
Michigan and Minnesota water systems report cyberattacks as federal agencies warn on exposed PLCs
Michigan and Minnesota water utilities reported cyberattacks as officials urged operators to secure exposed control systems.
Cyberattacks against local water infrastructure widened over the weekend, with Michigan reporting incidents at nine water systems after Minnesota officials had already confirmed malicious activity affecting more than 30 community systems. The Associated Press reported that Michigan officials said all affected systems continued operating safely and that no known public health impacts were identified.
The cases are significant because they hit operational technology rather than only back-office networks. These systems monitor or control pumps, wells, towers, treatment plants, communications links and related equipment. Minnesota IT Services said most confirmed attacks involved technology used for remote monitoring and control, while local operators were able to keep drinking water available.
Why federal agencies are concerned
The incidents followed a federal alert about attempts to tamper with operational technology at water systems. According to AP, the FBI is investigating and has not publicly identified a perpetrator. Federal agencies had warned that Iranian hackers have shown interest in water and wastewater systems, but the current public record does not assign responsibility for the Michigan and Minnesota incidents.
The National Special Districts Association also posted an August 3 update pointing infrastructure operators to CISA guidance and related FBI resources. Its update emphasized that water and wastewater operators should protect operational technology from internet exposure and use federal reporting channels when they suspect an incident.
Operational effects varied by location. AP reported that Braham, Minnesota, asked residents to minimize water use for several hours after attackers shut down operating controls for the city's well and treatment plant, leaving the city temporarily dependent on water stored in its tower. Plymouth, Minnesota, separately said water infrastructure communications had been restored after a cyberattack.
What utilities are being told to do
For small utilities, the episode underlines a familiar security gap: critical equipment often remains reachable through remote access arrangements, legacy networking or shared third-party configurations. Federal guidance referenced by the industry update tells operators to remove direct internet exposure for programmable logic controllers, require strong and unique passwords, restrict remote access to known systems, review controller logic for unauthorized changes and maintain the ability to operate manually.
The broader lesson is that municipal water systems are now part of the frontline cyber risk landscape. Even when attacks do not contaminate water or cause lasting outages, brief losses of visibility or control can force emergency procedures, public notices and expensive incident response. The safest reading of the public evidence is not that every utility was severely disrupted, but that adversaries are actively probing systems whose failure would quickly become a community safety issue.
Sources
Cover photo by Sky Eye Imagery on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment