Iran-Linked Hackers Hit 36 Minnesota Water Utilities, FBI and EPA Warn of Wider Campaign
Suspected Iranian-affiliated actors targeted programmable logic controllers at more than 30 municipal water systems in Minnesota, then the FBI and EPA widened the alert to seven states as attribution work continues.
Federal and state investigators are working to confirm whether Iran's government directed a coordinated assault on Minnesota's water infrastructure that hit at least 36 utilities in late July, setting off a cascade of federal warnings that the broader U.S. water sector is in the crosshairs.
The attacks targeted operational technology, not back-office networks. According to a statement reviewed by ABC News, Minnesota IT Services (MNIT) said the intrusions involved systems used to remotely monitor and control equipment, including programmable logic controllers. CISA, in a public alert, said threat actors modified PLC passwords "to lock out operators", a technique that strips plant staff of real-time control over water treatment, pressure regulation, and chemical dosing.
Drinking water safety was not compromised. A spokesperson for MNIT told NBC News there was no indication the breaches contaminated any municipal water supplies, and the agency said no localities had issued water-use advisories. But the disruption to monitoring capability itself is the operational concern worth holding onto: you can't fix what you can't see.
Attribution remains a live question. A senior law enforcement official told NBC News the Minnesota attack bore the hallmarks of Iran-backed hackers. The Washington Post reported that intelligence agencies assessed Iran was "likely" behind the campaign, a moderate-confidence framing consistent with the circumstantial picture but not a finished finding. CPO Magazine reported that federal investigators cautioned full attribution was still in progress and that false-flag scenarios, while unlikely, hadn't been ruled out. President Trump publicly cast doubt on Iranian involvement. Minnesota's chief information security officer, John Israel, said in a statement reported by ABC News that the state had "provided relevant information to the federal government, which is evaluating this activity in the broader national context."
The timing stacks context that analysts will weigh. The attacks came days after CISA and the FBI updated a joint advisory, originally published April 7, warning that Iranian-affiliated APT actors were targeting internet-exposed PLCs across U.S. critical infrastructure. A July 22 update to that advisory, reviewed on the CISA website, expanded the manufacturer scope to include Schneider Electric, Siemens, and Rockwell Automation equipment and added new guidance on detecting malicious changes in reusable code modules. The advisory noted that since at least March 2026, the identified group had been actively disrupting OT systems at victim organizations.
Within days of the Minnesota disclosures, the FBI and EPA issued a joint public service announcement warning that water and wastewater utilities in at least seven states had reported incidents, with some experiencing degraded operations, according to NBC News. The announcement did not name the additional states.
The structural vulnerability here isn't novel, but the scale is worth registering. Many community water systems operate without dedicated cybersecurity staff, and internet-exposed PLCs have been a documented problem for years. The CISA advisory lists basic mitigations: remove public-facing OT device access, implement multi-factor authentication, monitor for anomalous network activity. Those recommendations have been published in nearly identical form since at least 2023. The gap between guidance and implementation is where this campaign found its opening.
What the Minnesota incident adds to the record is coordination. This wasn't an opportunistic scan that caught a single utility with an exposed HMI. It was, by the count of investigators, three dozen systems across one state bearing the same technical fingerprints inside a compressed window. That pattern is consistent with a deliberate, pre-planned operation rather than a crime of opportunity, though that assessment should be held at moderate confidence until attribution is closed.
Sources cited:
- NBC News (https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210)
- ABC News (https://abcnews.com/US/investigators-iran-connection-minnesota-water-system-hacks-us/story?id=135237777)
- CISA Advisory AA26-097A (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- CPO Magazine (https://www.cpomagazine.com/cyber-security/cyber-attack-by-suspected-iranian-hackers-hits-36-minnesota-water-utilities-causing-outages/)
- The Washington Post (https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/)
This release was originally distributed via ETL Newswire. Visit NBC News for the full story, related releases, and contact information.
Visit NBC News →