Particle.news
Download on the App Store

U.S. Water Systems Hit by Widespread Cyber Campaign

Federal agencies have ordered utilities to disconnect internet‑exposed controllers as an FBI‑led multistate probe assesses the scope and possible policy response.

Overview

  • Federal alerts say attackers remotely accessed internet‑facing programmable logic controllers, changed IP addresses and passwords, and cut off operators’ remote monitoring and control.
  • The intrusion first hit more than 30 municipal systems in Minnesota on July 26–27 and reporting now shows at least a dozen states, including Michigan, Georgia and New Jersey, have seen similar activity.
  • Affected devices include Rockwell Automation MicroLogix 1100 and 1400 series PLCs, small industrial controllers that many utilities never meant to expose directly to the internet.
  • Operational effects reported to investigators have included loss of pressure, localized flooding, temporary boil‑water advisories and a shift to manual operations, but officials say there are no confirmed public‑health impacts to date.
  • The FBI is leading the investigation with CISA and the EPA urging immediate hardening steps, and the incidents have sharpened calls for federal funding, shared cyber services and tighter standards for the fragmented water sector.