Overview
- State officials say more than 30 municipal water systems in Minnesota were targeted in a coordinated campaign in late July, and the FBI warned of related intrusions in at least seven states while other reporting counts as many as 12 states.
- Attackers focused on internet-facing programmable logic controllers and remote access nodes, exploiting default or weak passwords, unpatched flaws, and misconfigurations to lock out operators or degrade control systems.
- Federal investigators from the FBI, CISA, and the EPA are conducting forensic probes and view Iran-linked actors as a leading hypothesis but have not publicly confirmed formal attribution.
- Immediate responses include CISA/EPA guidance to remove or firewall exposed controllers, utilities using manual workarounds or temporary boil advisories where needed, and the launch of the Water Watch Center to deliver managed cyber services to small utilities.
- Lawmakers introduced the Water Cyber Shield Act to give the EPA authority to set and enforce baseline cybersecurity, require incident reporting and risk assessments, and provide funding aimed at upgrading under-resourced local water systems.