Friday

World news with the sources attached

Hackers hit more than 30 Minnesota water systems, prompting a nationwide US alert

Intruders locked operators out of control equipment at small utilities in late July 2026. Drinking water stayed safe, officials said, and no attacker was formally named.

Event date
Published
Reading time
3 min
Brick wall of a small building with the sign Bigfork Water Treatment Plant and a white door marked chlorine
The water treatment plant in Bigfork, Minnesota, photographed in July 2017. It is shown as an example of a small community system; it was not named among those attacked. Photo: Tony Webster from Minneapolis, Minnesota, United States / Wikimedia Commons (CC BY-SA 2.0) · licence

Key points

  • More than 30 Minnesota community water systems were targeted on 26–27 July 2026; officials reported no effect on drinking water quality.
  • CISA told US water utilities on 30 July to remove industrial controllers from the public internet.
  • Utilities in at least seven states reported incidents, the FBI and EPA said.
  • Media reports cited officials who suspected Iranian hackers; no formal attribution was made.

More than 30 community water systems in the US state of Minnesota were targeted in a coordinated cyberattack on 26 and 27 July 2026, state officials said, in an incident that led federal agencies to tell water utilities across the country to disconnect their control equipment from the public internet.

Minnesota IT Services, the state’s technology agency, said most of the confirmed intrusions involved the systems utilities use to monitor and operate equipment remotely. Some utilities had to run pumps and treatment processes by hand. In the city of Braham, an intrusion briefly knocked out the controls for the well and the water treatment plant, the news site Nextgov/FCW reported. Officials said they had found no evidence that the quality of drinking water was affected.

A warning to every utility

On 30 July the Cybersecurity and Infrastructure Security Agency (CISA), the US government body responsible for protecting critical infrastructure, issued an alert describing a “significant increase” in activity against programmable logic controllers. These are the small industrial computers that open valves and switch pumps. According to the alert, attackers had changed the passwords on controllers to lock operators out and altered their network addresses to cut them off, which in some places led to boil-water notices and prolonged manual operation.

“These threat actors are targeting water entities of all sizes,” CISA said. It urged operators to take controllers off the public internet, route any remote access through a virtual private network or secure gateway, replace default passwords and keep verified backups of controller settings. The agency drew particular attention to cellular modems installed by vendors or contractors that a utility may not know it has.

The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency said the same day that utilities in at least seven states had reported incidents involving internet-facing equipment since 27 July. On 1 August Michigan said nine of its water systems had been attacked; a spokesman for the state’s environment department, Dale George, said “all systems continued to operate safely”.

Who was responsible

No government body publicly attributed the attacks. The New York Times reported on 30 July, citing unnamed state and federal officials, that investigators believed Iranian hackers were probably responsible, while stressing that the assessment was preliminary and could change. The attacks came five months into a war between the United States and Iran, and days after CISA had updated an advisory about Iran-linked intrusions into industrial controllers.

“The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents,” Emily Zimmer, a spokesperson for Minnesota IT Services, told Reuters. A memo sent to members of WaterISAC, the water sector’s information-sharing body, said the Minnesota attacks were “aligned” with the campaign CISA had described, but it presented no direct evidence tying them to Iran, Nextgov/FCW reported.

The question quickly became political. Asked about the incident on 31 July, President Donald Trump said: “I think Minnesota is behind it,” adding, “I don’t think there was an Iranian cyberattack.” Minnesota’s governor, Tim Walz, said he believed Iran was responsible and blamed federal staff cuts for leaving the country more exposed, the Associated Press reported.

An old weakness

Security specialists said the attacks did not appear to need advanced skills. Controllers reachable from the internet and still protected by factory-set passwords may have been enough, Bill Wright of the data storage company Everpure told the trade publication MeriTalk. A pro-Iran group defaced control screens at a water authority in Aliquippa, Pennsylvania, by similar means in the early months of the Israel-Hamas war.

Small utilities are especially exposed. Many run ageing equipment maintained over decades by different contractors, said Manish Sharma, chief information security officer at Aurigo Software, quoted by Nextgov/FCW. “Cybersecurity has to account for that complexity,” he said.

Update

CISA published further guidance on reducing internet exposure on 21 August 2026. The security news site Security Affairs reported on 27 August that more than 100 internet-exposed systems in the US water and wastewater sector had been hit in July, most of them controllers connected directly to cellular modems with no firewall in between, and that officials had still made no formal attribution. Searches carried out for this article in early October found no later public attribution or criminal charges.

Sources

  1. US authorities probe cyberattack on water systems in Minnesota Al Jazeera (with Reuters), 30 Jul 2026 · independent report
  2. CISA urges water utilities to take exposed systems down after Minnesota hacks Nextgov/FCW, 31 Jul 2026 · independent report
  3. CISA Urges Water Utilities to Disconnect Exposed Systems MeriTalk, 31 Jul 2026 · independent report
  4. CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs Cybersecurity and Infrastructure Security Agency, 30 Jul 2026 · primary source
  5. Michigan joins Minnesota in reporting cyber attacks with FBI investigating Al Jazeera (with AP), 1 Aug 2026 · independent report
  6. CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do Security Affairs, 27 Aug 2026 · independent report

Spotted an error? See how to request a correction.

From other sections