response capabilities are key to improving resilience against attacks targeting essential services.