
Cyberattacks aimed at water utilities are expanding across the United States, according to new warnings from federal agencies, after incidents involving operational control equipment were reported in at least seven states.
The FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA) said utilities have experienced attempts to interfere with the systems that help operate drinking water and wastewater facilities. The agencies warned that attackers have gained remote access to internet-connected control devices, preventing some operators from managing equipment normally.
Federal officials said the attacks focused on programmable logic controllers, commonly called PLCs. These controllers are used to automate equipment such as pumps and other parts of water treatment systems. Investigators said attackers have locked operators out by changing device settings, including passwords and network information. Some incidents also involved changes to the programming that controls pumps, valves, and related equipment.
The operational effects have varied. Authorities said some utilities reported flooding, while others experienced drops in water pressure. Lower pressure can create conditions where untreated groundwater could enter water pipes. A number of utilities have also had to run their systems manually while restoring access to their equipment. Federal agencies said some communities elsewhere have issued boil-water notices after similar disruptions, although officials have not linked those notices to specific states in the latest announcement.
The latest warnings follow a coordinated wave of cyber activity in Minnesota on July 26 and 27. State officials said more than 30 community water systems were affected. The incidents involved operational technology, including PLCs and the computer interfaces operators use to monitor and control water systems.
Minnesota officials said the attacks disrupted automated operations in several communities, including Braham, Plymouth, South St. Paul, Maple Plain, and St. Cloud. In Braham, the water treatment plant was temporarily taken offline for less than two hours before service was restored. Other utilities switched to manual operations after automated controls were affected. State health officials said they are not aware of any public health risks connected to the incidents, and officials said water quality remained safe in the affected communities.
The investigation is continuing, and authorities have not publicly identified who carried out the attacks. Minnesota officials said they have not attributed the activity to any specific threat actor. Federal agencies have also avoided naming a responsible group in the broader incidents reported across multiple states, saying attribution requires additional investigation.
Minnesota IT Services activated its statewide cyber incident response program after the attacks were discovered. The agency is working with the FBI, CISA, the EPA, the Minnesota Department of Health, local utilities, and other partners to investigate what happened, support recovery efforts, and share technical information with affected organizations. Officials said the response includes helping utilities contain the attacks, restore operations, and monitor for related activity.
At the federal level, agencies are urging utilities to reduce exposure of operational equipment connected to the internet. Recommended steps include limiting remote access, using stronger authentication, reviewing system configurations, maintaining offline backups, separating operational technology from other networks, and checking controller programming for unauthorized changes.
Rockwell Automation also issued guidance after attackers targeted some of its MicroLogix 1400 controllers. The company said customers who were locked out of affected devices may be able to restore access by powering the units down, removing and reinstalling their batteries, and then restoring their systems from backups. It also encouraged customers to keep those controllers off the public internet whenever possible.
This image is the property of The New Dispatch LLC and is not licenseable for external use without explicit written permission.







