FBI and EPA say attackers rewrote settings on internet exposed controllers at water plants in at least seven states; Minnesota is still investigating who is behind it.
At water utilities in at least seven U.S. states, operators logged in this week to find their industrial-control equipment's settings rewritten. IP addresses changed, passwords altered, the controllers locked them out. The FBI and EPA said the result was loss of pressure and flooding at treatment plants.
The controllers are programmable logic computers (PLCs) that run valves, pumps, and other equipment at water plants. The targeted models are Rockwell Automation's MicroLogix 1100 and 1400 series, the same product line the FBI and NSA warned about in April when they said Iranian hackers were exploiting internet-exposed units. Four months later, the same controllers were still online, and attackers were rewriting them.
Minnesota reported the largest cluster: more than 30 community water systems hit Sunday into Monday. The state has not formally attributed the activity; U.S. officials reportedly suspect Iran.
The FBI and EPA recommended four mitigations: disconnect PLCs from the public internet, apply firewall rules, use complex unique passwords, and secure IT systems. CISA's water-sector page lists the same controls.
The April warning named the equipment. The July intrusions hit it anyway.