MICHIGAN
Hackers target Michigan water systems
The Detroit News
Updated Aug. 1, 2026, 11:01 p.m. ET
View Comments
Municipal water systems in Michigan were targeted in a cyberattack, according to the state’s Department of Environment, Great Lakes, and Energy
The New York Times reported Saturday that Michigan is part of a wave of cyberattacks targeting U.S. water systems involving at least seven states, including Minnesota and South Dakota, which have also reported attacks. The attackers targeted internet-connected control systems used to manage water treatment, pressure and other operations
Dale George, spokesman for the Department of Environment, Great Lakes, and Energy, said in a statement to the media that Michigan received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described.”
“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said
The FBI warned earlier this week that “malicious cyber actors are conducting cyber attacks targeting operational technology devices” involving programmable logic controllers (PLCs)
“These threat actors are remotely accessing internet-facing PLCs, changing IPs and passwords, and causing operational disruption, including pressure loss and flooding,” the FBI said on social media on Friday
Michigan confirmed that nine municipal water systems reported activity consistent with the federal warnings, though officials also said there were no public health impacts and all systems remained operational
The FBI and Environmental Protection Agency said some of the activity in the United States has disrupted water operations, forcing utilities to rely on manual processes while they strengthen defenses
According to the Times, U.S. officials believe Iran is the leading suspect, though they stress the investigation remains preliminary and definitive forensic proof has not yet been established. President Donald Trump publicly dismissed Iran’s involvement, instead suggesting Minnesota was responsible, despite intelligence officials privately continuing to view Iran as the most likely culprit
The FBI and EPA released the following guidance to protect systems in the United States:
- Disconnect programmable logic controllers from the public internet and require secure, monitored remote access through a gateway or jump host.
- Secure cellular modems with strong authentication, current firmware and logging to detect suspicious activity.
- Limit remote operational technology access by using secure network architectures such as private APNs, Zero Trust, SD-WAN or VPNs.
- Require strong, unique passwords for all operational technology devices. Restrict programmable logic controllers network access to authorized devices only using firewalls and access control lists.
- Keep programmable logic controllers hardware and software key switches in “run” mode except during authorized updates, and verify project files before returning them to service.
- Maintain the ability to operate water systems manually and regularly test disaster recovery, backup, and business continuity plans.
- Routinely inspect programmable logic controllers programs for unauthorized changes using integrity-checking tools and known-good configurations.
- Verify backups are free of malicious code before restoring systems.
- Review logs from programmable logic controllers, modems, HMIs and workstations for signs of intrusion or lateral movement, and reimage compromised devices if necessary.
- Replace end-of-life hardware whenever possible, or isolate unsupported systems and apply additional security controls until they can be retired.
- Maintain and regularly review a 12-month forecast of end-of-life equipment, tracking ownership, location and planned replacement dates.

