Nine Michigan Water Systems Reported Cyber Activity. What Officials Still Haven’t Disclosed.
State officials say all nine continued operating safely and no known public-health threat emerged. The systems, incident scope and attacker remain undisclosed.
Listen to this article
AI-generated narration · 6:38
DEVELOPING — Last updated August 2, 2026, 12:46 a.m. EDT.
Michigan officials say nine water systems reported cyber activity matching a recent federal warning—but they have not publicly identified the systems, described what happened at each facility or named the attacker.
The Michigan Department of Environment, Great Lakes, and Energy told news organizations that all nine systems continued operating safely, local operators addressed the activity and there were no known public-health impacts.
That is the most important immediate fact for residents. It is not, however, a complete account of the incidents.
Public reporting has not established whether all nine systems were successfully breached, whether some reports involved blocked attempts or suspicious activity, or whether any operator temporarily lost remote visibility or control. The affected communities and facilities remain unnamed.
What Michigan has confirmed
EGLE said the state received a federal alert concerning attempts to tamper with operational technology at water systems. Michigan communities then reported activity consistent with the federal description, with nine systems ultimately counted in reporting by The Associated Press.
The agency said the systems kept operating safely and that no known impact created a public-health concern. The FBI said it was aware of reporting involving the water and wastewater sector and was working with government partners.
Beyond that aggregate account, basic incident-level facts remain unavailable: the dates of the events, whether access was attempted or successful, the equipment involved, whether credentials or controller settings were changed, whether systems switched to manual operations and what recovery work was required.
Why “nine systems” does not necessarily mean nine successful breaches
Officials and news reports have used broad terms including “activity,” “impacted” and “cyberattacks.” Those words are not interchangeable.
A system can report scanning, an attempted login, a blocked connection, confirmed unauthorized access, a configuration change or an operational disruption. Until Michigan releases a clearer incident taxonomy, saying nine water plants were successfully hacked would exceed the public evidence.
The same caution applies to consequences. EGLE’s statement addresses the urgent public-health question. It does not tell residents whether operators experienced communications loss, changed passwords, altered controller settings, pressure changes, overtime costs or temporary manual operation.
None of those effects has been publicly confirmed for Michigan. They are the questions officials still need to answer.
Two federal warnings—and an important attribution line
The federal record contains two related but distinct tracks.
A July 30 FBI and Environmental Protection Agency notice described malicious activity affecting internet-facing programmable logic controllers, or PLCs, in water and wastewater systems across at least seven states. The FBI said it had observed the described behavior on Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. Attackers changed device IP addresses and passwords, cutting off monitoring and control in some cases. At least one organization found modified controller project files. Reported effects across the broader wave included pressure loss and flooding.
A companion CISA alert said threat actors had locked operators out by changing passwords, disconnected controllers by changing IP addresses and caused boil-water notices and sustained manual operations somewhere in the sector. CISA urged water utilities and their integrators to remove publicly exposed PLCs and other operational technology from the internet.
Those federal notices do not say those specific effects occurred in Michigan. They also describe the perpetrators only as malicious cyber actors; they do not publicly attribute the late-July seven-state wave to Iran.
A separate federal advisory attributes a broader campaign against internet-connected PLCs to Iranian-affiliated actors. That advisory documents project-file manipulation, altered operator displays and disrupted PLC functions across critical infrastructure. It does not identify the nine Michigan systems or provide incident-specific attribution for them.
The campaigns may ultimately prove connected. Public evidence does not yet establish that connection system by system.
The disclosure gap is now the Michigan story
Michigan already maintains a water-sector cybersecurity program involving EGLE and the Michigan Cyber Command Center. State guidance recommends incident reporting, cyber assessments, stronger authentication, backups, monitoring and limits on public internet exposure.
The existence of guidance does not show how deeply those controls were implemented at the nine systems—or whether relevant weaknesses had already been identified and remained unresolved.
Officials can provide meaningful accountability without publishing live network addresses or a roadmap for attackers. At minimum, they could release anonymized totals showing:
- how many reports involved attempted access versus confirmed unauthorized access;
- how many systems lost monitoring, control or communications;
- whether any switched to manual operation;
- whether passwords, IP settings or controller files were changed;
- whether water pressure, service or quality testing was affected;
- whether the affected systems had completed prior cyber assessments; and
- when the state expects to identify systems or explain why their names must remain withheld.
What residents should know now
Michigan says the nine systems operated safely and that no known public-health impact occurred. There is no public evidence supporting claims that drinking water was contaminated or that all nine facilities shut down.
There is also no public incident-specific evidence establishing that Iran attacked the Michigan systems.
This remains a developing story because the state has acknowledged a significant cluster while releasing only an aggregate safety outcome. The next phase is not speculation about the attacker. It is obtaining a clear account of what happened, what worked, what failed and what Michigan will change before the next attempt.
GSJ will update this report as Michigan or federal officials identify affected systems, clarify incident scope or release attribution evidence.
Sources
- Associated Press: FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems — Associated Press
- ClickOnDetroit/AP: FBI investigates as Michigan joins Minnesota — ClickOnDetroit (WDIV)
- CISA: Protect OT Against Activity Targeting PLCs — CISA
- FBI/EPA PSA I-073026-PSA: Malicious Actors Targeting Internet-Facing PLCs — FBI / EPA
- CISA AA26-097A: Iranian-Affiliated Actors Exploit PLCs — CISA / FBI / NSA / EPA
- Michigan EGLE: Cybersecurity for the Water Sector — Michigan EGLE