What happened
Starting July 26, 2026, a coordinated cyberattack hit more than 30 community water systems across Minnesota. Minnesota IT Services (MNIT) confirmed the attackers changed operator passwords and altered the IP addresses of programmable logic controllers (PLCs) — the small industrial computers that open valves, run pumps, and dose chemicals — locking staff out of systems they normally monitor remotely. Several utilities issued boil-water notices and reverted to manual operation while engineers physically reclaimed control. The FBI says utility companies in at least seven states have now reported similar PLC intrusions.
On July 30, the Cybersecurity and Infrastructure Security Agency (CISA) issued a public alert describing a "significant increase" in activity targeting the water sector and telling every utility, regardless of size, to "remove publicly exposed PLCs and other operational technology from the internet as soon as possible." Investigators are examining a possible link to Iran-affiliated actors, and CISA's own advisory tracking this campaign — AA26-097A, covering Iranian-affiliated exploitation of Rockwell, Schneider Electric, and Siemens PLCs — had been updated on July 22, just four days before the Minnesota attacks began, to warn that intruders were now exfiltrating PLC project files, not just tampering with settings.
The warning existed. The authority to enforce it didn't.
The uncomfortable detail here isn't that a warning came four days too late — it's that federal regulators have spent three years unable to require water utilities to act on warnings like it at all. In March 2023, EPA issued an interpretive memorandum stating that its existing sanitary-survey authority already let it require states to evaluate operational-technology cybersecurity during routine water-system audits. Missouri, Arkansas, and Iowa sued, joined by the American Water Works Association and the National Rural Water Association, arguing EPA had no statutory basis for the mandate. The Eighth Circuit stayed the memo in July 2023, and EPA formally rescinded it that October — reverting the entire sector to voluntary cybersecurity assessments.
That is the regulatory baseline the Minnesota attackers walked into: roughly 50,000 community water systems in the United States, per EPA's own enforcement data, most serving small populations with no dedicated IT or OT security staff, and no federal requirement that any of them check whether a PLC is sitting exposed on the public internet.
Steelmanning the mandate
The case for a hard federal cybersecurity mandate is genuinely strong here, and it deserves to be stated plainly rather than waved off. Drinking water is a single-point-of-failure utility — you cannot shop around for a competing water provider mid-crisis — and the consequence of a lapse isn't a data breach notification letter, it's a boil-water order affecting tens of thousands of residents. When the threat actor is a state-linked group probing for pre-positioning ahead of a broader conflict, as CISA's advisory now explicitly frames the Iran-linked campaign, treating protection as optional starts to look like treating a physical-safety hazard as optional. Reasonable people can look at 30-plus utilities locked out of their own controllers in 48 hours and conclude that voluntary compliance has been given its chance and failed.
Why the 2023 ruling was still right
The Eighth Circuit's problem was never that cybersecurity is unimportant — it was that EPA tried to legislate through an interpretive memo rather than through the notice-and-comment rulemaking, or explicit congressional authorization, that binding mandates on 50,000 independently governed local utilities actually require. That distinction matters more, not less, in a sector this fragmented: a one-size-fits-all federal audit mandate written for large metro systems risks becoming an unfunded compliance burden that small rural utilities — the ones least equipped to pay for it — simply can't meet, without making anyone meaningfully safer.
The fix that's actually moving through Congress reflects that lesson. The bipartisan FLOWS Act, from Sens. John Boozman (R-AR) and Mark Kelly (D-AZ), would authorize $50 million a year in EPA grants specifically for rural and small water utilities to upgrade industrial control systems — with no local matching-fund requirement, the single biggest reason small systems cite for not modernizing. That's the proportionate model: pair CISA's free vulnerability-scanning and configuration guidance, which already exists and doesn't require new statutory authority, with money that lets under-resourced utilities actually act on it, rather than a compliance mandate that produces paperwork before it produces disconnected PLCs.
The near-term test
CISA's July 30 alert is, functionally, the free version of what a mandate would require: get PLCs off the public internet, put remote access behind a VPN or gateway, kill default passwords. None of that costs much, and none of it needs new legislation to happen this week. The real test is whether Congress funds FLOWS-style grants fast enough that small utilities can act on CISA's guidance before the next campaign, rather than waiting for the next boil-water notice to make the case again.
"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," MNIT's leadership said of the Minnesota incident response — a description that, so far, has applied to incident response a great deal more than to prevention funding.