Overview
- Security officials say the campaign began in late July with more than 30 municipal systems in Minnesota targeted on July 26–27, and reporting has expanded to roughly a dozen states since then.
- Attackers remotely accessed programmable logic controllers, including Rockwell MicroLogix devices, changing IP addresses and passwords on controllers that were directly connected to the internet.
- The intrusions caused drops in pressure and at least one documented flooding event while utilities isolated affected devices, switched to manual controls, and regained control of operations.
- The FBI is leading a multistate investigation and federal agencies have urged operators to disconnect internet‑exposed controllers and harden remote access; analysts say Iran‑linked actors are suspected but attribution remains unconfirmed.
- The incidents exposed long‑standing gaps: many small, locally run utilities use old equipment with weak or default passwords, and officials and industry groups are pressing for federal funding, shared services, and tighter cybersecurity requirements.