Particle.news
Download on the App Store

Hackers Target U.S. Municipal Water Systems by Accessing Internet‑Exposed Controllers

A multistate federal probe follows emergency guidance after attackers accessed controllers that many small utilities expose to the internet.

Overview

  • Federal agencies including the FBI, CISA and the EPA are leading a multistate investigation after intrusions first detected in Minnesota and reported in multiple other states.
  • Attackers focused on programmable logic controllers, or PLCs, the small industrial computers that run pumps, valves and pressure sensors used to move and treat drinking water.
  • Utilities responded by isolating or disconnecting exposed PLCs and operating equipment manually, and officials report no confirmed drinking‑water contamination so far.
  • A July 30 advisory said intruders remotely accessed Rockwell MicroLogix controllers and changed IP addresses and passwords, and agencies have urged placing controllers behind firewalls or VPNs and using unique strong credentials.
  • Security experts warn the incidents show how underfunded small and rural systems with legacy equipment and direct internet links are vulnerable and may need federal funding or shared cyber services to prevent larger disruptions.