Cybersecurity

Hackers target 30 US water systems via exposed controllers

1 min read

Hackers target 30 US water systems via exposed controllers
Photo: Kevin Horvat · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Hackers attempted to breach at least 30 municipal water systems in Minnesota on July 26-27, 2026, and similar cyberattacks have since been reported in Michigan and five other states. The attackers targeted programmable logic controllers—small computers that operate pumps, valves, and other equipment—rather than office networks, aiming to seize control of critical water infrastructure. Utility officials responded by shutting down the control computers and manually operating equipment, and they have stated that the water remained safe to drink. The FBI and Environmental Protection Agency issued a joint advisory on July 30, 2026, confirming that attackers remotely accessed Rockwell Automation MicroLogix controllers connected directly to the internet and changed their IP addresses and passwords. The U.S. government has not yet attributed the attacks, though initial suspicion has fallen on hackers allegedly aligned with Iran. According to the Cybersecurity and Infrastructure Security Agency, some utilities were still using manufacturer default passwords, a vulnerability exploited in similar 2023 incidents involving Iranian-linked hackers targeting Unitronics controllers. Researchers at the National Institute of Standards and Technology warn that intruders could replace legitimate control instructions with malicious commands, potentially disrupting water flow or quality. The attacks highlight the vulnerability of the approximately 152,000 public drinking water systems in the U.S., many of which rely on aging industrial equipment that lacks modern security features and operate with small staffs. In response, the Cybersecurity and Infrastructure Security Agency has urged utilities to remove controllers and dashboards from direct internet connections, use secure gateways or VPNs for remote access, change default passwords, and separate operational networks from business systems. A group of volunteer cybersecurity experts is providing guidance, but smaller utilities may need government funding or shared services to defend against future intrusions.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.