Alleged Iran-linked hackers target 30 water systems in Minnesota in July
This digest was compiled by AI from multiple sources — links to the originals are below.

Hackers attempted to breach at least 30 municipal water systems in Minnesota on July 26-27, 2026, targeting industrial control computers. Similar attacks have since been reported in Michigan, New Jersey and other states, prompting utilities to switch to manual operations to protect drinking water. The attacks, attributed by initial suspicion to Iran-aligned hackers, have not been officially traced to any actor, even as federal officials investigate.
Minnesota Breach and Response
Hackers attempted to compromise programmable logic controllers (PLCs) at 30 Minnesota water systems by exploiting remote internet connections. Utilities countered by shutting down automated controls and dispatching staff to operate equipment manually, ensuring water remained safe. The attacks, which targeted operational technology rather than corporate networks, began on July 26-27 and marked a coordinated effort. At least 30 utilities were affected, representing a small fraction of the state's systems. No physical damage or contamination occurred.
National Spread and Attribution
Since the Minnesota incidents, Michigan, New Jersey, and several other states have reported similar cyberattacks on water systems. The FBI and CISA are leading investigations but have not attributed the attacks; initial suspicion has fallen on Iran-affiliated hackers. Water sector groups have urged utilities to review remote access controls and update default passwords. The attacks underscore the challenges of securing widely distributed critical infrastructure.
Vulnerability of U.S. Water Systems
The U.S. has approximately 152,000 public drinking water systems, many with limited cybersecurity resources. Internet-connected PLCs, often using factory-default passwords, present an easy target for adversaries. Past CISA alerts have warned about these weaknesses, particularly in rural areas where remote monitoring is essential. The recent attacks highlight the persistent risk of operational technology breaches.
What's Next
The FBI and CISA are continuing forensic analysis, with a joint advisory expected in the coming weeks. It remains unclear whether the attackers will escalate or if water utilities can rapidly close the default-password loopholes that enabled the breach.
1 source
Alleged Iran-linked hackers target 30 water systems in Minnesota in July



