Particle.news

Cyberattacks Target More Than 30 Minnesota Water Systems

The incidents show that internet‑connected industrial control systems are being actively probed and targeted by foreign actors.

Overview

  • State officials detected coordinated malicious activity against water utility control systems on July 26–27 that involved more than 30 Minnesota community water systems.
  • Investigators have a preliminary assessment that Iran‑linked actors are the likely culprit based on the attackers’ tradecraft and the lack of a ransom demand, though the FBI has not issued a definitive attribution and false‑flag operations remain possible.
  • The intrusions focused on operational‑technology equipment used to monitor and control water systems, including programmable logic controllers (PLCs) and human‑machine interfaces (HMIs), and many utilities restored operations by isolating affected devices, using backups, or switching to manual controls.
  • Federal agencies led by the FBI and coordinated by CISA and the EPA have opened a multiagency response, issued guidance urging utilities to remove direct internet access and change default credentials, and reported related malicious activity in at least seven states.
  • The attacks exposed long‑standing gaps in local water cybersecurity funding and aging, internet‑facing control equipment, and have triggered political dispute over attribution while prompting calls for federal support and faster investments to harden municipal infrastructure.