Overview
- A coordinated intrusion that investigators traced to more than 30 Minnesota community water systems on July 26–27 targeted internet‑connected operational technology used to monitor and control pumps and valves and forced some operators to switch to manual controls.
- The FBI, CISA and the EPA say at least seven states have reported similar incidents and federal teams are conducting a multistate probe and sharing technical guidance with affected utilities.
- U.S. and state investigators point to Iranian‑affiliated actors because of the attackers’ tradecraft and the lack of any ransom demand, but officials emphasize that formal forensic attribution has not yet been completed.
- State and local officials report no evidence that drinking water was made unsafe and no active boil‑water orders, and many utilities maintained service by isolating affected controllers and using manual workarounds per federal guidance.
- Cybersecurity experts say the campaign highlights recurring weaknesses—internet‑exposed programmable logic controllers, default or weak credentials and underfunded, aging systems—and could spur requests for federal help and investment in industrial control security.