TECH Signal 41
Cyberattacks hit water facilities in seven states across the US
For engineers operating industrial control systems, this confirms that exposed PLCs without proper network segmentation are being actively exploited with physical consequences. The attacks demonstrate that credential and access changes can lock operators out of their own infrastructure, and that pressure loss in water systems creates contamination risks far beyond simple service disruption.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Attackers are specifically targeting internet-facing Programmable Logic Controllers, changing IP addresses and passwords to lock operators out of monitoring and control systems.
The FBI and EPA advise utilities to implement secure gateways, firewalls, stronger passwords, and access control lists to prevent direct internet exposure of control devices.
Over 30 municipal water facilities in Minnesota were infiltrated, with reports suggesting possible Iran-affiliated involvement consistent with a prior CISA warning about state-sponsored targeting of water infrastructure.
THE CLUSTER
↗