Key Takeaways
- Recent cyberattacks have compromised more than 30 municipal water facilities across seven states, with Minnesota experiencing the largest cluster of incidents.
- Federal officials attribute the Minnesota attacks to likely Iranian interference, though state officials dispute claims of system‑pressure drops triggering alarms.
- The Cybersecurity and Infrastructure Security Agency (CISA) warns that successful intrusions can force boil‑water notices and require prolonged manual operation of plants.
- A federal advisory urges water utilities to eliminate direct internet exposure of programmable logic controllers (PLCs); Raleigh Water confirms it already follows this practice.
- Raleigh Water completed a CISA‑led simulated cyber‑attack stress test last year, successfully defending its systems and reinforcing confidence in its security posture.
- Despite potential disruptions, Raleigh Water emphasizes that its plants can be operated manually and that its highly trained staff can respond swiftly to any outage.
Overview of Recent Cyberattacks on Water Facilities
Over the past few weeks, a wave of cyberattacks has struck water infrastructure in at least seven U.S. states, raising alarms about the vulnerability of essential public services. Reports indicate that more than thirty municipal water facilities in Minnesota were compromised, representing the most concentrated impact observed so far. While the full scope of the incidents remains under investigation, the attacks have prompted heightened scrutiny from federal agencies, state regulators, and utility operators concerned about the potential for service disruption, contamination risks, and public health consequences.
Statements from Raleigh Water Leadership
Ed Buchan, Assistant Director of Raleigh Water, sought to reassure the public that his agency is well‑positioned to withstand similar threats. He acknowledged that speaking in absolutes is unwise in cybersecurity but emphasized that Raleigh Water has undertaken “due diligence” to protect its systems. Buchan’s comments reflect a broader industry sentiment that proactive measures, rather than reactive fixes, are essential for safeguarding water supplies against increasingly sophisticated cyber adversaries.
Details of the Minnesota Attack
Law‑enforcement sources briefed NBC News that the Minnesota intrusion bears the hallmarks of Iranian meddling, suggesting a state‑sponsored motive behind the campaign. The attackers reportedly gained access to supervisory control and data acquisition (SCADA) systems, manipulating operational parameters and triggering alerts across multiple facilities. Although the exact techniques employed have not been disclosed publicly, the pattern aligns with known Iranian cyber‑espionage tactics targeting critical infrastructure abroad.
Conflicting Reports on System Pressure Drops
A spokesperson for the Wisconsin Department of Natural Resources warned that the Minnesota attacks caused system pressures to drop, which in turn activated alarms and prompted a law‑enforcement response. Conversely, a Minnesota official denied that any pressure‑loss incidents occurred, asserting that monitoring data showed normal operating ranges throughout the events. This discrepancy highlights the challenges of obtaining real‑time, accurate situational awareness during cyber incidents, especially when disparate agencies rely on different data streams and reporting protocols.
Federal Guidance and CISA Findings
The Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory noting that some larger cyberattacks on water utilities have resulted in boil‑water notices and forced operators to sustain manual control of treatment processes for extended periods. While CISA refrained from naming specific locations impacted, the warning underscores the potential severity of successful intrusions: loss of automated regulation can jeopardize water quality, increase operational workload, and delay restoration of normal service.
Raleigh Water’s PLC Protections
In response to the federal advisory, Buchan confirmed that Raleigh Water has already removed programmable logic controllers (PLCs) from direct internet exposure, a key recommendation for reducing attack surfaces. He explained that PLCs are integral to modern plants, governing valves, chemical dosing, and other critical functions. Although it is technically feasible to operate a plant remotely via these controllers, Raleigh Water deliberately isolates them from external networks, thereby limiting the avenues through which hackers could gain unauthorized access.
Stress Testing and Simulation Outcomes
Last year, Raleigh Water participated in a simulated cyber‑attack exercise conducted by CISA. Buchan described the experience as a “trying” but valuable test, during which agency professionals attempted to breach the utility’s defenses. The utility’s systems withstood the attempted intrusions, allowing Raleigh Water to navigate the exercise successfully. This outcome validated the effectiveness of existing security controls and provided concrete evidence that the agency’s preparations could withstand real‑world threat actors.
Proactive Measures and Industry Preparedness
Buchan expressed pride in his team’s decision to undertake the stress test ahead of any high‑profile incident, noting that the water industry has long recognized cyber risk as a growing concern. By acting preemptively, Raleigh Water positioned itself ahead of the curve, avoiding the reactive scramble that often follows a breach. The assistant director stressed that continuous vigilance, regular testing, and staff education are essential components of a resilient cybersecurity strategy for water utilities.
Manual Operation Capabilities and Staff Training
Should a cyber incident compromise automated controls, Buchan assured that Raleigh Water’s facilities can still be operated manually. He noted that while many modern industries rely heavily on automation and may struggle to revert to hand‑run processes, water treatment plants retain the procedural knowledge and equipment necessary for manual operation. The utility’s staff are “highly trained” and capable of swiftly adapting to alternative control methods, ensuring that service continuity can be maintained even under adverse conditions.
Conclusion and Assurance to Customers
In summary, Raleigh Water’s combination of hardened PLC networks, recent successful stress testing, robust manual‑operation procedures, and a well‑trained workforce provides a multilayered defense against the rising tide of cyber threats targeting water infrastructure. While no system can be deemed impervious, the utility’s proactive stance offers a credible basis for confidence that its 670,000 customers will continue to receive safe, reliable water service even if malicious actors attempt to disrupt operations. The experience of other states serves as a cautionary reminder, but Raleigh Water’s preparedness illustrates how foresight and investment in cybersecurity can help safeguard essential public health resources.

