The Cybersecurity and Infrastructure Security Agency is warning of a rise in attacks on water utilities, telling operators to pull internet-facing programmable logic controllers and other operational technology offline as investigators examine disruptions in Minnesota.
CISA said Thursday that malicious activity against the water and wastewater sector has grown significantly and that attackers are going after utilities regardless of size. Minnesota’s state IT agency said earlier this week that more than 30 community water systems in the state were affected by a coordinated cyberattack that began July 26.
Multiple news organizations reported that state and federal investigators are looking at whether the Minnesota incidents are connected to Iran-linked hackers. Wired reported that a memo from WaterISAC, the water sector’s cybersecurity information-sharing organization, attributed the attacks to Iran. CISA’s Thursday alert did not name Iran.
What did CISA say about water system attacks?
CISA said attackers have changed passwords to keep operators out and altered PLC IP addresses, disconnecting the devices. The agency said the activity has led to boil-water notices and forced some facilities to run manually for extended periods.
A PLC, or programmable logic controller, is operational technology used to control physical processes in industrial settings. In a water system, that kind of device can sit close to the machinery operators rely on, so exposing it to the internet gives attackers a direct path to change configurations or interrupt operations.
CISA said even organizations with strong cybersecurity programs should check outside connections, including cellular modems installed by operators, vendors or system integrators. The agency warned that those connections may be missing from normal scans of internet-exposed assets.
The FBI said utilities in at least seven states have reported PLC-related incidents to the bureau. CISA, the FBI and the Environmental Protection Agency are all involved in the response, according to the federal alert and the FBI’s notice.
The agencies are telling facilities to remove publicly reachable PLCs and other operational technology from the internet as quickly as possible. CISA said internet-exposed OT faces higher risk of website-style defacement, configuration tampering, operational disruption and, in the worst cases, physical damage.
What is known about the Minnesota investigation?
Minnesota officials have described the incident as coordinated and affecting more than 30 community water systems. The public record so far does not establish who carried it out.
Reports from The New York Times, CBS News and Wired said investigators are examining a possible Iran connection. That remains separate from CISA’s latest public alert, which warns about the broader activity but does not attribute it to any country or group.
President Donald Trump addressed the issue Friday during a Cabinet meeting at Camp David, where he blamed Minnesota’s Democratic government and said Iran had larger problems than focusing on Minnesota.
CISA had earlier updated federal warnings about malicious activity targeting industrial operational technology linked to Iran. The new water-sector alert lands as hostilities continue around the Strait of Hormuz and as oil companies report higher profits tied to the conflict’s effect on energy prices.
This story draws on original reporting from The Record.