CiberLATAMbywhalemate

FBI, CISA warn on U.S. water attacks

FBI, CISA and EPA flagged attacks on U.S. critical infrastructure, including water systems and tankers, plus exposed utility credentials.

Whalemate Labs · AI-assisted researchPublished:3 min read

The FBI and CISA warned about pre-positioning attacks against U.S. critical infrastructure, with activity tied to communications, energy, transportation and water. The sequence also includes incidents at water systems in at least seven states in July 2026, more than 30 community systems hit in Minnesota, exposed utility credentials, and two tankers under federal investigation for possible onboard network compromise.

The FBI and CISA have warned about pre-positioning attacks and other activity tied to U.S. critical infrastructure, with a focus on communications, energy, transportation and water. The sequence also includes incidents against water systems in at least seven states in July 2026, more than 30 community systems affected in Minnesota, and a federal investigation into two tankers headed to the United States.

What does the federal warning cover?

The FBI and CISA warning focused on activity against critical U.S. sectors, including communications, energy, transportation and water. Cyber Caselibrary recorded the notice in its case library, while other coverage tied to July 2026 broadened the focus to water and wastewater utilities.

During that period, the FBI and the EPA reported incidents against water systems in at least seven states, according to independent coverage citing both agencies. In Minnesota, more than 30 community water systems were also reported hit during July 2026 attacks.

What is known about the impact on water and wastewater?

SpyCloud found exposed credentials for U.S. water and wastewater organizations, and said some could provide access to operational networks and remote access tools used to run pumps and control water movement. The analysis summarized by Security Boulevard said exposed credentials alone do not prove an intrusion or OT tampering.

CRBC News said SpyCloud's study found infostealer malware credentials collected from 1,787 U.S. water and wastewater organizations. According to that report, at least 250 appeared to provide access to operational networks or remote access tools, and a single vendor device allegedly exposed passwords linked to 167 utilities.

Upper Michigan's Source added that actors targeted Internet-exposed PLCs at more than 100 drinking water and wastewater systems across 12 states, using coordinated, brief, one-stage attacks. That coverage also said communications were lost with wells, pump stations, lift stations and water towers.

What happened with the investigated tankers?

Two tankers bound for the United States came under federal cybersecurity investigation after signs of compromise in onboard networks, including propulsion, navigation and cargo systems. Ice Miller framed the case as part of the OT risk facing the maritime and transportation sectors.

Bloomberg later reported that FBI and Coast Guard investigators found evidence of temporary access to the propulsion system of a supertanker as it approached the Texas coast. The investigation into the intrusion method and the responsible party remained open.

Additional coverage of the VL Prosperity said the FBI had not received reports of operational disruption, loss of stability, physical danger to the crew or environmental damage, narrowing the reported operational scope of the compromise.

What does this sequence of incidents show?

The incidents show simultaneous pressure on water and maritime transport in the United States, with attacks on exposed PLCs, utility credentials in circulation and investigated compromises aboard tankers. In the water sector, the coverage points both to coordinated campaigns against exposed systems and to the risk of remote access to operational networks.

Sources

View all