Iranian-linked hackers hit 30+ Minnesota water utilities in coordinated cyberattack
More than 30 community water systems in Minnesota were hit by a coordinated cyberattack on July 28, 2026, targeting operational technology — pumps, wells, water towers and wastewater lift stations — rather than office networks. Several towns were forced onto manual operations and one treatment plant was briefly taken offline. A leaked WaterISAC memo obtained by WIRED links the intrusions to Iranian-affiliated hackers, though no US agency has formally attributed the attack. CISA had issued a warning four days earlier about Iranian actors compromising internet-facing PLCs.
Full text
Cyberattack hits operational technology at more than 30 Minnesota community water systems, briefly taking treatment plant offline and forcing several towns onto manual operations
A leaked WaterISAC memo obtained by WIRED relays a state fusion center assessment tying the intrusions to Iranian-affiliated hackers, but no US agency has formally attributed the attack yet
The CISA had warned four days earlier that Iranian-affiliated actors were compromising internet-facing PLCs, repeating guidance that has mostly fallen on deaf ears
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack, targeting the operational technology running pumps, wells, water towers, and wastewater lift stations rather than the office networks behind them.
Minnesota IT Services disclosed the attack on July 28 2026 and activated a statewide incident response, stating that it wasn't aware of any Minnesota city asking residents to change their drinking water use just yet.
A memo obtained by Wired , circulated by the water sector information-sharing group WaterISAC and carrying a restricted TLP: AMBER handling marking, relays a Minnesota state fusion center assessment that ties the intrusions to Iranian-affiliated hackers.
A warning that was more or less ignored
Four days before the attacks, CISA updated an advisory, AA26-097A, warning that Iranian-affiliated actors were compromising internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens, and possibly others across the US water, energy, and government sectors. It documented confirmed disruptions and financial losses.
This drew no immediate response from state functionaries, and it is easy to see why: the US has tens of thousands of community water systems that serve small populations and lack budgets for dedicated cybersecurity staff.
This is despite there being a precedent: Iranian-linked actors hit the Municipal Water Authority of Aliquippa in Pennsylvania in November 2023, defacing a Unitronics controller with an anti-Israel message. CISA said at the time those devices were exposed to the internet with default passwords still in place. The advice issued then is the same advice being issued this week, which is telling about how little has changed since.
The WaterISAC memo, dated the day the attacks concluded, passes on a state fusion center report linking the activity to Iranian-affiliated actors. That memo was not meant to be public, but it has been corroborated by The New York Times and The Washington Post, which reported that they spoke to federal officials and US intelligence agencies, respectively, lending credence to the claims.
CISA later warned that attackers are changing PLC passwords to lock operators out of their own equipment, and repeated the advice that has been unchanged for years: get PLCs off the public internet and put remote access behind a VPN or gateway.
Who was affected?
The worst of the cyberattack hit Braham, a town of roughly 1,700 people, where the city said attackers shut down the operating controls, taking the water treatment plant and the well offline. Crews restored it manually within a couple of hours, and residents were told to minimize water use in the meantime.
Plymouth, a Minneapolis suburb of about 80,000, found the problem confined to equipment connected over cellular links at two water towers and several wastewater lift stations. Its IT division disconnected the affected kit from the network entirely to stop the attack and prevent retargeting during reconfiguration.
Maple Plain declared a local state of emergency to manage its response, and South St. Paul reported that some automated controls were compromised. In most cases, contingency procedures held and water and wastewater operations continued.
None of this is happening in a vacuum, however. The June memorandum that paused fighting between the US and Iran has broken down, and both are trading strikes, including recent US attacks near the Strait of Hormuz that destroyed a water facility and cut supply to more than 20,000 people. Whoever carried out the Minnesota attacks, the symbolism of targeting municipal water is unlikely to be accidental.
The damage that these intrusions caused was limited; they produced brief outages that trained staff fixed by hand. That is an outcome with a silver lining, and it depended on utilities having people who knew how to run a treatment plant without its automation, even if its digital defenses collapsed outright.
Similar stories
💻 Technology
US water systems hit by cyberattacks as FBI investigates suspected Iranian hackers
The Independent World · 17h ago
🌍 World
Iran behind wider cyberattacks on US water supply systems, evidence shows
Hacker News · 22h ago
Similar stories
💻 Technology
US water systems hit by cyberattacks as FBI investigates suspected Iranian hackers
The Independent World · 17h ago
🌍 World
Iran behind wider cyberattacks on US water supply systems, evidence shows
Hacker News · 22h ago
Should water utilities be legally required to disconnect control systems from the internet?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!