Overview
- Federal and state officials say hackers remotely accessed internet‑facing programmable logic controllers, changed IP addresses and passwords, and disrupted monitoring and control of water pumps and valves during attacks first detected in late July.
- Local operators isolated affected devices and switched to manual operations, and there are no confirmed reports that drinking water quality was compromised.
- The FBI has opened a multistate probe and agencies including CISA and the EPA have issued guidance urging utilities to remove PLCs from direct internet exposure and use secure gateways and stronger access controls.
- Reports vary on scope: the FBI says at least seven states have reported incidents while several media outlets place the number as high as a dozen, with Minnesota reporting more than 30 municipal systems targeted.
- Investigators have not publicly attributed the intrusions; some intelligence and news reports point to Iranian‑linked actors but U.S. agencies have not confirmed a perpetrator, and the incidents have renewed calls for federal funding, standards, and shared cyber services for small utilities.