Circuit Wire — a daily news update from the Circuit.
The US Cybersecurity and Infrastructure Security Agency told water utilities on July 30 to remove exposed control systems from the public internet. The alert followed a coordinated attack that disrupted operational technology at more than 30 Minnesota community water systems on July 26 and 27.
CISA said it is seeing a significant increase in threat actors targeting programmable logic controllers across the water and wastewater sector. The agency said the activity reaches water entities of all sizes, and that even utilities with mature security programs should recheck their external connections. It singled out cellular modems fitted by operators, vendors or system integrators, which often sit outside routine attack surface scans. "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible," said Nick Anderson, the agency's acting director.
Minnesota IT Services activated the state's incident response and is working with the Department of Public Safety, the Bureau of Criminal Apprehension's Minnesota Fusion Center, the Department of Health, CISA, the Environmental Protection Agency and the FBI. Most confirmed cases involved technology used to monitor and control equipment remotely, including PLCs. Investigators found similarities in the timing of the incidents and in the equipment affected, but have not confirmed that a single actor carried them all out.
Two cities have described what happened. South St. Paul spotted a problem early on Monday and moved public works staff to manual operation, with no break in water or wastewater service. In Braham, north of Minneapolis, crews noticed the well feeding the city water tower was malfunctioning, isolated the system, restored a backup and restarted the plant in about 90 minutes. Mayor Nate George said residents lost no service, and the city has since taken the system off public-facing networks.
Mike Ernster of the Minnesota Department of Public Safety said none of the state's water supply has been reported compromised. The FBI said it is aware of the incident and in contact with victims.
US officials told CBS News that investigators are examining whether Iranian hackers are responsible, and separately whether another actor tried to appear Iranian. Neither the state nor the federal government has attributed the activity publicly. Federal agencies widened an advisory on Iran-linked attacks against industrial controllers on July 22, four days before the Minnesota incidents began. Actors tied to Iran's Islamic Revolutionary Guard Corps reached multiple US water and wastewater sites in 2023 by exploiting internet-connected controllers still running default passwords.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

