Hackers logged into internet exposed control equipment, changed passwords, and forced some plants into manual operation. No contamination confirmed yet.
The federal government told America's water utilities to do one thing last week: take the controllers off the public internet. Whether or not hackers keep hitting municipal water plants will turn on whether utilities listen.
A joint FBI and EPA public service announcement and a parallel CISA alert (CISA is the federal Cybersecurity and Infrastructure Security Agency) on July 30 warned that malicious actors are logging into industrial controllers at water and wastewater plants, changing passwords and IP addresses, and locking out the operators who run them. The count of affected states has climbed from seven at the time of the advisory to at least 12 by Aug. 4, according to public reporting.
The attack pattern is the same in every case. The targets are programmable logic controllers (PLCs), the ruggedized computers that physically open valves, run pumps, and switch treatment steps. Many of these devices sit on the public internet, reachable through remote-access tools, undocumented cellular modems, or default vendor settings. Once inside, the attacker changes the device password and the network address, severing the operator's connection. The plant keeps running only because staff switch to manual control on the floor.
Minnesota took the worst of it. State officials confirmed that more than 30 municipal water facilities were targeted between July 26 and 27. Michigan reported incidents, as did Rapid City, South Dakota. A Michigan Department of Environment, Great Lakes, and Energy spokesperson told NBC News that "all systems continued to operate safely." Minnesota's IT services agency said there was no evidence of drinking water contamination.
No utility has reported confirmed drinking water contamination as of the latest state count. The reported harms are operational: pressure loss, alarms disabled, boil-water notices issued, and staff pulled into round-the-clock manual operation. A switch to manual mode is the kind of incident that fades from headlines the moment a plant returns to automatic control, even though it eats staff time and shrinks the margin for the next failure.
The FBI and EPA named Rockwell Automation and Allen-Bradley PLCs specifically in their advisory. CISA's parallel alert treats the problem more broadly: any internet-exposed operational-technology controller is at risk, regardless of vendor, because the entry point is exposure and default credentials, not a zero-day in any single product.
Attribution is contested. The FBI and EPA have not officially named a suspect. Unnamed officials and outside cybersecurity experts have pointed to similarities with past Iran-linked activity, according to ABC News. President Trump has publicly disputed that attribution and blamed Minnesota's state leadership. Governor Tim Walz has responded by pointing to recent federal cybersecurity workforce reductions and broader Iran tensions. The political fight is live; the technical advice is not in dispute.
That advice is short and concrete. CISA tells utilities to remove publicly exposed PLCs and other operational technology from the public internet, validate every external connection including undocumented cellular modems, enforce strong password protocols, and limit remote access to credentialed, logged users. CISA has stopped short of mandatory standards: the water sector is not covered by the same federal cybersecurity rules that apply to electric utilities, which face enforceable reliability standards through the North American Electric Reliability Corporation. The water sector relies on voluntary guidance and whatever state-level rules happen to apply.
The next data point is whether the state count keeps climbing after the advisory. The FBI and EPA have asked utilities to report incidents, and the Aug. 4 coverage shows the count is still moving. The second-order question is whether the federal posture changes: voluntary guidance works when the entry point is configuration, and breaks when the entry point is a vendor flaw the sector cannot fix on its own.
For now, the wave looks like an exposure story, not an attribution story. Same controller, same default settings, same remote-access path, hit plant after plant. The fix lives on the utility side of the network. The agencies have said so out loud; the question is who acts first.