- August 15, 2026
- Updated 9:15 am
Cyberattack Targets Minnesota Water Systems
- 15 Views
- admin
- July 31, 2026
- Cybersecurity Technology U.S. News
On July 30, 2026, malicious cyber activity affected technology across over 30 community water systems in Minnesota. This forced some utilities to switch to manual operations. State and federal authorities are investigating the attack’s origin. U.S. officials and sources suspect potential involvement of Iranian hackers. However, the attribution of the attack has not been confirmed and could change as new technical evidence emerges.
The probe is also exploring whether the attackers tried to appear Iran-based, possibly to escalate tensions with the U.S. Minnesota and the federal government have not publicly blamed a specific party for the attack. Most affected systems involved technologies like programmable logic controllers (PLCs), used to monitor and control water system equipment remotely, as reported by Minnesota IT Services.
Mike Ernster from the Minnesota Department of Public Safety confirmed that the state’s water supply remains uncompromised. The Minnesota Fusion Center is collaborating with municipalities and state and federal partners to address the issue. Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration (CISA), noted a significant rise in cyber threats targeting PLCs at water utilities. He urged infrastructure owners to remove publicly exposed PLCs from the internet immediately.
Investigators found some timing similarities in the incidents and the technology targeted, but have not confirmed a single actor’s involvement in all cases. In Plymouth, Minnesota, a cyberattack targeted operational technology across several water systems. Early on Monday, South St. Paul identified an issue, enacting contingency measures and switching to manual operations to ensure continuous water and wastewater services. The incident was limited to technologies supporting parts of the water utility, with no impact on drinking water quality, pressure, or delivery. Resident data remained secure.
In Braham, north of Minneapolis, a water supply issue was discovered Monday. Public works isolated the malfunctioning system, implemented a backup, and restarted the plant within 90 minutes. No water service disruptions occurred. The city ensured the system’s disconnection from public-facing networks and plans to consult its tech provider for remediation.
The FBI is aware of the incident and maintains contact with affected parties but provided no further details. CISA highlighted a rise in threats targeting PLCs in the Water and Wastewater Systems sector. CISA stressed the need for infrastructure owners to secure external connections, as unauthorized installations could increase vulnerabilities.
In the past, Iran-linked hackers targeted U.S. water utilities. In 2023, actors affiliated with Iran’s Islamic Revolutionary Guard Corps exploited internet-connected controllers with default passwords, accessing multiple facilities. Such activity remains a concern for federal agencies investigating current threats.