Recent cybersecurity incidents involving Internet-facing programmable logic controllers (PLCs) have been reported by water and wastewater utilities in at least seven states, as highlighted by the FBI and the Environmental Protection Agency (EPA). These incidents, which began on July 27, have seen malicious actors remotely accessing PLCs, including models from Rockwell Automation/Allen-Bradley, leading to changes in device IP addresses and passwords. This has resulted in temporary loss of monitoring and control functions at some facilities, raising significant concerns for cybersecurity decision-makers in critical infrastructure sectors. For further details, refer to the report by GovTech.
Nature of the Cyber Incidents
The reported incidents have caused operational impacts such as pressure loss and flooding, with the potential for untreated groundwater to seep into pipes. The extent of these impacts varies based on the configuration of the PLCs and the ability of utilities to switch affected systems to manual operation. The FBI and EPA have detailed that attackers gain remote access to these PLCs, subsequently altering IP addresses and passwords, effectively locking utilities out of their monitoring and control functions.
Specific Cases in Minnesota
In Minnesota, officials have confirmed that at least 30 community water systems were targeted by malicious cyber activity, prompting an ongoing investigation. While the Minnesota IT Services (MNIT) noted similarities among the attacks, they have not yet attributed them to a specific actor. Importantly, the affected systems have not resulted in water service disruptions, and no public health risks have been reported from these incidents.
Recommendations for Utilities
In light of these incidents, MNIT has issued recommendations that align closely with guidance from the FBI and EPA. Utilities are urged to identify and secure Internet-accessible operational technology, including PLCs and human-machine interfaces. Key recommendations include:
- Removing unnecessary Internet access
- Strengthening access controls and passwords
- Implementing multifactor authentication
- Reviewing logs and configurations
- Separating operational technology from other networks
- Maintaining accurate inventories and offline backups
- Testing incident-response and recovery plans
Ongoing Threat Landscape
The incidents come amid warnings from the Cybersecurity and Infrastructure Security Agency (CISA) and its federal partners about the attractiveness of Internet-connected industrial control systems to malicious actors. An advisory updated on July 22 indicated that Iranian-affiliated attackers have exploited PLCs across various sectors of U.S. critical infrastructure. However, Minnesota officials have not linked the recent incidents to any specific threat actor.
As the cybersecurity landscape continues to evolve, it is crucial for utilities to remain vigilant and proactive in securing their operational technology against potential cyber threats.


