Overview
- In late July a coordinated campaign first detected in Minnesota targeted internet-connected control devices at municipal water and wastewater sites, forcing many operators to disconnect systems and run plants manually.
- Federal agencies including the FBI, CISA and the EPA confirm ongoing intrusions and say utility operators in at least seven states have reported disruptions while other media reporting suggests the number of states affected may be larger.
- Attackers remotely accessed internet-facing programmable logic controllers, changed IP addresses and passwords, and caused loss of monitoring and control that led to pressure drops and some local flooding at affected facilities.
- Most systems maintained safe service by switching to manual procedures and brief boil-water advisories were quickly rescinded, and there are no government-confirmed reports of widespread water contamination to date.
- Officials recommend removing PLCs from direct internet exposure, using secure gateways and firewalls, and enforcing strong unique passwords, but small, underfunded municipal utilities with limited staff face real obstacles to making those fixes and lawmakers may face pressure to increase aid.