Overview
- A coordinated wave of intrusions in late July affected operational technology at utilities in at least seven states, including more than 30 community systems in Minnesota and nine in Michigan.
- The attackers focused on internet‑connected programmable logic controllers, with agencies reporting intrusions that changed passwords and altered IP settings to disrupt remote control access.
- The FBI, CISA, the EPA and state teams have opened a multistate probe, issued guidance to isolate exposed controllers, and say there are no confirmed contamination events or widespread public‑health impacts so far.
- U.S. officials, cited anonymously in press reports, view Iran as a leading suspect based on tradecraft and targets but forensic attribution has not been completed and the assessment has prompted public dispute from President Trump.
- Cybersecurity experts and officials warn the incidents expose chronic vulnerabilities—aging controllers, default credentials and common remote‑monitoring vendors—and are renewing calls for utilities to remove PLCs from the internet and receive federal support.