Michigan officials confirmed on August 2 that cyberattacks had targeted water systems in the state, joining at least seven states reporting similar incidents since July 27. The attacks focused on internet-connected programmable logic controllers (PLCs), which monitor and control industrial equipment at water and wastewater facilities.
The FBI and Environmental Protection Agency (EPA) issued a joint warning on July 30, alerting utilities to malicious cyber actors altering device passwords and IP addresses. Some incidents resulted in loss of pressure, raising concerns about potential contamination risks if untreated groundwater enters drinking water pipes through leaks. Federal agencies urged operators to remove exposed control systems from the public internet and implement stronger cybersecurity measures.
State and Federal Responses
Michigan’s Department of Environment, Great Lakes and Energy stated that local operators addressed the issues, with no known public health impacts. Dale George, the department’s communications director, noted that all systems continued to operate safely. The FBI confirmed that attacks occurred in at least seven states between July 27 and 30, targeting Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 PLCs.
In Minnesota, state officials reported more than 30 attacks on water systems, the largest publicly disclosed cluster of incidents. The state has not yet identified the perpetrators or the full scope of disruptions. Federal agencies have not publicly named the affected states beyond Michigan and Minnesota.
Technical Details and Vulnerabilities
The FBI described the attacks as targeting internet-facing PLCs, which allowed hackers to gain remote access. Consequences included flooding, pressure loss, and disrupted monitoring capabilities. Utilities were advised to switch to manual operations where possible and secure systems behind firewalls.
The Environmental Protection Agency emphasized that the severity of any disruption depends on the affected equipment and the ability to maintain operations manually. Federal officials warned that significant pressure loss could allow untreated water to enter drinking systems, posing health risks.
Broader Implications
The incidents highlight ongoing vulnerabilities in critical infrastructure cybersecurity, particularly for water and wastewater systems. The FBI and EPA have urged utilities to isolate control systems from direct internet exposure and implement layered security protocols. The attacks follow a pattern of increasing cyber threats to public services, prompting calls for enhanced federal oversight and industry-wide safeguards.