Malicious cyber activity has affected technology at water systems in at least seven states last week, forcing some facilities to switch to manual operations and prompting the FBI and Environmental Protection Agency (EPA) to warn facilities nationwide of hackers. Minnesota IT Services said in a statement last week that at least 30 municipal water facilities were targeted July 26-27 and that it had “immediately activated the state's cybersecurity incident response capabilities.” Over the weekend, Michigan also reported cyberattacks on nine of its water systems. Without confirming just how widespread the attacks may have been or which states they affected, the FBI and EPA said in a joint statement that multiple incidents had occurred. It explained that hackers are remotely accessing internet-connected controls, changing administrator passwords, and “causing operational disruption” like flooding and pressure loss, which “could potentially allow untreated ground water to seep into pipes.” The incidents also came days after federal agencies updated a warning about ongoing Iranian cyber threats targeting U.S. critical infrastructure, though investigators have not publicly linked the latest attacks to Tehran. Read More: Why Cybersecurity Threats Are Growing United States water systems are a part of critical infrastructure in the country, which makes them attractive targets for cyberattacks. The EPA has warned in recent years that a significant number of local water systems had critical or high-risk vulnerabilities, including “outdated software, poor network security, weak access controls, and a lack of employee cybersecurity training.” But it has also indicated that it’s up to individual operators to protect their own systems from external threats. An EPA spokesperson pointed TIME to Administrator Lee Zeldin’s comments on FOX on Saturday, where he called on utility operators and local entities to protect themselves. “There is a lot of individual responsibility on the part of companies and local water systems