News Summary

  • The U.S. Federal Bureau of Investigation (FBI) announced on July 30 that malicious cyber actors have targeted programmable logic controllers (PLCs) in water and wastewater systems across at least seven states, with some attacks "resulting in degraded water treatment operations."

  • Minnesota's IT services department announced on Thursday, July 31, that state, local, and federal officials have responded to "malicious cyber activity targeting technology in more than 30 community water systems" in the state; Michigan reported on Saturday, August 1, that nine water systems in the state were cyberattacked but stated all systems are operating safely. Authorities did not disclose other affected states.

  • The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) recommend that water utilities disconnect PLCs from the internet, enable password protection, and restrict remote access.

In-Depth Analysis

CISA warned in a July 22 advisory that "Iranian-linked cyberattacks continue to target internet-connected operational technology (OT) devices" (including PLCs), "resulting in operational disruptions and financial losses."

According to the FBI advisory, attackers at water facilities remotely accessed internet-facing devices and changed IP addresses and passwords, causing loss of monitoring and control functions. Attackers last week targeted Rockwell Automation/Allen-Bradley brand PLCs, but the FBI noted that "similar risks should be considered for PLCs of other brands."

CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. "These threat actors are targeting water entities of all sizes," CISA said in a July 30 alert. "Even water organizations with mature cybersecurity processes should verify their external connections, as such attack campaigns include cellular modems installed by operators, suppliers, or system integrators that may not be documented or included in routine attack surface scans."

Water systems are particularly vulnerable to cyberattacks due to the industry's high fragmentation. Sean Tufts, chief technology officer for the industrial sector at cybersecurity firm Claroty, said in an email: "Minnesota has fewer than 100 electric utilities but more than 1,000 water systems serving about 5 million residents. Many of these systems are run by small teams and tight budgets, which creates the uneven security environment attackers seek."

The incident is notable because attackers targeted more than 30 systems simultaneously, indicating "shared dependencies, whether common technology, service providers, or a broader state-level IT backbone," Tufts said.

He added that the attacks on Rockwell PLCs in Minnesota should create urgency beyond the state, as Rockwell controllers "are widely used in critical infrastructure and have increasingly become an attack vector since the start of the conflict with Iran."