Overview
- A coordinated intrusion that hit more than 30 Minnesota water systems on July 26–27 has been tied to reports from as many as a dozen states, and the FBI is leading a multistate investigation.
- Attackers remotely accessed internet‑exposed programmable logic controllers (PLCs), changed IP addresses and passwords, and in some cases altered controller files so operators lost remote visibility and control.
- Operational effects included loss of water pressure, localized flooding and fallback to manual operations, but officials say there are no confirmed widespread contamination or public‑health impacts.
- The FBI, CISA and the EPA have issued technical advisories urging utilities to disconnect PLCs from the public internet, use secure gateways and strong access controls, and report incidents to federal field offices.
- The campaign has exposed chronic gaps: many small municipal systems use legacy controllers, run with tiny staffs and limited cybersecurity budgets, prompting calls for sustained federal funding and sectorwide standards.