CISA warned water and wastewater operators on July 30 to remove internet-exposed programmable logic controllers after PLC attacks targeted operational technology at more than 30 community water systems in Minnesota. Minnesota IT Services said malicious activity occurred on July 26 and 27, while state and federal authorities continued investigating the incidents. Officials reported no effect on drinking water quality and had not publicly attributed the campaign.

The federal alert said CISA has observed a significant increase in malicious activity against PLCs across water systems of every size. The agency issued the warning days after Minnesota communities including Braham, Plymouth, Maple Plain and South St. Paul reported disruptions involving automated or remotely connected equipment. The FBI, CISA and Minnesota agencies are supporting the investigation, according to Associated Press and SecurityWeek reporting.

CISA said attackers have changed PLC passwords to lock out operators and altered controller IP addresses to disconnect devices. Such interference has led affected facilities to sustain manual operations and, in some incidents observed by the agency, issue boil-water notices. CISA also cautioned that cellular modems installed by utilities, vendors or integrators may create undocumented external connections that routine attack-surface scans miss.

In Braham, officials initially took the water plant offline and asked residents to conserve water while crews investigated. The city later said malicious actors shut down operating controls, stopping the well and treatment plant, but service was restored and water quality was not affected. Plymouth said crews maintained operations while communications to equipment connected through cellular links were restored. Minnesota IT Services emphasized that confirmed malicious activity did not mean every targeted community suffered a service disruption.

CISA advised operators to disconnect PLCs from direct internet exposure and route required remote access through a secure gateway or virtual private network. It also recommended enabling password protection, replacing default credentials, restricting connections to allowlisted IP addresses and retaining a known-clean PLC image for recovery if attackers change a password. Operators should review the tactics and indicators in joint advisory AA26-097A for evidence of current or earlier compromise.

The July 30 alert did not name a threat actor, and investigators had not determined whether one actor was responsible for every Minnesota incident. Although a separate federal advisory described Iran-linked activity against industrial controllers, officials had not formally connected that activity to these attacks. Water utilities should therefore prioritize verified exposure reduction, recovery testing and monitoring while the investigation continues.