Overview
- The campaign began with a coordinated intrusion that hit more than 30 Minnesota municipal water systems on July 26–27, 2026 and has since been reported by operators in about a dozen states.
- Attackers remotely accessed internet‑exposed programmable logic controllers, commonly called PLCs, changed IP addresses and passwords and in some cases disrupted monitoring or control of pumps, valves and dosing equipment.
- The FBI, CISA and EPA are leading a multistate investigation and have issued urgent guidance to remove PLCs from direct internet exposure, use secure gateways or VPNs, enforce strong credentials and rehearse manual operations.
- There are no confirmed public‑health impacts so far, but some communities saw pressure loss, brief boil advisories, flooding and temporary switches to manual operation that strained small utility staffs.
- The incidents highlight chronic underfunding and fragmented governance across roughly 152,000 U.S. public water systems and have prompted calls for sustained federal funding and tighter sectorwide cybersecurity standards while attribution remains under active review.