A federal warning about hackers attacking water systems in at least seven states carries a familiar ring in Westchester County.
In 2013, an Iranian hacker broke into the control system of the Bowman Avenue Dam in Rye Brook, gaining access to water levels, temperature data, and the flood-control sluice gate. Now the FBI and EPA say a similar campaign is underway, and local water departments have not confirmed whether their systems use the same vulnerable equipment.
The agencies issued a joint alert Thursday, July 30, warning that water and wastewater utilities reported cyberattacks beginning Monday, July 27. Some operations were degraded.
Attackers targeted internet-connected programmable logic controllers, specifically Rockwell Automation MicroLogix 1100 and 1400 series devices that monitor pumps, pressure, and wastewater equipment. Hackers changed device passwords and IP addresses, locking operators out.
Some utilities reported pressure drops. A loss of pressure can allow untreated groundwater to seep into drinking water pipes, the FBI warned.
No contamination has been confirmed. The Minnesota Department of Health said drinking water quality was unaffected in that state, where more than 30 community water systems were hit on the nights of July 26 and July 27.
Who is behind it
The FBI and EPA did not formally name a country or group. But U.S. and state investigators view Iran-affiliated hackers as the probable perpetrators, according to The New York Times.
A separate federal advisory issued April 7 had already warned that Iranian-affiliated actors were exploiting PLCs across U.S. critical infrastructure "likely in response to hostilities between Iran and the United States."
Investigators are also examining whether the attackers deliberately mimicked Iranian tactics as a false-flag operation.
Minnesota's chief information security officer, John Israel, told reporters July 29 that the threat would spread. "I suspect that those attackers are going to continue to look nationally across the infrastructure," he said. "The hackers will continue to rattle those doorknobs and try to break into systems that have weak configurations."
The Westchester precedent
The 2013 Bowman Dam breach led to a federal indictment on March 24, 2016. Seven Iranians working for IRGC-affiliated entities were charged, according to Department of Justice records. Then-U.S. Attorney Preet Bharara called the infiltration "a frightening new frontier in cybercrime" when the indictment was unsealed.
The dam, owned by the City of Rye, controls water on Blind Brook flowing south through the city. Its computer-operated sluice gate is designed to mitigate flooding for downstream neighborhoods. Only a maintenance disconnection in 2013 prevented the hacker from operating the gate remotely. Remediation cost over $30,000.
Bronxville, Scarsdale, and Eastchester water departments have not responded to inquiries about whether they use internet-connected PLCs or what precautions they are taking.
What utilities should do
The FBI and EPA advised water systems to:
- Remove PLCs from direct internet exposure and route remote access through secure gateways
- Use strong, unique passwords and secure cellular modems
- Restrict connections to authorized devices
- Review project files for unauthorized changes
- Test manual operating procedures
- Replace or isolate equipment that no longer receives security updates
CISA acting director Nick Andersen urged operators on July 31 to "remove publicly exposed PLCs and other operational technology from the internet as soon as possible."
Residents who notice unusual water pressure changes or suspect cyber-related outages can contact the FBI's New York field office at 212-384-1000 or file a report at IC3.gov.







