
US cyber agency warns of water system attacks after 30 Minnesota utilities targeted; Iran suspected
More than 30 community water systems in Minnesota were hit by a coordinated cyberattack on July 26-27, prompting a CISA advisory and an FBI investigation into a possible Iranian link.
The attack
On July 26 and 27, more than 30 community water systems across Minnesota were hit by what the state's IT agency described as a "coordinated cyberattack." The hackers targeted programmable logic controllers (PLCs) that automate water treatment and distribution, changing passwords to lock out operators. In at least one city, a well and treatment plant temporarily went offline, and some systems had to be operated manually. Boil water notices were issued in affected areas. Local officials said there was no indication that drinking water was rendered unsafe. The affected communities included Plymouth, South St. Paul, Maple Plain, and Braham.
CISA warning and federal response
On July 30, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory warning of a significant increase in hackers targeting water and wastewater systems. The agency urged operators to remove internet-connected devices from public access immediately. The FBI confirmed it was "actively engaged with victims" and emphasized its commitment to protecting critical infrastructure. Minnesota's chief information security officer, John Israel, said the state had provided information to federal authorities, who are evaluating the activity "in the broader national context" and working to attribute it.
We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor.
Possible Iranian link
Investigators are examining whether Iran was behind the attacks. A leaked memo from the Water Information Sharing and Analysis Center (WaterISAC) said the Minnesota Fusion Center found the intrusions aligned with a hacking campaign that CISA had attributed to "Iran-affiliated" hackers in April. The New York Times reported that government officials believe Iranian hackers were likely responsible, though the assessment is preliminary and could change. Officials also noted the possibility that attackers posed as Tehran-aligned groups to inflame tensions. However, former intelligence officials told the Times that a false-flag operation was less likely. Emily Zimmer, a spokesperson for Minnesota IT Services, said the timing, methods, and targeted infrastructure shared characteristics with other coordinated cyber incidents involving critical infrastructure.
The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.
Escalation in cyber conflict
The attacks come amid the ongoing US-Israel war against Iran, which began in late February. Since then, Iranian hackers have conducted retaliatory intrusions, including paralyzing medical supplies company Stryker and breaching the personal email of FBI director Kash Patel. Joe Slowik, a former Los Alamos National Labs cybersecurity researcher, said the water utility attacks represent a rare instance of state-sponsored targeting of civilian infrastructure outside the Russia-Ukraine war. He warned that the threat is not contained to Minnesota.
Now we have documented disruption and even modification of safety and protection parameters in critical infrastructure. Seeing this sort of tradecraft expand to Iran, and seeing it across multiple sites, it should really be making people concerned right now.
Slowik added that many other sites use the same vulnerable technology, and the adversary has shown a willingness to strike. CISA's advisory noted that threat actors are targeting water entities of all sizes. The US has 152,000 public drinking water systems and more than 16,000 wastewater treatment systems, many of which rely on internet-connected PLCs.
- CISA issues advisory on Iranian-affiliated hackers targeting Rockwell Automation PLCs
- CISA updates advisory to include devices from other manufacturers
- Coordinated cyberattack hits more than 30 Minnesota water systems
- CISA issues new warning; FBI confirms engagement with victims


