Key Takeaways
- The FBI and CISA issued a joint warning that cyberattacks on U.S. water utilities are rapidly increasing, with attackers locking operators out of operational technology (OT) networks.
- Programmable Logic Controllers (PLCs) – the devices that automate pumps, treatment processes, and monitoring – are the primary targets; attackers change IP addresses and passwords to disable remote access.
- Impacts include forced boil‑water notices, loss of water pressure, flooding, and a shift to manual operations in several states.
- Initial coordinated strikes in Minnesota affected more than 30 water systems; evidence points to Iran‑linked threat groups exploiting vulnerable PLCs from Rockwell Automation, Schneider Electric, and Siemens.
- Mitigation steps recommended by CISA, the FBI, and vendors include removing PLCs from the public internet, maintaining offline backups, rotating credentials, and conducting power‑cycle resets to restore device configurations.
Federal Agencies Sound the Alarm on Escalating Water‑Utility Cyber Threats
On Thursday, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory warning that cyberattacks targeting drinking‑water and wastewater treatment facilities have seen a “significant escalation.” The agencies noted that threat actors are increasingly able to compromise Programmable Logic Controllers (PLCs), the industrial computers that automate pumps, valves, and monitoring equipment. By gaining unauthorized access, attackers can lock utility operators out of their own OT networks, disrupting essential services and forcing utilities to resort to manual operations or issue public health advisories such as boil‑water notices.
How Attackers Disable PLCs and Lock Out Operators
According to the advisory, hackers employ two main tactics to cripple PLC functionality: they modify the device’s IP address, which severs communication between the controller and the supervisory control and data acquisition (SCADA) system, and they change or reset administrative passwords, effectively blocking legitimate users from logging in. In several reported cases, these actions have left water system operators unable to monitor flow rates, tank levels, or treatment processes, prompting a rapid shift to manual valve operation and, in some instances, causing untreated water to infiltrate distribution pipes due to lost pressure.
Geographic Spread of the Incidents
The FBI’s public service announcement indicated that the reported attacks have now spread to seven states, following an initial wave that struck Minnesota earlier in the week. While the advisory did not name all affected jurisdictions, it emphasized that the threat is not isolated to a single region. Operators across the impacted states have reported similar symptoms—loss of remote connectivity, unexpected pump shutdowns, and the need to issue boil‑water advisories—suggesting a coordinated campaign rather than isolated, random incidents.
Operational Consequences: Flooding, Pressure Loss, and Public Health Risks
Water utility officials told the FBI that certain attacks have led to tangible physical consequences, including flooding at pump stations and a noticeable reduction in water pressure throughout distribution networks. When pressure drops below safe thresholds, there is a risk that untreated groundwater or sewage can infiltrate clean‑water pipes, potentially contaminating the drinking supply. This scenario has forced some utilities to issue precautionary boil‑water notices to protect public health while they work to restore normal operations and verify water quality.
Minnesota as the Epicenter of the Early Wave
The attacks began on Sunday with a series of coordinated strikes that impacted more than 30 water systems across Minnesota. State officials have not formally attributed the intrusions to a specific actor, but investigators have linked the activity to prior warnings about Iran‑linked threat groups targeting vulnerable PLC devices from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens. The timing and similarity of the tactics used suggest a possible nexus to state‑sponsored or affiliated cyber actors seeking to disrupt critical infrastructure.
Impact on PLCs and Human‑Machine Interfaces (HMIs)
Minnesota officials confirmed that the majority of the compromised systems experienced disruptions to both PLCs and the associated Human‑Machine Interfaces (HMIs)—the graphical screens operators use to view system status and issue commands. When HMIs lose contact with PLCs, operators are left without real‑time data, making it impossible to respond swiftly to anomalies such as over‑pressurization, pump failures, or chemical dosing errors. This dual loss of control and visibility amplifies the operational impact of the cyber intrusion.
Federal and State Response Coordination
In response to the growing threat, the Environmental Protection Agency (EPA) has been working closely with state and local officials, as well as water system operators, to coordinate mitigation efforts. The EPA held a conference call on Wednesday with hundreds of utility representatives to share threat intelligence, technical guidance, and best practices for securing OT environments. The agency emphasized the importance of network segmentation, regular credential rotation, and the removal of unnecessary internet‑facing devices as immediate steps to reduce the attack surface.
Historical Context: Iran‑Linked to Water‑Energy
Iran‑water and‑months since the start of the Iran conflict in February 2024, with a documented focus on exploiting legacy PLCs that lack robust authentication or encryption. Initial campaigns targeted Rockwell Automation’s MicroLogix 1400 series, but recent activity has broadened to include Schneider Electric and Siemens PLCs, indicating that threat actors are updating their toolkits to leverage newly disclosed vulnerabilities across multiple vendors.
Vendor Guidance: Rockwell Automation’s Advisory and Recovery Steps
On Thursday, Rockwell Automation issued its own security advisory concerning the MicroLogix 1400 PLC line, confirming that attackers have been able to change IP addresses and modify passwords to lock out legitimate users. The company outlined a recovery procedure: power‑cycle the device, remove and reinstall the backup battery (or reinsert the battery to clear volatile memory, which erases the altered IP address and program, then restore the last known good configuration from an offline backup. Rockwell also urged customers to maintain regular, air‑gapped backups of PLC logic and to disconnect PLCs from the public internet unless absolutely necessary for remote monitoring.
Broader Recommendations for Water‑Utility Cyber Resilience
Beyond vendor‑specific fixes, CISA and the FBI recommend a layered defense strategy for water and wastewater operators:
- Network Segmentation: Isolate OT networks from corporate IT and the internet, using firewalls and unidirectional gateways where needed.
- Multi‑Factor Authentication (MFA): Enforce MFA for any remote access to PLCs, HMIs, or SCADA servers.
- Patch Management: Apply firmware and software updates promptly, prioritizing devices with known exploitable flaws.
- Continuous Monitoring: Deploy intrusion detection systems (IDS) tailored to industrial protocols (e.g., Modbus, DNP3) to flag anomalous traffic.
- Incident Response Planning: Develop and regularly test playbooks that include procedures for manual operation, water‑quality sampling, and public notification.
Implementing these measures can significantly reduce the likelihood of attackers gaining control over critical water‑infrastructure components and help ensure rapid recovery when incidents do occur.

