The nation's top cybersecurity agency is warning of escalating attacks on water systems after coordinated hackers targeted more than 30 Minnesota utilities on July 26-27. The hackers accessed programmable logic controllers (PLCs), changed passwords, and locked out operators – forcing some systems into manual mode and triggering boil-water advisories.
The Cybersecurity and Infrastructure Security Agency (CISA) says threats against water and wastewater infrastructure are rising, with earlier warnings focused on Iranian-affiliated actors. None of Minnesota's water supply has been reported compromised as a result of the recent attack.
Acting CISA Director Nick Anderson confirmed significant increase in cyber threats targeting PLCs at water utilities. Anderson urged critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.
Markus Mueller, field chief information security officer at Nozomi Networks, told CSO Online that "this is a first-of-its-kind distributed attack on water utilities, and based on the publicly available information, it was clearly aimed at disruption rather than financial gain.”
U.S. Sen. Amy Klobuchar, D-Minn., released a statement on the attacks saying, “I’ve requested a briefing from the CISA on the ongoing investigation and the potential involvement of foreign actors; protecting our critical infrastructure and the safety of Minnesotans remains a top priority.”
The incident is under federal investigation, as the rise in foreign cyberattacks highlights vulnerabilities and the need for stronger protections on critical infrastructure.




