Key Takeaways
- Since July 27, water and wastewater utilities in at least seven states have experienced cyber incidents targeting Internet‑facing programmable logic controllers (PLCs), notably Rockwell Automation/Allen‑Bradley models.
- Attackers gain remote access, change PLC IP addresses and passwords, and may reprogram devices, causing temporary loss of monitoring/control, pressure loss, and potential flooding.
- Minnesota reported malicious activity affecting at least 30 community water systems; four utilities publicly disclosed impacts, though no service disruptions or public‑health risks have been confirmed.
- Federal agencies (FBI, EPA, CISA) and Minnesota IT Services advise removing unnecessary Internet exposure, enforcing strong authentication, maintaining offline backups, and regularly verifying controller programming.
- The incidents highlight a broader trend: Internet‑connected industrial control systems remain attractive targets for threat actors, including Iranian‑affiliated groups exploiting PLCs across critical‑infrastructure sectors.
Overview of Reported Cyber Incidents
The FBI and the Environmental Protection Agency (EPA) issued a joint public service announcement revealing that water and wastewater utilities in at least seven states have suffered cybersecurity incidents involving Internet‑facing programmable logic controllers (PLCs) since July 27. While the announcement specifically mentions Rockwell Automation/Allen‑Bradley PLCs, it stresses that operators using other brands should also take protective measures. The agencies did not disclose the names of the affected states or utilities, but they confirmed that malicious actors remotely accessed the PLCs, altered IP addresses and passwords, and in some cases modified the programming that governs pumps, valves, and other equipment. These actions resulted in temporary loss of monitoring or control functions at certain facilities.
Details of Attack Methods on PLCs
According to the FBI and EPA, the attackers’ methodology follows a consistent pattern: first, they establish remote connectivity to PLCs that are directly exposed to the Internet. Once inside, they change the device’s IP address and password, effectively locking the legitimate operators out of the controller’s management interface. In addition to credential theft, the intruders may reprogram the PLCs, altering the logic that dictates how pumps, valves, and other process equipment should operate. This dual approach—denial of access combined with malicious reconfiguration—enables threat actors to disrupt normal plant functions without necessarily causing immediate physical damage.
Operational Impacts and Risks
The alteration of PLC settings has produced tangible operational consequences. Utilities have reported pressure loss within distribution networks, which can create negative pressure zones that allow untreated groundwater to infiltrate potable‑water pipes. In some cases, the loss of control led to temporary flooding or overflow at lift stations and water towers. The severity of the impact depends on how each PLC is configured and whether the utility can quickly shift the affected system to manual operation. While no confirmed service outages or public‑health emergencies have been reported to date, the agencies warn that prolonged or more sophisticated attacks could compromise water safety and reliability.
Minnesota State‑Specific Findings
Minnesota officials released a separate announcement noting that at least 30 community water systems across the state experienced malicious cyber activity, with an investigation ongoing. The Minnesota IT Services (MNIT) bulletin observed similarities among the attacks but stopped short of attributing them to a single threat actor or confirming that the same group was responsible for all incidents. The announcement did not name the manufacturers of the compromised devices or the specific utilities involved. Four Minnesota utilities—Braham, Plymouth, South St. Paul, and Maple Plain—publicly disclosed incidents: Braham’s water plant went temporarily offline; Plymouth noted impacts to automated controls and cellular‑connected equipment at water towers and lift stations; South St. Paul reported a cybersecurity event on automated controls; and Maple Plain declared a temporary emergency. State health officials and the affected utilities have not reported any public‑health risks stemming from the activity, which occurred on July 26‑27.
Response Recommendations from Agencies
Both the federal agencies and MNIT converge on a set of defensive measures for water and wastewater operators. Key recommendations include: identifying and isolating all Internet‑accessible operational technology (OT) assets such as PLCs and human‑machine interfaces; removing unnecessary Internet connections; enforcing strong, unique passwords and implementing multifactor authentication; regularly reviewing PLC logs and configuration files for unauthorized changes; segmenting OT networks from corporate IT and the broader Internet; maintaining accurate inventories of all control‑system components; keeping offline, air‑gapped from the network; and routinely testing incident‑response and recovery plans. These steps aim to reduce the attack surface, detect tampering early, and ensure rapid restoration of normal operations if a breach occurs.
Broader Context and Ongoing Threats
The incidents are part of a wider pattern highlighted by the Cybersecurity and Infrastructure Security Agency (CISA). In an advisory updated July 22 and redistributed July 30, CISA warned that Iranian‑affiliated threat actors have been exploiting programmable logic controllers across multiple U.S. critical‑infrastructure sectors, including water, energy, and manufacturing. The advisory underscores that Internet‑connected ICS devices remain attractive targets due to their often‑lax security configurations and the potential for high‑impact disruption. While Minnesota officials have not linked the state’s water‑system attacks to a specific actor, the federal guidance reflects a growing consensus that utilities must treat OT cybersecurity with the same rigor as traditional IT security.
Conclusion and Outlook
The recent wave of PLC‑focused cyber intrusions serves as a stark reminder that water and wastewater infrastructures are not immune to sophisticated digital threats. Although the observed attacks have so far caused only temporary operational disruptions and no confirmed public‑health harm, the potential for more severe consequences—such as widespread contamination or prolonged service loss—remains real. By adhering to the recommended hardening practices—limiting Internet exposure, strengthening authentication, monitoring for unauthorized changes, and preparing robust response plans—utilities can significantly mitigate their risk. Continuous vigilance, information sharing among federal, state, and local partners, and investment in OT‑specific cybersecurity capabilities will be essential to safeguard the nation’s water supplies against evolving cyber threats.

