US cyber defence agency warns of water attacks after Minnesota targeted
The Cybersecurity and Infrastructure Security Agency has issued a formal warning regarding a surge in attacks on water and wastewater systems across the United States. These incidents involve hackers compromising programmable logic controllers that regulate critical infrastructure. By modifying access credentials, attackers have successfully locked out legitimate operators, forcing some facilities to initiate manual oversight and issue boil water notices to local communities.
This advisory follows a coordinated breach affecting more than 30 community water systems in Minnesota late last month. State IT officials confirmed that malicious activity occurred on July 26 and 27, where equipment was remotely accessed and controlled. While not all systems suffered service disruptions, the event triggered a federal investigation into the origin of the interference.
Investigators are currently examining potential ties to Iran, though officials emphasize that this assessment remains preliminary. Tensions in the Middle East have long fueled concerns about the vulnerability of American utility networks to state-sponsored sabotage. Federal agencies have documented a history of foreign groups targeting industrial control devices, particularly those connected to the public internet.
With over 150,000 public drinking water systems and 16,000 wastewater facilities nationwide, the scale of the risk is substantial. CISA has previously released specific guidance regarding compromised industrial devices, including those manufactured by Rockwell Automation. As the investigation continues, federal authorities are coordinating with local IT departments to identify specific threat actors and harden infrastructure against further unauthorized access.

