Federal and state authorities are investigating coordinated cyberattacks on water and wastewater facilities in at least 12 states, with the first public cluster surfacing in Minnesota and several utilities confirming disruption. Cybersecurity Dive reports officials suspect Iran-linked groups, and the campaign has hit PLCs and human-machine interfaces at sites in Minnesota, Michigan, Georgia, South Dakota, and New Jersey.
The pattern is control-plane exposure: in New Jersey, vulnerable internet-exposed devices briefly blocked operators from managing systems remotely, forcing a shift to manual operation. Rockwell Automation had warned in March that CVE-2021-22681 in Studio 5000 Logix Designer could let an attacker use an unauthorized third-party tool to alter a Logix controller’s configuration, which shows how a reachable controller or HMI can become the point that changes what operators can control.
For utilities with exposed PLCs, HMIs, or vendor tools that reach directly into controllers, the enduring exposure is not just the perimeter but the device that runs the process. The reporting still leaves the entry path and full scope unsettled, but it already shows that losing remote management can be an operational outage even when water service stays safe.