Start with the part that matters most to anyone drinking from a tap: the water was fine.

Cyber intruders reached programmable logic controllers at water utilities in at least seven states this week, the FBI said, CBS News reported. More than 30 community water systems in Minnesota were affected, and Michigan reported incidents on Saturday. Water quality, treatment, pressure and delivery were not affected, and no supply was compromised.

What was actually reached

A programmable logic controller is the small industrial computer that opens a valve or starts a pump when told to. Utilities connect them to networks so operators can monitor a water tower without driving to it. Some end up reachable from the open internet, which is the vulnerability being exploited here.

In Plymouth, Minnesota, controllers were compromised at two water towers and 14 sewer lift stations, CBS News reported. The federal agencies involved are the FBI, EPA and CISA, along with the Minnesota Department of Public Safety.

The distinction between reaching a control system and affecting water is the whole story, and it is the thing most likely to get lost. Nobody poisoned anything. Someone got into the machinery that operators use to run equipment remotely, in systems that were exposed to the internet, and in Minnesota that was enough to force manual operation at some utilities.

On Iran

Investigators are looking at whether Iranian hackers were responsible. They have not said that they were.

CBS News reported that sources cautioned that "since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected." No agency has issued a formal attribution. We are reporting the question because the government is asking it, not because it has been answered, and the difference matters when the subject is a foreign state.

What the federal warning actually says

CISA's language is unusually direct. The agency said it is "currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities," and urged operators to "remove publicly exposed PLCs and other operational technology from the internet as soon as possible."

It also told utilities to validate their external connections, document cellular modems and system-integrator links, and review attack-surface scans for connections nobody remembers installing. That last instruction describes the real problem: small utilities accumulate remote-access hardware over years, often installed by contractors, and frequently do not know what is reachable from outside.

The California question

Nothing in the reporting we could verify names a California water agency in this week's incidents, and there is no reported intrusion at the Los Angeles Department of Water and Power or the Metropolitan Water District.

That is not the same as saying California is not exposed. The utilities being hit are small and mid-sized systems without dedicated security staff, and California has hundreds of them, serving towns whose water systems are run by a handful of people. The federal advisory is national and applies here.

What a reader should do

Nothing. There is no consumer action in this story, no boil notice in Southern California, and no reason to buy bottled water.

The action items belong to utility operators, and they are the ones CISA published: get the controllers off the open internet. Utilities can reach CISA's operations center at 1-844-729-2472.