Iranian-Linked Hackers Hit Water Utilities in Seven States, FBI Warns
A coordinated PLC intrusion campaign that disrupted more than 30 Minnesota water systems in late July has spread to at least six other states, with federal investigators probing ties to Iranian-affiliated threat actors.
Federal investigators are trying to confirm whether Iranian-affiliated hackers are behind a wave of cyberattacks that hit municipal water and wastewater systems across at least seven states in the last two weeks of July, according to a public service announcement reviewed by NBC News and CBS News.
The campaign came into focus on the evening of July 26, when Plymouth, Minnesota, operators noticed communications breaking down across their control network. <cite index="14-1">Officials detected compromised programmable logic controllers at two water towers and 14 sewer lift stations, then disconnected them from the cellular network.</cite> <cite index="17-7,17-8">Operators shifted to manual mode temporarily; normal communications were restored by the afternoon of July 28, and water quality, treatment, and pressure were never affected.</cite> Plymouth was not alone. <cite index="16-1,16-2">From July 26 to July 27, a coordinated attack targeted more than 30 municipal water systems statewide, with Plymouth, South St. Paul, Maple Plain, and Braham publicly confirming the intrusions.</cite>
The attribution picture is moderate confidence at best, and officials are saying so. <cite index="16-3">A preliminary report by American investigators suggested that Iranian hackers were probably responsible, but stressed that their assessments could change.</cite> <cite index="16-12">A communication leaked to Wired and made by the Water Information Sharing and Analysis Center suggested Iranian-linked hackers were likely responsible.</cite> That's an industry-sharing-channel assessment, not a formal government attribution, and it should be read as such.
The intrusion method is not complex. <cite index="19-3,19-4,19-5">After remotely accessing internet-facing devices, the actors changed IP addresses and passwords, resulting in loss of monitoring and control functionality. Default or weak credentials on internet-exposed hardware left operators locked out of their own systems.</cite> CISA's updated advisory, AA26-097A, ties the campaign to a pattern running since at least March. <cite index="19-7,19-8">Since March 2026, Iranian-affiliated threat actors have actively exploited a critical Rockwell Automation flaw, CVE-2021-22681, prompting CISA to add it to its Known Exploited Vulnerabilities catalog; Rockwell has confirmed no security patch is available, making network isolation essential.</cite>
The July 22 update to that advisory escalated the concern further. <cite index="19-9,19-10">Attacks exploiting internet-exposed PLCs had expanded beyond Rockwell Automation to include Schneider Electric and Siemens devices, and the advisory documented attackers stealing PLC project files for the first time.</cite> <cite index="19-11,19-12">Exfiltrating project files means the attacker is taking the engineering logic of the plant, the actual programmed behavior of the industrial process, and studying it offline. That's reconnaissance for a more targeted future attack, not just disruption for its own sake.</cite> That assessment warrants moderate-to-high confidence given it comes from direct forensic analysis documented in the advisory.
Also noted in the CISA advisory: <cite index="12-4,12-5">at one U.S. victim, FBI observers saw the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained normal ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters.</cite> That's a qualitatively different capability than locking operators out. Overwriting safety parameters is the precursor move to causing physical harm.
The response posture has been reactive. <cite index="14-4,14-5">Nick Anderson, acting director of CISA, confirmed the agency is observing a significant increase in cyber threat actors targeting PLCs at water utilities, and urged critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.</cite> That guidance predates this campaign by months and has not been universally followed.
<cite index="15-4,15-5">In June 2026, U.S. strikes along Iran's southern coast destroyed a water facility near the Strait of Hormuz. The following day, the Handala threat group, linked to Iran's Ministry of Intelligence and Security, claimed it had breached water utility systems in several California cities as a retaliatory warning.</cite> The Minnesota campaign follows that escalation arc. <cite index="15-6">CyberAv3ngers' exploitation techniques have also proliferated to 60-plus affiliated hacktivist groups that have adopted its playbook, coordinated through an Electronic Operations Room established at the start of the conflict.</cite> Proxy amplification like that makes clean attribution harder and clean containment harder still.
The structural problem underneath all of this is documented and not new. <cite index="8-4">Legacy industrial control systems were built for reliability, not security, and remain hard to patch, poorly segmented, and difficult to monitor.</cite> Utilities knew that. The difference now is that someone is actively working through the list.
Sources cited:
- CBS News (https://www.cbsnews.com/news/us-investigating-iran-cyberattack-minnesota-water-systems/)
- NBC News (https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210)
- CISA Advisory AA26-097A (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- Security Affairs (https://securityaffairs.com/196453/ics-scada/cisa-urges-utilities-to-remove-internet-exposed-plcs-after-minnesota-attacks.html)
- Tenable Research (https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know)
- Wikipedia / 2026 Minnesota water system cyberattack (https://en.wikipedia.org/wiki/2026_Minnesota_water_system_cyberattack)
- SC Media (https://www.scworld.com/feature/critical-infrastructure-facing-cyber-surge-in-ot-and-supply-chains-in-2026)
This release was originally distributed via ETL Newswire. Visit CBS News for the full story, related releases, and contact information.
Visit CBS News →