Nine Michigan Water Systems Reported Cyber Activity. What Officials Still Haven’t Disclosed.
State officials say all nine continued operating safely and no known public-health threat emerged. The systems, incident scope and attacker remain undisclosed.
Listen to this article
AI-generated narration · 13:08
DEVELOPING — Last updated August 21, 2026, 12:03 p.m. EDT.
Michigan officials say nine water systems reported cyber activity matching a recent federal warning—but they have not publicly identified the systems, described what happened at each facility or named the attacker.
The Michigan Department of Environment, Great Lakes, and Energy told news organizations that all nine systems continued operating safely, local operators addressed the activity and there were no known public-health impacts.
UPDATE — added Aug. 21 (CISA AA26-231A, Aug. 19): NSA, CISA, FBI, DOE and EPA warned of an active threat to internet-exposed Siemens S7 series PLCs, including in the water and wastewater sector. The agencies said actors are using internet scanning services and AI-generated Python/`snap7` scripts that mimic legitimate monitoring tools. They described persistent reconnaissance and capability development; this advisory does not document a confirmed plant-level disruption, name a Michigan system, or attribute the July water incidents. It is a new federal overlay, not proof that the nine Michigan systems were Siemens targets.
UPDATE — added Aug. 21 (reporting published Aug. 12–13): Sen. Elissa Slotkin, D-Mich., said on her Aug. 10 “Intel Brief” that after a CISA bulletin, Michigan “looked at our own water treatment facilities and realized, holy crap, the same thing was going on.” The Detroit Free Press reported that she described passwords being changed at water treatment facilities in Michigan and elsewhere. That is Slotkin’s account. It is stronger than EGLE’s public statement and has not been confirmed, system by system, by EGLE, MSP or the FBI. Slotkin’s remarks about Iran are not treated here as attribution.
UPDATE — added Aug. 21: Twenty days after Michigan first disclosed the cluster, state and federal officials still have not identified the nine systems, said whether any Michigan operator lost monitoring or control, or published a formal attribution. A same-day check of the Michigan Department of Environment, Great Lakes, and Energy water-sector cybersecurity page found no incident statement. The disclosure gap that opened this report remains the Michigan story.
UPDATE — added Aug. 21 (reporting published Aug. 18): The Christian Science Monitor, recapping the national campaign, said the FBI still would not comment on who was responsible and referred only to its July 30 public statement. Karleen Kos, chief executive of the Minnesota Municipal Utilities Association, described effects in Minnesota that Michigan still has not confirmed or denied for its nine systems: some operators lost visibility, some switched to manual control, and some saw controls “acting oddly.” Kos said nobody’s drinking water was threatened. Those Minnesota effects do not establish what happened in Michigan.
UPDATE — added Aug. 21 (utility advisory dated Aug. 3): Clayton County Water Authority in Georgia said unauthorized cyber activity may have caused or contributed to a July 27 disruption that produced a precautionary boil-water advisory in parts of north Clayton County. The authority said service was restored within hours and the advisory was lifted after required water-quality testing. It said it coordinated with the FBI and CISA and found no evidence that customer billing or payment information was accessed. That is a named boil-water case in the national wave. Michigan still has not said whether any of its nine systems issued an advisory, lost pressure, or switched to manual operations.
UPDATE — added Aug. 21 (industry letters dated Aug. 5; reported Aug. 18): The American Water Works Association asked congressional leaders to pass water-utility cybersecurity funding bills. The National Association of Water Companies said the absence of uniform cybersecurity standards leaves too many systems vulnerable. Cynthia Finley, director of regulatory affairs at the National Association of Clean Water Agencies, told the Monitor that utilities noticed the attacks quickly and there were no dire consequences, but that more sophisticated attacks will be harder. Those are national policy responses. They are not Michigan incident disclosures.
UPDATE — checked Aug. 21: OpenAI’s Aug. 4 offer of what the company described as $1 million in water-sector service credits, first noted here on Aug. 12, still has no public accept-or-decline from the Michigan Department of Technology, Management & Budget. The unanswered offer does not identify the nine systems or the attacker.
UPDATE — added Aug. 12 (reporting published Aug. 7; letter dated Aug. 4): OpenAI sent Michigan officials an Aug. 4 letter offering what the company described as $1 million worth of service credits for water-sector cyber defense and direct technical support, according to public reporting reviewed for this update. Michigan Department of Technology, Management & Budget spokesperson Laura Wotruba confirmed that the department received the letter, but did not say whether Michigan would accept the offer. The offer does not establish that OpenAI tools have been deployed or affected the response, and it does not identify any of the nine systems or the attacker.
UPDATE — added Aug. 9 (research published Aug. 6; scan dated Aug. 3): Forescout reported finding 4,407 internet-facing Rockwell Automation controllers worldwide, including 2,844 in the United States and 22 in cities associated with the current campaign. The researchers could not confirm that those 22 devices were compromised, found no confirmed vulnerability exploited in the campaign and said there is no confirmed link between the water incidents and Iranian-affiliated actors. The findings document a broad exposure problem; they do not identify the nine Michigan systems or prove that an exposed controller was attacked.
UPDATE — added Aug. 9 (program announced Aug. 7): The Record reports that the National Rural Water Association and DEF CON Franklin launched the Water Watch Center to provide threat intelligence and cybersecurity support for utilities serving fewer than 10,000 people. Five managed detection and response providers are participating. The program is an operational response to the broader campaign, not a disclosure about which Michigan systems were involved or what happened inside them.
UPDATE — checked Aug. 9: A same-day review of CISA's July 30 water-sector alert, Michigan EGLE's water-sector cybersecurity page and GSJ's 71-source feed found no new Michigan-specific incident disclosure. Officials still have not publicly identified the nine systems, separated attempted activity from confirmed access, described whether any Michigan operator lost monitoring or control, or formally attributed the Michigan incidents.
UPDATE — added Aug. 6 (reporting published Aug. 4): MLive reports that Michigan State Police is “actively monitoring” the situation and communicating with municipal water systems across the state. MLive also reports that MSP and EGLE did not identify the systems, affected regions, or whether the reports involved drinking-water or wastewater facilities. Kalamazoo Public Services Director James Baker told MLive that Kalamazoo was not among the affected systems. The new disclosures narrow the public record slightly, but they still do not establish that all nine systems were successfully breached or connect the Michigan reports to Iran.
UPDATE — added Aug. 6 (reporting published Aug. 3): WILX reports that Lansing Board of Water & Light was not among the nine systems reported by EGLE, but BWL Public Information Officer Vernon Myers said the utility had seen an uptick in scans of its firewalls and relevant ports. WILX reports that none of those attempts got past BWL’s firewalls. That identifies a separate Michigan utility seeing increased cyber activity; it does not identify any of the nine systems, establish that all nine were breached, or link the Michigan incidents to Iran.
UPDATE — added Aug. 6: The national scope has widened. ABC News reported Aug. 4, and CBS News and The Record confirmed Aug. 5, that water utilities in at least 12 states are now responding to attacks, with sources naming Michigan, Minnesota, Georgia, New Jersey and South Dakota. CBS reported that some utilities lost remote-control capability and that attackers reached pumps, valves and pressure controls in several cases; New Jersey officials said two municipal systems shifted to manual operations after automated monitoring was temporarily disabled. Federal agencies still have not publicly attributed the campaign. Officials cited by ABC, CBS and The New York Times reportedly view Iran-backed actors as the leading suspects while stressing that the investigation remains preliminary, and President Donald Trump has publicly dismissed Iranian involvement. Separately, the Great Lakes Water Authority and Oakland County have said their systems were not affected. None of this identifies the nine Michigan systems, establishes that all nine were breached or provides incident-level attribution for them.
That is the most important immediate fact for residents. It is not, however, a complete account of the incidents.
Public reporting has not established whether all nine Michigan systems were successfully breached, whether some reports involved blocked attempts or suspicious activity, or whether any Michigan operator temporarily lost remote visibility or control. The affected Michigan communities and facilities remain unnamed.
What Michigan has confirmed
EGLE said the state received a federal alert concerning attempts to tamper with operational technology at water systems. Michigan communities then reported activity consistent with the federal description. EGLE communications director Dale George later told The Associated Press that nine systems were impacted.
The agency said the systems kept operating safely and that no known impact created a public-health concern. The FBI said it was aware of reporting involving the water and wastewater sector and was working with government partners.
Beyond that aggregate account, basic incident-level facts remain unavailable: the dates of the events, whether access was attempted or successful, the equipment involved, whether credentials or controller settings were changed, whether systems switched to manual operations and what recovery work was required.
Why “nine systems” does not necessarily mean nine successful breaches
Officials and news reports have used broad terms including “activity,” “impacted” and “cyberattacks.” Those words are not interchangeable.
A system can report scanning, an attempted login, a blocked connection, confirmed unauthorized access, a configuration change or an operational disruption. Until Michigan releases a clearer incident taxonomy, saying nine water plants were successfully hacked would exceed the public evidence.
The reporting itself shows why that distinction matters. WILX paraphrased EGLE as saying none of the systems were compromised, while George told the AP that nine systems were impacted. Those descriptions can coexist only if “impacted” includes activity short of a confirmed compromise—or if the agency's public terminology remains inconsistent.
The same caution applies to consequences. EGLE’s statement addresses the urgent public-health question. It does not tell residents whether Michigan operators experienced communications loss, changed passwords, altered controller settings, pressure changes, overtime costs or temporary manual operation.
Those effects have now been reported elsewhere in the national campaign. CBS said some utilities lost remote-control capability and that attackers reached pumps, valves and pressure controls in several cases. New Jersey officials said two municipal systems temporarily lost automated monitoring or operations and shifted to manual control. None of those effects has been publicly confirmed for the nine Michigan systems. They remain questions Michigan officials need to answer.
Two federal warnings—and an important attribution line
The federal record contains two related but distinct tracks.
A July 30 FBI and Environmental Protection Agency notice described malicious activity affecting internet-facing programmable logic controllers, or PLCs, in water and wastewater systems across at least seven states. The FBI said it had observed the described behavior on Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. Attackers changed device IP addresses and passwords, cutting off monitoring and control in some cases. At least one organization found modified controller project files. Reported effects across the broader wave included pressure loss and flooding.
A companion CISA alert said threat actors had locked operators out by changing passwords, disconnected controllers by changing IP addresses and caused boil-water notices and sustained manual operations somewhere in the sector. CISA urged water utilities and their integrators to remove publicly exposed PLCs and other operational technology from the internet.
Those federal notices do not say those specific effects occurred in Michigan. They also describe the perpetrators only as malicious cyber actors; they do not publicly attribute the late-July wave to Iran.
A separate federal advisory attributes a broader campaign against internet-connected PLCs to Iranian-affiliated actors. That advisory documents project-file manipulation, altered operator displays and disrupted PLC functions across critical infrastructure. It does not identify the nine Michigan systems or provide incident-specific attribution for them.
Later reporting has added suspicion, not formal attribution. Sources cited by ABC and CBS said Iran or Iran-backed hackers are the leading suspects in the expanded 12-state campaign. The New York Times reported that U.S. officials view Iran as the leading suspect while stressing that the investigation is preliminary and lacks definitive forensic proof. Tenable has pointed to similarities with prior CyberAv3ngers activity, while WaterISAC has said it has not assessed attribution. President Trump has publicly dismissed Iranian involvement. The campaigns may ultimately prove connected, but public evidence still does not establish that connection system by system.
The disclosure gap is now the Michigan story
Michigan already maintains a water-sector cybersecurity program involving EGLE and the Michigan Cyber Command Center. State guidance recommends incident reporting, cyber assessments, stronger authentication, backups, monitoring and limits on public internet exposure.
The existence of guidance does not show how deeply those controls were implemented at the nine systems—or whether relevant weaknesses had already been identified and remained unresolved.
Officials can provide meaningful accountability without publishing live network addresses or a roadmap for attackers. At minimum, they could release anonymized totals showing:
- how many reports involved attempted access versus confirmed unauthorized access;
- how many systems lost monitoring, control or communications;
- whether any switched to manual operation;
- whether passwords, IP settings or controller files were changed;
- whether water pressure, service or quality testing was affected;
- whether the affected systems had completed prior cyber assessments; and
- when the state expects to identify systems or explain why their names must remain withheld.
What residents should know now
Michigan says the nine systems operated safely and that no known public-health impact occurred. There is no public evidence supporting claims that drinking water was contaminated or that all nine facilities shut down.
There is also no public incident-specific evidence establishing that Iran attacked the Michigan systems. Public reporting that officials suspect Iran-backed actors is not the same as a formal or forensic attribution.
This remains a developing story because the state has acknowledged a significant cluster while releasing only an aggregate safety outcome. The next phase is not turning suspicion into certainty. It is obtaining a clear account of what happened, what worked, what failed and what Michigan will change before the next attempt.
GSJ will update this report as Michigan or federal officials identify affected systems, clarify incident scope or release attribution evidence.
Sources
- Associated Press: FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems — Associated Press
- ClickOnDetroit/AP: FBI investigates as Michigan joins Minnesota — ClickOnDetroit (WDIV)
- CISA: Protect OT Against Activity Targeting PLCs — CISA
- FBI/EPA PSA I-073026-PSA: Malicious Actors Targeting Internet-Facing PLCs — FBI / EPA
- FBI/CISA/NSA/EPA/DOE/CNMF/Treasury AA26-097A: Iranian-Affiliated Actors Exploit PLCs — FBI / CISA / NSA / EPA / DOE / CNMF / Treasury
- Michigan EGLE: Cybersecurity for the Water Sector — Michigan EGLE
- Iranian cyber threat warnings preceded Michigan water incidents — MLive
- Cyberattacks target nine Michigan water systems, Lansing BWL sees uptick in attempts — WILX
- At least 12 states face cyberattacks on their water systems, sources say — ABC News
- At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers — CBS News
- Cyberattacks on water systems expand to 12 states — The Record
- FBI investigates cyberattacks on water systems across seven states, Michigan among those hit — ClickOnDetroit (WDIV)
- Cyberattack targets 2 NJ municipal water systems — NJBIZ
- Georgia, Michigan say water systems hacked by Iran-tied crew — The Register
- Scope of hacks on U.S. water supply widens as evidence points to Iran — The New York Times
- Forescout: OT Security Analysis — Exposed Devices Attacked in US Water Systems — Forescout
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities — The Hacker News
- Water utilities group partners with DEF CON offshoot for Water Watch Center — The Record
- Christian Science Monitor, Aug. 18, 2026 — Christian Science Monitor
- Clayton County Water Authority security advisory, Aug. 3, 2026 — Clayton County Water Authority
- EGLE water-sector cybersecurity page (checked Aug. 21; no incident statement) — Michigan EGLE
- CISA AA26-231A, Aug. 19, 2026 — CISA
- Detroit Free Press, Slotkin, Aug. 12–13, 2026 — Detroit Free Press