Driving the news: Michigan reported Saturday that nine of its water systems were hit by cyberattacks. That follows more than 30 confirmed intrusions in Minnesota earlier this week. Federal officials tell the New York Times that Iran is the chief suspect.
The FBI and CISA have not formally attributed the attacks. Both agencies confirmed they are 'fully engaged.' The forensic analysis is ongoing.
By the numbers: - 30+ water systems hit in Minnesota - 9 systems impacted in Michigan - At least 7 states targeted in total - 5 additional unidentified states flagged by the New York Times
How they did it: Hackers targeted programmable logic controllers. They changed passwords. That locked out operators and forced some facilities into manual mode. Braham, Minnesota — population ~1,700 — lost its well and treatment plant for several hours. Plymouth, a city of 80,000, had communications restored by Tuesday afternoon.
Reality check: No public health impacts were confirmed. Michigan's Dale George said all systems 'continued to operate safely.' Minnesota IT Services said no residents were asked to change their water usage.
Between the lines: Small municipalities are the soft underbelly of critical infrastructure. Braham's mayor put it plainly: 'IT infrastructure upgrades are very costly and we are a very small municipality.' CISA's fix is straightforward — disconnect controllers from the open internet, use a VPN. Many systems simply haven't done it.
The bottom line: Whether or not Iran pulled the trigger, this attack exposed a real gap: America's water infrastructure runs on aging, internet-facing controls that local governments cannot afford to harden. Washington can issue alerts. The bill still lands on small-town taxpayers.
