Particle.news
Download on the App Store

Cyber Intrusions Target Water-Plant Control Systems in Multiple U.S. States

Investigators say internet-exposed programmable logic controllers were accessed, prompting agencies to order their immediate disconnection to prevent further operational disruption.

Overview

  • Minnesota reported intrusions that hit at least 30 municipal water sites on July 26–27, and federal officials say related malicious activity has been identified in at least seven states.
  • Attackers focused on internet-connected programmable logic controllers, changing administrator passwords and network settings to disable remote controls and force operators to run systems manually.
  • The FBI is leading a multistate probe supported by CISA and the EPA, and some officials view Iranian-affiliated actors as a leading suspect even though formal public attribution has not been completed.
  • So far there are no confirmed reports of contaminated drinking water or widespread public-health impacts, but small towns such as Braham temporarily switched to manual operations and asked residents to limit water use.
  • Officials and experts say the incidents expose chronic weaknesses—outdated control devices, default or weak credentials, and underfunded IT staffing—and CISA has urged immediate disconnection of exposed devices while policymakers weigh funding and regulatory options.