Key Takeaways
- The Cybersecurity and Infrastructure Security Agency (CISA) issued a warning that cyber threat actors are targeting programmable logic controllers (PLCs) in water systems, altering passwords to lock out operators.
- Thirty water plants in Minnesota were hit with cyberattacks on Sunday and Monday, prompting boil‑water notices and a return to manual operations in some locations.
- Federal and state investigators are examining whether Iran or Iran‑linked hackers are responsible, though attribution remains preliminary and no formal determination has been made.
- Minnesota IT Services (MNIT) clarified that “impacted” means malicious activity was confirmed on a system’s technology, not that every affected community lost water service.
- No current advisories ask residents to change water use; officials are sharing information with federal partners for a broader national assessment.
- Similar intrusion patterns have been observed in other states, raising concerns about a coordinated Iran‑linked campaign against critical water infrastructure.
- CISA urges water utilities to disconnect PLCs from the public internet, use VPNs or gateway devices for any necessary remote access, and follow hardening guidelines to reduce risk.
- The FBI acknowledges the intrigues but has not assigned blame, pending deeper forensic analysis.
- Ongoing collaboration between Minnesota authorities, CISA, the FBI, and other federal agencies aims to clarify the threat actor’s identity and strengthen defenses nationwide.
Federal Warning Issued
On Thursday, the Cybersecurity and Infrastructure Security Agency (CISA) released an alert warning that cyber threat actors are actively targeting programmable logic controllers (PLCs) used to monitor and control water‑treatment equipment. The advisory noted that attackers are modifying PLC passwords to “lock out operators,” which can disrupt normal control functions and force utilities into manual operation modes. CISA emphasized that such intrusions have already produced boil‑water notices in affected jurisdictions and urged water utilities to review their remote‑access configurations immediately. The alert serves as a nationwide call to action for critical‑infrastructure owners to harden their OT (operational technology) environments against similar incursions.
Minnesota Water Plants Hit
According to Minnesota officials, thirty water‑treatment plants across the state experienced cyber intrusions on Sunday and Monday of the same week. The attacks resulted in several communities issuing boil‑water advisories as operators switched to manual processes while they worked to regain control of automated systems. Minnesota IT Services (MNIT) confirmed that the incidents involved malicious activity against the plants’ control networks but stressed that “impacted” does not necessarily mean a total loss of water service for every affected locality. Instead, it indicates that investigators verified the presence of harmful code or unauthorized changes within the PLCs or related monitoring systems.
Nature of the Intrusion
The attackers focused on gaining remote access to the PLCs that govern pumps, valves, and chemical dosing equipment. By altering default or administrative passwords, they effectively locked legitimate operators out of the control interfaces, forcing facilities to rely on manual overrides. In some cases, the manipulation of sensor readings or control logic could have led to unsafe water chemistry, prompting the preventive boil‑water notices. The intrusion did not appear to cause widespread physical damage to infrastructure, but the potential for harm to public health and safety was sufficient to trigger immediate protective measures.
Investigation Attribution Efforts
Federal and state authorities are actively investigating whether the cyberattacks originate from Iran or hackers acting on behalf of the Iranian government. Multiple U.S. officials told ABC News that early forensic indicators suggest a possible link to Iranian threat actors, but they cautioned that the analysis remains preliminary. Officials are awaiting a more detailed forensic report before drawing any definitive conclusions, and as of the latest statements, no formal attribution has been announced by the U.S. government. The Federal Bureau of Investigation (FBI) confirmed awareness of the intrusions but declined to assign responsibility pending further evidence.
Preliminary Findings and Official Statements
John Israel, Minnesota’s chief information security officer, stated that MNIT has shared all relevant information with the federal government, which is evaluating the activity within a broader national context to determine if a specific threat actor can be identified. He emphasized that the state’s response includes continuous monitoring, coordination with CISA, and assistance to affected utilities in restoring normal operations. Israel also noted that while the attacks have prompted operational disruptions, there have been no active requests from municipalities for residents to alter their water consumption or usage habits at this time.
Clarifying the Term “Impacted”
MNIT issued a clarification to prevent public alarm: the term “impacted” in their communications refers strictly to the confirmation of malicious technical activity on a system’s technology, such as unauthorized PLC access or password changes. It does not automatically equate to a disruption in water delivery or a loss of service for every community served by a compromised plant. Many facilities were able to maintain safe water provision through manual processes while their IT and OT teams worked to eradicate the threat and restore automated controls.
Broader Pattern of Intrusions
The incidents in Minnesota mirror a series of similar cyber intrusions reported in other states over recent months, which security analysts have linked to suspected Iran‑linked actors. Those earlier attacks also targeted PLCs in water and wastewater facilities, employing comparable tactics such as credential theft, password modification, and attempts to hinder remote‑access capabilities. The recurrence of this pattern across multiple jurisdictions has heightened concerns that a coordinated campaign may be underway to test or degrade the resilience of U.S. critical water infrastructure.
Federal Guidance for Utilities
In response to the emerging threat, CISA issued concrete recommendations for water and wastewater utilities: disconnect PLCs from the public internet whenever feasible, and if remote access is required, route connections through a virtual private network (VPN) or a secure gateway device that enforces strong authentication and monitoring. Additionally, utilities should review of network traffic for anomalous behavior, timely patching of OT devices, and implementation of multi‑factor authentication for administrative accounts are highlighted as essential defensive measures. CISA also encouraged participation in information‑sharing platforms such as the Auto‑ISAC to stay apprised of evolving tactics.
Ongoing Coordination and Outlook
The situation remains fluid, with Minnesota officials, CISA, the FBI, and other federal partners continuing to exchange forensic data and threat intelligence. While the immediate danger appears contained through manual operations and advisory notices, the underlying vulnerability of water‑system PLCs to cyber exploitation persists. Stakeholders agree that strengthening the security posture of operational technology—through network segmentation, strict access controls, and regular cyber‑hygiene audits—is critical to safeguarding public health and ensuring the reliability of the nation’s water supply in the face of increasingly sophisticated cyber threats.

