CISA warns of spike in attacks on water systems as Minnesota incidents probed

The federal cybersecurity agency is reporting a “significant increase” in malicious activity aimed at water utilities, as investigators are reportedly trying to determine whether recent incidents in Minnesota might be the work of Iran-linked hackers.
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” PLCs — programmable logic controllers — are at the core of processes in multiple industries.
Multiple news outlets reported that state and federal investigators were working to determine whether disruptions to water systems in Minnesota earlier this month were connected to Iran. Wired magazine reported that a memo from the WaterISAC, the industry’s cybersecurity information-sharing body, said the attacks were tied to Iran.
Minnesota’s state IT agency said earlier this week that “more than 30 Minnesota community water systems” were affected by a coordinated cyberattack beginning July 26. The threat actor is “targeting water entities of all sizes,” CISA said.
The intruders “have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses,” CISA said. “This activity has resulted in boil water notices and sustained manual operations.”
CISA, the FBI and the Environmental Protection Agency are all involved in the response. The FBI said “utility companies in at least seven states” have reported incidents involving PLCs to the bureau.
At a Cabinet meeting at Camp David on Friday, President Donald Trump placed the blame on Minnesota’s Democratic government. “Iran's got bigger problems than worrying about Minnesota," he said.
Earlier this month, CISA updated previous warnings that industrial OT was facing malicious activity linked to Iran.
Thursday’s alert does not mention Iran.
“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” CISA said. “OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”
Hostilities continued around the Strait of Hormuz on Friday, as oil companies reported massive profits related to the conflict’s effects on energy prices.
References in this story
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs | CISA www.cisa.gov
- U.S. investigating if Iran was behind cyberattack on water systems in 7 states, including Minnesota www.cbsnews.com Malicious cyber activity affected technology at water systems in at least seven states this week, including Minnesota, leading authorities to dig into whether Iranian actors are behind the attack, CBS News has learned.
- A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran www.wired.com A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
- 400 Bad Request mn.gov
- Aaron Rupar (@atrupar) on X x.com Trump: "We heard in Minnesota there was a cyberattack and they blame it on Iran. I don't think so. I blame it on Minnesota because they're grossly incompetent. Iran's got bigger problems than worrying about Minnesota."
- Federal agencies broaden alert on Iran-linked OT attacks therecord.media The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
- Major oil companies reap massive profits as US and Iran fighting drives energy prices higher apnews.com Major oil companies reported massive profits while fighting between Iran and the U.S. impeded petroleum shipments.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Joe Warminsky (@jwarminsky.bsky.social) bsky.app News Editor at The Record: @therecordmedia.bsky.social [ Tired of bios ] [ Often thinking about music ] [ Etc. ]


