Iranian-Affiliated Actors Hit Water Systems in Seven States, FBI Warns
A coordinated campaign exploiting internet-facing programmable logic controllers has degraded water operations across at least seven U.S. states since late July, with more than 30 Minnesota utilities confirmed affected.
The FBI and the Environmental Protection Agency issued a public service announcement on July 30 warning that malicious cyber actors are actively hitting water and wastewater treatment systems across at least seven states by exploiting internet-connected programmable logic controllers, or PLCs. According to the FBI-EPA PSA reviewed by ETL Newswire, some of that activity has degraded actual water operations, not just IT systems.
The immediate trigger was a coordinated overnight incident on July 26-27. <cite index="18-2,18-3">More than 30 Minnesota community water and wastewater systems experienced a coordinated cyber incident overnight; Minnesota IT Services confirmed the coordinated nature of the activity on July 28, publicly naming four communities: Braham, Plymouth, South St. Paul, and Maple Plain.</cite> <cite index="21-8">No contamination has been reported, though some utilities issued precautionary boil-water notices.</cite>
The Minnesota wave is not an isolated flare-up. It arrived on top of a longer-running campaign that U.S. agencies have been tracking since at least the spring. <cite index="26-2">The original advisory, published April 7, 2026, by the FBI, CISA, NSA, EPA, the Department of Energy, and U.S. Cyber Command's Cyber National Mission Force, warned that Iranian-affiliated APT actors were actively exploiting internet-facing operational technology devices across multiple U.S. critical infrastructure sectors.</cite> CISA updated that advisory, designated AA26-097A, on July 22 and again following the Minnesota incidents.
The technique is worth spelling out. <cite index="20-6,20-7">At one confirmed U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using the vendor's own configuration software; analysis indicated the project file retained normal ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters.</cite> In plain terms: operators were left watching displays that no longer reflected reality, while the underlying controller had been quietly reprogrammed.
<cite index="21-10">After gaining access to PLCs, threat actors remotely modified passwords and disconnected devices by changing their IP addresses to lock out operators.</cite> <cite index="19-10">Pressure loss of the kind recorded in Minnesota could potentially allow untreated groundwater to seep into distribution pipes, the FBI warned.</cite>
The July 22 CISA update expanded the hardware scope of the advisory. <cite index="23-2,23-3">The agencies added new guidance on detecting malicious changes in reusable code modules within Rockwell Automation PLC programs, and expanded the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded PLCs, emphasizing the importance of restricting direct internet access.</cite> The Department of the Treasury was added as a co-author of the advisory in the July update, a signal that financial-sector OT exposure is now in scope.
<cite index="20-5">CISA's advisory assesses that Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran and the United States and Israel.</cite> That's a moderate-confidence geopolitical framing in the advisory itself; the underlying technical evidence for the PLC intrusions is separately documented through victim-organization engagements and carries higher confidence.
<cite index="19-11">The FBI notes that even small utilities with limited cybersecurity resources remain attractive targets because many continue to operate older industrial control systems directly accessible from the internet.</cite> That's the structural problem the government has flagged repeatedly without resolving: <cite index="8-4">legacy industrial control systems were built for reliability, not security, and remain hard to patch, poorly segmented, and difficult to monitor.</cite>
<cite index="21-7">CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT devices from the internet as soon as possible.</cite> <cite index="21-11">The agency notes these threat actors are targeting water entities of all sizes.</cite> The indicators of compromise and detection guidance are published in advisory AA26-097A on cisa.gov.
Sources cited:
- CISA Advisory AA26-097A (July 22, 2026 update) (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- FBI-EPA Public Service Announcement (July 30, 2026) (https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions)
- Cybernews: Minnesota water hacks tied to 7-state Iranian APT campaign (https://cybernews.com/security/fbi-minnesota-water-hacks-7-state-iranian-cyber-campaign/)
- Cyber Warrior 76 / Substack: Iranian-Linked PLC Exploitation and the Minnesota Water-Sector Cyberattack (https://cyberwarrior76.substack.com/p/iranian-linked-plc-exploitation-and)
- Cybersecurity Magazine: Iran-Linked Cyberattack on US Water Systems Explained (https://cybermagazine.com/news/iran-linked-cyberattack-on-us-water-systems-explained)
- Security Affairs: Iran-Linked Actors Targeting US Water and Energy Control Systems (https://securityaffairs.com/195991/apt/iran-linked-actors-breach-are-targeting-us-water-and-energy-control-systems.html)
This release was originally distributed via ETL Newswire. Visit CISA Advisory AA26-097A (July 22, 2026 update) for the full story, related releases, and contact information.
Visit CISA Advisory AA26-097A (July 22, 2026 update) →