More than 30 Minnesota facilities were breached in late July, with Michigan later confirming similar incidents, as federal officials point to hallmarks of Iranian-linked hacking.
A coordinated cyberattack targeted operational technology at more than 30 community water systems across Minnesota on July 26 and 27, triggering a statewide cybersecurity response and prompting a federal warning that at least seven states have now reported similar incidents. The FBI and the Environmental Protection Agency issued a joint public service announcement on the matter, without naming all the states affected.
How the Attack Unfolded in Minnesota
Four Minnesota cities publicly confirmed disruptions: Braham, Plymouth, South St. Paul and Maple Plain. In Braham, a community of roughly 1,700 people, the attack disabled computerized operating controls and briefly shut down the city’s well and water treatment plant; public works crews restored service within about two hours. In Plymouth, home to roughly 80,000 residents, the city’s IT division had to disconnect cellular-connected equipment at two water towers and several wastewater lift stations to contain the intrusion, while staff switched to manual operations.
South St. Paul and Maple Plain kept services running despite disruptions to their automated controls, and Maple Plain’s mayor, Julie Maas-Kusske, declared a local state of emergency so the city could coordinate resources and speed up its response. City and state officials said Tuesday they had few additional specifics to share about why or how particular communities were targeted, and Minnesota IT Services described the incident only as a coordinated attack on technology at community water systems statewide.
Federal Investigators Point to Iran, With Caveats
A preliminary assessment by American investigators suggested Iranian-linked hackers were probably behind the intrusion, according to a law enforcement official, though officials stressed that the assessment could still change as the investigation continues. Days after the Minnesota incidents came to light, Michigan reported cyberattacks on nine of its own water systems, and the FBI said Saturday it was investigating both states’ cases. Officials have not confirmed how many of the seven states referenced in the federal advisory match publicly known incidents beyond Minnesota and Michigan.
According to the FBI and EPA advisory, the hackers involved in the broader campaign remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities over their systems. The agencies urged water system operators nationwide to remove programmable logic controllers from direct internet exposure, place them behind secure gateways and firewalls, use strong passwords, and limit communications between authorized control system devices through access control lists.
A Vulnerability Years in the Making
Cybersecurity researchers say the incident reflects a broader exposure problem rather than an isolated lapse. An analysis conducted in April 2026 identified thousands of internet-exposed devices worldwide that responded to industrial protocols and self-identified as equipment from a major automation manufacturer, with the United States accounting for close to three-quarters of that global exposure. A disproportionate share of those devices operate on cellular carrier networks, a pattern consistent with the field-deployed, cellular-connected equipment described in the Plymouth incident.
The exposure problem is not new. The EPA warned back in 2024 that more than 70% of U.S. water systems were failing to comply with a federal requirement to develop or update risk assessments and emergency response plans, and a later audit of 1,000 systems serving roughly 193 million people found dozens with significant gaps in their defenses.
What Officials Say Comes Next
Local officials in the affected Minnesota cities have emphasized that water quality itself was never compromised, even as automated monitoring and control systems went offline. Plymouth’s public works director credited advance planning for the city’s ability to restore full service in under two days. Still, cybersecurity experts interviewed by Minnesota public radio said the state’s water systems need broader technical upgrades to prevent a repeat, particularly around removing remote, internet-facing access points from critical equipment.
With the investigation still open and no official attribution confirmed, the incident has renewed attention in Washington on the vulnerability of small and mid-sized utilities, many of which lack the cybersecurity staffing and budgets of larger metropolitan systems, even as they perform functions just as critical to public health.
Sources:
- https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210
- https://www.startribune.com/plymouth-south-st-paul-water-system-cyber-attack/601872810
- https://www.aljazeera.com/news/2026/8/1/michigan-joins-minnesota-in-reporting-cyber-attacks-with-fbi-investigating
