Hackers breach water utility controllers in Minnesota and other US states, FBI and EPA warn
Hackers targeted at least 30 municipal water systems in Minnesota on July 26-27, plus systems in Michigan, New Jersey and other states since. They accessed internet-connected PLCs, changing passwords and IPs to lock out operators. Iran-aligned actors are suspected; attribution is
An FBI and Environmental Protection Agency advisory dated July 30 confirms hackers have been accessing internet-connected programmable logic controllers at municipal water utilities, the small computers that automatically run pumps, valves and treatment equipment rather than the office networks utilities normally worry about protecting. At least 30 water systems in Minnesota were targeted on July 26 and 27, and Michigan, New Jersey and several other states have reported similar intrusions since. The attackers did not encrypt data for ransom. Instead, they remotely changed the controllers' passwords and IP addresses, effectively locking utility operators out of the equipment that manages their own water systems. Utilities responded by shutting down the affected control computers and sending staff into the field to run pumps and valves manually. Officials say the water supply itself was not compromised and remained safe to drink throughout. Initial suspicion has fallen on hackers aligned with Iran, based on a memo reported by Wired, though the US government has not officially attributed the intrusions to any actor. The method matters here: locking operators out of their own controllers, rather than encrypting files for payment, points toward disruption as the goal rather than financial extortion, a pattern security researchers have tied to state-linked campaigns rather than criminal ransomware gangs. Federal officials are now urging utilities to remove these controllers from direct internet access and place them behind properly configured firewalls.