FBI is investigating intrusions at nine Michigan utilities and more than 30 Minnesota systems. The federal advisory named the exact mechanism. The bottleneck is who can act on it.
The FBI is investigating cyber intrusions at nine Michigan water systems and more than 30 Minnesota systems, federal and state officials said this week, two days after a Cybersecurity and Infrastructure Security Agency alert named the exact technical target: small utilities' industrial controllers, sitting on the open internet.
Michigan Department of Environment, Great Lakes, and Energy communications director Dale George told the AP via WHEC that all affected systems continued operating safely and no public-health impact had been reported. Minnesota IT Services said as of Thursday it had no active boil-water or usage-modification requests. The intrusions were disruptive, not catastrophic, for now.
The mechanism CISA named is mundane on paper. Attackers went after programmable logic controllers, or PLCs, the small ruggedized computers that run valves, pumps, and chemical feeds at treatment plants. The agency's July 30 advisory said it had observed a significant increase in targeting of internet-exposed PLCs in the water and wastewater sector. Operators reported PLC passwords being changed to lock out staff, and PLC IP addresses being altered to disconnect controllers from the network. The result: boil-water notices, manual operations, and a restoration job for whoever still had physical access to the box.
At the city of Braham, Minnesota, population roughly 1,700, attackers shut down operating controls at the well and treatment plant for several hours on Monday. The water tower reserve kept the town supplied. Plymouth, population about 80,000, lost communications and had them restored by Tuesday afternoon.
FBI investigators are examining whether the activity is the work of Iranian hackers, CBS News reported on Friday, and the bureau has put the number of affected states at at least seven. Attribution is not definitive; investigators are also probing whether an actor is masquerading as Iran-linked. The federal advisory language refers to "activity consistent with" the Iranian pattern, not a confirmed culprit.
The pattern itself is not new. In 2016, the Justice Department indicted seven Iran-linked hackers for breaking into the controls of a small dam near New York City, a case that ended without a trial because the defendants remained in Iran. In 2023, IRGC-affiliated actors hit multiple U.S. water and wastewater facilities through the same vulnerability class, default-password internet-exposed controllers, according to CBS.
The responsibility chain is the part that breaks down. CISA can warn. The FBI can investigate. The EPA regulates large systems and has limited reach over the roughly 50,000 community water systems that serve small towns. States can coordinate. Local operators, often one or two IT generalists with no operational-technology staff, are left to take a controller off the public internet, front it with a VPN, and rotate credentials on a device that was never designed to be on a network in the first place.
The political overlay landed Friday at Camp David. President Trump publicly attributed the incidents to Minnesota and Governor Tim Walz and said he did not believe an Iranian cyberattack had occurred, per the AP. Walz responded on social media that the Trump administration had cut CISA and left the country exposed. Both are political statements; neither is a finding.
The next test is whether the small utilities in the alert's blast radius move the controllers off the public internet before the next attempt. CISA's joint advisory with the FBI and EPA is the playbook. Funding to execute it is a separate question, and one the federal alert does not answer.