MICHIGAN — Federal and state authorities are investigating a series of cyberattacks that targeted nine Michigan water systems, prompting a joint response involving the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and Michigan officials responsible for protecting critical infrastructure. Authorities say that drinking water remained safe and there is no evidence of a public health threat, despite the attempted intrusions.
The incidents come just days after officials in neighboring Minnesota disclosed a similar wave of cyberattacks affecting more than 30 water systems, raising concerns that public utilities across the Midwest are facing a coordinated cybersecurity campaign.
Water Supply Remains Safe
Michigan officials emphasized that all nine affected water systems continued operating safely throughout the incidents.
According to investigators, the attacks targeted operational technology (OT) used to monitor and manage water infrastructure rather than attempting to contaminate drinking water directly. Officials reported no disruption to water quality and no indication that residents were exposed to unsafe drinking water.
Authorities have not publicly identified the affected utilities, citing the ongoing investigation and security concerns.
FBI and Federal Agencies Investigating
The FBI, CISA, the U.S. Environmental Protection Agency (EPA), and Michigan agencies are working together to determine who was responsible and whether the incidents are connected to attacks reported in other states.
Investigators have not officially attributed responsibility to any individual or nation. However, federal cybersecurity agencies have previously warned that Iranian-affiliated cyber actors have increasingly targeted water and wastewater infrastructure across the United States by exploiting vulnerable industrial control systems.
Growing Concerns Over Critical Infrastructure
Cybersecurity experts have long warned that many local water utilities rely on aging operational technology with limited cybersecurity protections.
Recent federal advisories have urged utilities to:
- Disconnect unnecessary internet-connected control systems.
- Strengthen authentication and password policies.
- Apply security updates promptly.
- Maintain manual operating capabilities in case of cyber incidents.
- Regularly review network access and monitoring systems.
Michigan's Department of Environment, Great Lakes, and Energy (EGLE) already works alongside the Michigan Cyber Command Center (MC3), the FBI, CISA, and the EPA to help utilities prepare for and respond to cyber threats affecting drinking water infrastructure.
Part of a Wider Pattern
The Michigan incidents follow similar attacks reported in multiple states over the past week, highlighting growing concerns about cybersecurity risks facing America's critical infrastructure.
While investigators continue working to determine the source of the attacks, officials stress that the events demonstrate the importance of protecting systems responsible for essential public services such as drinking water, wastewater treatment, and other municipal utilities.
Looking Ahead
The FBI's investigation remains ongoing, and authorities have indicated they will continue monitoring water systems for additional suspicious activity.
Officials encourage utilities to review cybersecurity practices and report any unusual activity immediately, while emphasizing that Michigan residents can continue using their drinking water normally, as there is currently no indication that water quality or public safety has been compromised.











































































































































































































































Comments (0)
No comments yet. Share the first perspective.
Sign in with a listener account to add a comment.