Michigan has confirmed that cyberattacks affected nine of the state's water systems, joining Minnesota, where officials reported malicious activity at more than 30 systems days earlier. State officials in both places say the same thing about the outcome that matters most to households: the water is safe.
Dale George, communications director for the Michigan Department of Environment, Great Lakes and Energy, said in a statement reported by The Associated Press that "all systems continued to operate safely," that issues were addressed by local operators, and that there are no known impacts posing a public health concern.
That reassurance is worth taking at face value while also understanding its scope. No contamination has been reported, and no community has been told its water is unsafe to drink. What was targeted was the digital equipment utilities use to monitor and control treatment and distribution, which is why federal investigators are treating this as an infrastructure event rather than a routine IT problem.
Nine Michigan Systems, More Than 30 in Minnesota
The Michigan reports surfaced after the state received a federal cyber alert about attempts to tamper with operational technology at water systems. Soon after, George said, the state received a small number of reports from Michigan communities describing activity consistent with what federal agencies had outlined.
In Minnesota, the earlier wave affected more than 30 systems, including Plymouth's. Minnesota IT Services said most confirmed cases involved technology that water systems use to remotely monitor and control equipment. The agency drew an important distinction: a system being classified as impacted means investigators confirmed malicious activity involving that system's technology, not that every affected community lost water service.
State officials in Minnesota have said no part of the water supply has been reported compromised, and that as of late last week there were no active requests for residents to change how they use their drinking water. Earlier in the week, at least one city, Braham, had briefly asked residents to limit water use.
The FBI has reported incidents in at least seven states without identifying all of them. Rapid City, South Dakota, has also confirmed a water system cyber incident.
Operational Technology Explained in Plain Terms
Operational technology is the layer of equipment that physically runs a utility. In a water system, that includes programmable logic controllers, or PLCs, which are small industrial computers that open and close valves, run pumps, and regulate chemical dosing and system pressure.
Tampering with that layer is different from stealing data. According to the joint federal advisory issued by the Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency, the Environmental Protection Agency and other partners, the documented activity has involved reaching internet-exposed controllers using vendors' own legitimate engineering software, altering controller logic and falsifying what operators see on their screens, producing operational disruption and financial loss. In the recent incidents, federal agencies said attackers also changed IP addresses and passwords, locking operators out of monitoring and control.
That is the health-relevant risk. If dosing or pressure controls are altered, or if operators are shown inaccurate readings, the potential consequences run through water quality and system pressure. In these incidents, utilities detected problems and in some cases shifted to manual operation, and no contamination has been reported.
Nick Anderson, acting director of CISA, said the agency is "currently observing a significant increase in cyber threat actors targeting programmable logic controllers." He urged operators to remove publicly exposed controllers and other operational technology from the internet as soon as possible.
Federal Investigators Have Not Named a Culprit
The advisory at the center of this, originally published in the spring and updated in July, describes ongoing Iranian-affiliated cyber activity against internet-connected operational technology. The update added detection guidance for Rockwell Automation programs and expanded the manufacturer scope to include Schneider Electric, Siemens and potentially other controllers.
Attribution of the Michigan and Minnesota incidents specifically has not been finalized. U.S. officials told CBS News that investigators are examining whether the activity is the work of Iranian hackers, while cautioning that the assessment could change as more technical evidence is collected. Minnesota officials have likewise said investigators have not determined who was behind each attack.
Attribution should be treated as an open question. What is confirmed is the targeting pattern, the number of affected systems in each state, and the official assessment that water remains safe.
EPA Assistant Administrator for Water Jess Kramer said in the federal announcement that cybersecurity threats pose a legitimate risk to the communities, businesses, hospitals and schools that depend on water systems, and urged utilities to adopt cybersecurity best practices.
Signs a Household Should Actually Watch For
There is no evidence-based reason for households in Michigan or Minnesota to stockpile bottled water, install emergency filtration or stop drinking tap water. State officials have not issued any such recommendation, and doing so on the basis of a cyber incident with no reported contamination would be premature.
What is reasonable is knowing where your local notice would come from. Boil water advisories and use restrictions are issued by your individual water utility or municipality, not by the FBI or a national outlet. Sign up for your city or county's alert system if you have not already. If you notice a sudden loss of pressure, unusual discoloration or a strong chemical odor at the tap, report it to your utility rather than diagnosing it yourself, and follow any instructions the utility issues.
People at higher risk from waterborne illness, including infants, pregnant people, older adults and anyone who is immunocompromised, should follow local advisories carefully if one is ever issued in their community.
Utilities in both states are working with federal partners on remediation. The Minnesota Department of Health maintains cybersecurity assessment and breach reporting requirements for public water systems, and federal agencies have said they will continue updating guidance as the investigation develops. MedicalDaily will report any change in the public health assessment.
Frequently Asked Questions
Is the drinking water in Michigan and Minnesota safe? State officials in both states say yes. Michigan's environment department said all affected systems continued to operate safely with no known public health impact, and Minnesota officials said no part of the state's water supply has been reported compromised.
How many water systems were affected? Nine in Michigan and more than 30 in Minnesota. The FBI has reported incidents in at least seven states.
What does operational technology tampering actually mean? It refers to interference with the industrial computers and control screens that run pumps, valves, chemical dosing and pressure, rather than theft of customer data.
Who is behind the attacks? That has not been publicly confirmed. Investigators are examining whether Iranian-affiliated actors are responsible, and have cautioned that the assessment could change.
Should I buy bottled water or a filter? No official has recommended it. There is no reported contamination. The useful step is signing up for alerts from your local water utility so you receive any advisory directly.
What symptoms would indicate a water problem? Waterborne illness typically causes stomach cramps, diarrhea, nausea or vomiting. Anyone with severe or persistent symptoms, particularly infants, older adults or immunocompromised people, should contact a clinician.
Where do boil water notices come from? From your individual water utility or city, not from federal agencies. Local notices are the authoritative source for any change in guidance.