Overview
- Operational technology used by more than 30 community water systems was targeted on Sunday and Monday, July 26–27, leading operators to move some sites to manual controls or backups.
- Minnesota IT Services activated a statewide incident response and federal partners including the FBI and CISA are investigating while supporting affected cities.
- CISA has urged operators to remove internet-exposed programmable logic controllers (PLCs) and isolate operational technology, issuing guidance to limit remote-access paths.
- Investigators have a preliminary assessment that Iran-linked hackers were probably responsible and private researchers say the activity matches patterns tied to the group CyberAv3ngers, though officials say attribution is not yet definitive.
- Small utilities’ internet-exposed PLCs, use of consumer remote-access tools and aging systems increased risk in this campaign and could prompt new state funding, regulation, and wider hardening of water-sector controls.