Particle.news
Download on the App Store

Hackers Target Internet‑Connected Controllers at Dozens of U.S. Water Utilities

Federal agencies opened a multistate investigation and told utilities to disconnect exposed controllers because the intrusions revealed widespread, long‑standing cybersecurity gaps.

Overview

  • On July 26–27 attackers remotely accessed programmable logic controllers at more than 30 Minnesota municipal sites and similar incidents were later reported in at least a dozen states.
  • The intruders reached controllers that were directly connected to the internet and changed device IP addresses and passwords, with the FBI naming Rockwell MicroLogix models among those accessed.
  • Operators countered the intrusions by taking control systems offline and switching to manual operation, and officials say there is no confirmed contamination of drinking water despite pressure loss and at least one flooding event.
  • CISA, the FBI and the EPA have issued urgent guidance that tells utilities to remove PLCs from direct internet access, use firewalls or VPNs, change default passwords and apply other hardening steps while the probe continues.
  • Security experts say the attacks expose chronic problems: tens of thousands of small, underfunded water systems run legacy controllers made for convenience not security, prompting calls for sustained federal funding, mandatory standards and shared cyber services.