On Thursday, the Cybersecurity and Infrastructure Security Agency (CISA) released a nationwide alert after identifying a pattern of attacks against programmable logic controllers (PLCs), the industrial devices commonly used to automate essential infrastructure such as water treatment facilities.
CISA warned that attackers were not simply probing systems—they were actively attempting to seize control by locking legitimate operators out.
“This activity has resulted in boil water notices and sustained manual operations,” CISA said.
The federal warning followed Minnesota’s public acknowledgment that numerous municipal water systems had been targeted on Sunday and Monday. Officials emphasized that while malicious activity had been confirmed, the impact varied from one community to another.
According to multiple U.S. officials who spoke with ABC News, investigators are evaluating whether Iran or hackers operating on behalf of the Iranian regime may have been behind the attacks. Those officials stressed that the digital forensic investigation is still underway and that the federal government has not formally attributed the incidents to any specific threat actor.
The New York Times previously reported that authorities were investigating possible Iranian connections, adding further attention to the rapidly developing case.
Minnesota IT Services said the attackers focused on remote monitoring and industrial control technology used by local utilities. Among the targeted equipment were programmable logic controllers, which help automate essential functions inside water infrastructure.
Officials explained that a confirmed intrusion does not necessarily mean residents lost access to clean drinking water or experienced service interruptions.
“In this situation, ‘impacted’ means investigators confirmed malicious activity involving a system’s technology. It does not mean every affected community experienced a disruption to water service,” the agency said in a statement.
State officials also sought to reassure residents that no immediate changes in water usage are currently being recommended while investigators continue reviewing the attacks.
Minnesota Chief Information Security Officer John Israel said the state has already shared technical evidence with federal authorities, who are now coordinating the broader investigation.
“We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor,” Israel said in a statement.
The FBI confirmed it is aware of the cyber incidents but stopped short of assigning blame while investigators continue collecting evidence.
Cybersecurity experts note that the attacks resemble previous campaigns directed at American industrial control systems, particularly those connected to water utilities. Federal agencies have repeatedly warned in recent years that hackers linked to Iran have demonstrated interest in targeting internet-connected infrastructure, especially systems that are exposed online.
Those warnings have become increasingly urgent as local governments continue relying on aging operational technology that often lacks modern cybersecurity protections.
In response to the latest attacks, CISA urged water utilities nationwide to review their security practices immediately. The agency recommended disconnecting internet-facing programmable logic controllers whenever operationally possible.
For facilities that require remote management, officials advised routing access through a secure virtual private network or dedicated gateway rather than exposing critical systems directly to the internet.
The investigation remains ongoing, and federal authorities have not announced when a formal attribution decision could be made. Until then, cybersecurity officials continue urging operators of critical infrastructure to remain on heightened alert as concerns grow that America’s essential public services remain attractive targets for sophisticated foreign cyber actors.


