Cyber Incident Victim: Michigan
Timeline
Summary
A coordinated cyberattack targeted operational technology at water and wastewater facilities across multiple states, including Michigan, causing service disruptions and prompting boil water advisories in some communities. Federal officials and cybersecurity experts noted that the attackers exploited internet‑exposed devices with default credentials, and the FBI confirmed that at least seven states experienced similar incidents. While investigators have not attributed the attacks, officials have expressed suspicion of Iranian involvement based on prior activity and current geopolitical tensions. Water sector information‑sharing groups convened calls and the EPA hosted a webinar to share threat intelligence and note measures such as changing default passwords and disconnecting industrial devices from business networks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Between July 26 and July 28, several local authorities in Minnesota reported problems at community water plants from Braham to Maple Plain, where officials declared a brief state of emergency before determining that the immediate threat to public health, safety and welfare had been addressed. In Braham, crews took the plant offline, urged residents to conserve water while drawing on a backup supply stored in a local tank, and restored flow after a couple of hours by taking manual control of the pump. Similar outages occurred in Plymouth and other Minnesota communities, as well as in New Jersey and Michigan, as part of a coordinated cyberattack targeting operating technology at over 30 water systems nationwide. The attacks disrupted industrial control devices but did not compromise the water supply itself. The self‑proclaimed homemade pie capital of Minnesota still hosted its annual Pie Day celebration at the Park Cafe just days later, indicating that daily life resumed quickly after the incident. The incident inspired headlines and provoked uncertainty among residents and officials about the vulnerability of critical infrastructure.

Local and federal officials responded by convening information‑sharing calls through WaterISAC for its roughly 400 members, and the EPA hosted a publicly available webinar to discuss the urgent operational matter. The FBI confirmed that at least seven states experienced similar attacks on water and wastewater facilities and said its investigation is ongoing. Officials noted that the scope and scale could be larger, with concerns about impacts to transportation and energy sectors, and some experts linked the activity to the Iranian Revolutionary Guard Corps based on intelligence. Efforts such as Project Franklin, the Water Watch Center, and a DARPA‑funded initiative to train AI agents for real‑time defense of operational technology were mentioned as ongoing responses aimed at improving sector resilience. The water sector comprises more than 150,000 water and wastewater treatment systems across the United States, underscoring the broad potential reach of such attacks. Officials emphasized the need to get visibility into local systems, hunt for hackers, and improve coordination despite chronic underfunding and expertise gaps in the sector.
