• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Sci-Fi

CISA warns hackers are increasingly targeting US water systems after Minnesota attack

July 31, 2026
Share on FacebookShare on Twitter

A coordinated intrusion knocked out industrial controllers at more than 30 Minnesota water systems. The US cyber-defence agency is telling utilities to get that hardware off the internet.


The US cyber-defence agency has warned that hackers are increasingly targeting the country’s water systems, urging utilities to lock down the industrial controllers that keep taps running.

CISA issued the alert days after a coordinated attack knocked out equipment at more than 30 water systems across Minnesota, echoing an earlier case in which Poland’s water plants were breached through default passwords.

The Minnesota attack was the trigger. Over the weekend of 26 July, intruders reached the programmable logic controllers that automate treatment and pumping, locking operators out and forcing several towns to run their systems by hand.

Four municipalities were named. Plymouth, South St. Paul, Maple Plain, and Braham were among those hit, with at least one municipal well and treatment plant taken offline before staff restored service, usually within about 90 minutes.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

One official put the danger bluntly. Attackers could “turn the well off, basically,” a stark description of what happens when someone else controls the machinery that moves and cleans a town’s water.

Officials stressed that the water stayed safe. No municipality asked residents to change how they used their taps, and drinking water was not contaminated, though the scare exposed how thin the margin can be.

CISA framed this as a pattern rather than a one-off. The agency, itself recently caught without an incident-response playbook when it was hacked, said Iranian-affiliated actors have been exploiting internet-exposed controllers across water, energy, and government networks.

The technical detail is alarming. According to CISA’s advisory, attackers have downloaded and altered controller project files and manipulated the code modules that run safety logic, disabling alarms so operators would not notice the tampering.

The vulnerable hardware is everywhere. The advisory named controllers from Rockwell Automation, Schneider Electric, Siemens, and Unitronics, the workhorses of industrial automation that were never designed to sit exposed on the open internet.

Much of the weakness is basic. Investigators pointed to unsecured controllers, default passwords, poor network segmentation, and misconfigured software rather than exotic exploits, the same failings that have dogged the sector for years.

Where a specific flaw was involved, it was an old one. CISA highlighted a 2021 authentication-bypass bug in Rockwell controllers, rated 9.8 out of 10 for severity, that still has no vendor patch and must be mitigated by other means.

The agency’s advice was concrete. It told operators to disconnect controllers from the public internet, set physical mode switches to “run,” segment IT and operational networks, and require multi-factor authentication for remote access.

The scale of the exposure is daunting. The US has between 150,000 and 170,000 water systems, many of them small and rural, run by staff with little budget or expertise for cybersecurity.

Regulators have flagged the gap before. The EPA has said more than 70% of US water systems were failing to comply with a 2018 law requiring updated risk assessments, and an audit found scores of high-risk vulnerabilities among systems serving nearly 200 million people.

Attribution points to a familiar group. The Minnesota intrusion is suspected to be the work of CyberAv3ngers, an Iran-linked crew that hit Pennsylvania water equipment in 2023, though state officials have not formally named a culprit.

The episode fits a wider trend of state-linked hacking. Western governments have moved to sanction Russia’s cyber ecosystem and to rehearse infrastructure attacks in purpose-built training ranges, a sign of how central water, power, and transport have become as targets.

For water utilities, the message is uncomfortable. The tools to break in are cheap, the defences are often weak, and the next attack may not stop at 90 minutes of manual pumping.

Next Post

Tecno's borderless phone concept looks too good to be real

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • 4 reasons why I switched to this Google Maps alternative
  • Best headphones deal: Save $110 on Skullcandy Crusher
  • Tesla is reportedly weighing a China sell-off to clear the way for a SpaceX merger
  • BMW Group drives digital cockpit, automated driving future with Qualcomm
  • Lloyds Bank bets on AI to cut £2bn in costs by 2030 as profits jump

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously