July 31, 2026

Cyberattack Impacts Minnesota Community Water Systems

By the end of July 2026, malicious cyber activity affected technology at over 30 community water systems in Minnesota. Some utilities had to switch to manual operations as authorities investigated the attack. Officials are looking into potential involvement of Iranian hackers, but the source has not been confirmed.

Experts are investigating whether the perpetrator could have disguised their origins. No public attribution to a specific actor has been made by Minnesota or the federal government.

The cyberattack involved technology used to remotely monitor and control water system equipment, such as programmable logic controllers (PLCs). Fortunately, no water supply was compromised, according to the Minnesota Department of Public Safety.

The Minnesota Fusion Center, along with state and federal partners, is actively addressing the issue. Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration (CISA), noted an increase in cyber threats targeting PLCs at water utilities.

CISA recommends removing publicly exposed PLCs and other operational technology from the internet immediately to avoid potential threats.

Recently, investigators identified timing similarities in the incidents but have not confirmed if all were by the same actor. In Plymouth, Minnesota, one such incident occurred earlier this week.

South St. Paul officials identified an issue early on and switched to manual operations, ensuring no disruption in service. No resident or customer data was accessed.

In Braham, north of Minneapolis, public works discovered a malfunction in the city water tower’s well. The system was isolated, a backup was restored, and operations resumed within 90 minutes. Mayor Nate George affirmed that residents did not lose water service.

The FBI is aware of the incident and in communication with victims. CISA reiterated the importance of removing internet-exposed PLCs and other technologies, as even organizations with strong cybersecurity must verify their external connections.

Iran-linked hackers have previously targeted U.S. water utilities. Federal agencies noted past attacks used similar methods, infiltrating facilities via internet-connected controllers with default passwords.

TAGS: