Particle.news
Download on the App Store

Cyber Intrusions Hit Water Systems in Seven States

Federal teams say attackers manipulated internet‑exposed industrial controllers and forced many utilities to run on manual controls, raising urgent concerns about critical‑infrastructure security.

Overview

  • Federal and state officials disclosed this week that a coordinated campaign targeted internet‑connected operational technology in at least seven states, with Minnesota reporting more than 30 community systems and Michigan confirming nine.
  • The intruders focused on programmable logic controllers, which are devices that remotely monitor and control pumps and treatment equipment, and CISA says attackers changed PLC passwords and IP settings to disrupt remote access.
  • Most affected utilities switched to manual operations or contingency plans and local operators kept supplies running, and there are no confirmed public‑health or drinking‑water safety impacts so far.
  • The FBI is leading a multistate investigation and intelligence officials have pointed to Iranian‑affiliated actors based on tradecraft and motive, but federal agencies have not completed formal forensic attribution.
  • The incidents expose long‑standing weaknesses at small, underfunded water systems and are likely to prompt expanded federal technical help and calls for investment to remove OT devices from the public internet and strengthen local cyber defenses.