Minnesota water hacks revive fears of Iranian attacks on US infrastructure
MINNEAPOLIS, MINNESOTA: A coordinated cyberattack targeting more than 30 community water systems across Minnesota has renewed concerns over the vulnerability of America's critical infrastructure as federal investigators examine whether the incidents could be connected to a cyber campaign previously associated with Iran-affiliated hackers.
While officials have not confirmed Iran was behind the attacks, a leaked industry memo has reportedly pointed investigators toward a possible connection, stressing that the assessment remains preliminary as the investigation continues.
The incident has drawn national attention not because drinking water was contaminated - it was not - but because it targeted systems that provide an essential public service to American communities. It has also revived questions about whether a cyber threat that US agencies have warned about for years is re-emerging at a time of heightened tensions between Washington and Tehran.
🇺🇸 U.S. water systems got a wake-up call.
— Mario Nawfal (@MarioNawfal) July 31, 2026
Federal cyber defenders are warning that hackers are ramping up attacks on the technology that keeps water and wastewater plants running.
Their advice is simple and urgent: if your control systems are exposed to the internet, pull them… pic.twitter.com/iDgZKz4PER
Why do Minnesota attacks matter beyond one state's water systems?
Minnesota IT Services said more than 30 community water systems were targeted between July 26 and 27 in what it described as a "coordinated cyberattack." While no communities were advised to stop using their drinking water, some utilities temporarily switched to manual operations after hackers accessed automated control systems.
The FBI said water and wastewater utilities in at least seven states have since reported related incidents, with some activity degrading water operations.
The attacks have become more significant because they come against the backdrop of repeated federal warnings about Iranian cyber activity targeting critical infrastructure. On April 7, the Environmental Protection Agency (EPA), FBI, Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) issued a joint advisory warning US organizations, including water utilities, of an "urgent and ongoing Iranian-affiliated cybersecurity threat."
🚨 FBI PSA: Malicious Cyber Actors Targeting Water and Wastewater Sector PLCs
— FBI Cyber Division (@FBICyberDiv) July 30, 2026
The FBI warns that malicious cyber actors are conducting cyber attacks targeting operational technology devices. These threat actors are remotely accessing internet-facing PLCs, changing IPs and… pic.twitter.com/nUPXJBToDA
The agencies urged operators to disconnect vulnerable industrial control systems from the internet and strengthen remote-access protections against attacks targeting programmable logic controllers used in water and wastewater facilities.
Federal agencies have since intensified those warnings. On July 30, CISA warned that hackers were increasingly targeting technology used to operate water and wastewater systems, while the FBI said utilities in at least seven states had reported incidents and some had experienced operational degradation.
Although officials have not confirmed who was responsible for the Minnesota attacks, they said the investigation is being treated seriously because of similarities with previously observed campaigns targeting critical infrastructure.
Investigators examining a possible Iran connection
The investigation intensified after a leaked Water Information Sharing and Analysis Center (WaterISAC) memo reportedly suggested the Minnesota incidents shared characteristics with a cyber campaign previously identified by CISA and associated with Iran-affiliated hackers. Cybersecurity researchers cited by WIRED said the attacks bear similarities to tactics previously used by Iranian-linked groups targeting industrial control systems.
However, federal and state officials have stopped short of attributing the attacks to Iran. Investigators continue to analyze forensic evidence and have cautioned that attribution remains preliminary.
Officials have also acknowledged the possibility that attackers could be impersonating Iranian threat actors, a known tactic in cyber operations designed to complicate attribution.
Authorities have not reported evidence that drinking water quality was compromised or that permanent operational damage occurred. The FBI, CISA and Minnesota officials continue to investigate the incidents.
A 2023 Pennsylvania attack offers the precedent
The Minnesota investigation has inevitably drawn comparisons with a confirmed 2023 cyberattack on the Municipal Water Authority of Aliquippa in Pennsylvania, where the Iran-linked hacking group CyberAv3ngers breached a booster station that regulated water pressure.
US officials later attributed that attack to Iranian-affiliated hackers, prompting nationwide warnings that American water infrastructure had become a target for foreign cyber actors. The Pennsylvania incident established a documented precedent for Iran-linked attacks on US water utilities, but it does not prove Iran was behind the Minnesota attacks.
Instead, cybersecurity experts say it provides important context for why investigators are examining whether a previously documented threat may have resurfaced. Whether the current attacks are ultimately linked to Iran or another actor will depend on the outcome of the federal investigation, officials say.
Minnesota activates statewide response as investigation continues
Minnesota IT Services (MNIT) said it activated the state's cybersecurity incident response capabilities immediately after learning of the coordinated attacks, working alongside the FBI, Cybersecurity and Infrastructure Security Agency (CISA), US Environmental Protection Agency (EPA), Minnesota Department of Health, Minnesota Department of Public Safety, Bureau of Criminal Apprehension's Minnesota Fusion Center and local water utilities.
Officials said the investigation remains active as responders continue assessing affected systems and helping utilities recover. According to the Minnesota Department of Health, there is no indication that drinking water has been compromised, and the agency is "not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage."
"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer, said in a statement.
"MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."
MNIT said its teams continue to coordinate technical response efforts across government agencies, share threat intelligence and indicators of compromise, assist affected utilities with containment and recovery, and monitor for related malicious cyber activity while working with state and federal partners.
The agency said additional information will be released as the investigation progresses.