
A cyberattack this week hit more than 30 municipal water systems across Minnesota, with federal and state investigators pointing to Iranian-linked hacking groups as the likely perpetrators. The attacks targeted programmable logic controllers (PLCs) used to monitor and control water treatment and distribution equipment, forcing some utilities to disconnect from cellular networks and revert to manual operations.
What Happened
The attacks began on or around July 26, according to the Minnesota Fusion Center, a state-level intelligence-sharing entity. In suburban Plymouth, officials detected an outage on Sunday evening after noticing compromised PLCs at two water towers and 14 sewer lift stations. The city immediately disconnected the affected systems from its cellular network.
The FBI and EPA issued a joint advisory confirming that malicious cyber actors targeted specific brands of control systems used by municipal water utilities. The advisory covered incidents across at least seven states, with Minnesota bearing the heaviest impact.
The Iran Connection
U.S. intelligence agencies and cybersecurity researchers have linked the attacks to Iranian-affiliated hacking groups. A July 22 joint report from seven federal agencies, including the FBI, NSA, EPA, and CISA, warned that Iranian cyber actors were exploiting internet-connected PLCs that retained default passwords. The Minnesota Fusion Center found the July attacks were “aligned” with that same campaign.
This is not the first time Iranian hackers have targeted U.S. water infrastructure. In 2023, actors affiliated with Iran’s Islamic Revolutionary Guard Corps accessed multiple water and wastewater facilities by exploiting default credentials on internet-connected controllers.
No Water Supply Compromised
Minnesota officials stressed that no water supply was compromised as a result of the attack. The breach affected monitoring and control systems, not the physical treatment or distribution of water. Mike Ernster, a public information officer for the Minnesota Department of Public Safety, confirmed that no pressure changes or water quality issues were reported.
Still, the incident exposed the vulnerability of small municipal utilities that often operate with limited IT staff and outdated security practices. Many of the affected PLCs were accessible over cellular networks without multi-factor authentication or network segmentation.
Political Fallout
The attacks quickly became a political flashpoint. President Trump publicly blamed Minnesota Governor Tim Walz, calling the state’s cybersecurity posture inadequate. Walz responded by suggesting the attacks were retaliation for U.S. military strikes in Iran earlier in 2026, placing the blame on the administration’s foreign policy.
Cybersecurity experts noted the political back-and-forth distracted from the core issue: critical infrastructure in small American cities remains dangerously exposed to state-sponsored attackers.
What Comes Next
The FBI and EPA have urged all water utilities, regardless of size, to audit their PLC configurations, change default credentials, and segment operational technology networks from internet-connected systems. CISA has released specific guidance for water sector operators to harden their defenses against PLC exploitation.
Several Minnesota cities have already begun disconnecting remote access to their water systems as a precaution, switching to on-site manual control until security audits are complete.
Frequently Asked Questions
Which water systems were attacked in Minnesota?
More than 30 municipal water systems across Minnesota were affected, including Plymouth, which detected compromised PLCs at two water towers and 14 sewer lift stations.
Was the water supply contaminated?
No. Minnesota officials confirmed that no water supply was compromised. The attacks targeted monitoring and control systems, not physical treatment or distribution.
Who is behind the cyberattack?
Federal investigators believe the attacks were carried out by Iranian-affiliated hacking groups. The Minnesota Fusion Center found the attacks were aligned with an Iranian cyber campaign identified in a July 22 joint advisory from seven federal agencies.
How did the hackers get in?
The attackers exploited internet-connected programmable logic controllers (PLCs) that retained default passwords, a known vulnerability that CISA had warned about in a July 22 advisory.
What should water utilities do to protect themselves?
The FBI and EPA recommend changing all default credentials, implementing multi-factor authentication, segmenting operational technology networks from the internet, and conducting regular security audits of PLC configurations.
