Close
newsletters Newsletters
X Instagram Youtube

Cyberattack hits 30+ Minnesota water systems, Iran link under review

An illustration shows a person displayed as a hacker using a laptop on an unspecified date and location. (Adobe Stock Photo)
Photo
BigPhoto
An illustration shows a person displayed as a hacker using a laptop on an unspecified date and location. (Adobe Stock Photo)
July 31, 2026 11:49 AM GMT+03:00

U.S. officials are looking into whether Iran was behind a cyberattack on Minnesota water systems this week. More than 30 municipal water systems were hit.

No formal attribution has been made, according to CBS News, The Washington Post and NBC News.

The attacks happened Sunday and Monday. That is according to a statement from Minnesota IT Services.

The activity forced some utilities to switch to manual operations.

What happened at Minnesota's water utilities?

Most confirmed cases involved equipment used to remotely control water systems. That includes devices called programmable logic controllers, or PLCs. Minnesota IT Services shared those details.

No water supply has been compromised, officials said.

Mike Ernster is a public information officer for the Minnesota Department of Public Safety. He told CBS News the state's Bureau of Criminal Apprehension is working with cities and state and federal partners on the issue.

Emily Zimmer is a spokesperson for Minnesota's information technology agency. She said the breaches did not contaminate any city's water supply.

She said no residents have been asked to change their drinking water use.

Is Iran behind the attack? Officials stay cautious

U.S. intelligence agencies have assessed that Iran was likely behind the attack. That is according to several U.S. officials cited by The Washington Post.

A senior law enforcement official told NBC News the breach bears the hallmarks of Iran-backed hackers. But that official said the forensic work is still in early stages.

CBS News reported that investigators are also checking something else. They want to know if the hacker tried to look like Iran to stir tension during the current U.S.-Iran conflict.

Sources told CBS News their view could change as more evidence comes in.

Minnesota has not named a specific actor. "Attribution requires careful analysis of technical evidence alongside broader national and international threat intelligence, and our federal partners are best positioned to lead that work," Zimmer said, according to NBC News.

The FBI is leading the probe. It is working with federal, state and local partners.

"The FBI is aware of the incident and in contact with victims to resolve the matter," the bureau said in a statement to NBC News.

Motorists drive past a large billboard pledging revenge against US President Donald Trump along Jomhouri Street in central Tehran on July 27, 2026. (AFP Photo)
Motorists drive past a large billboard pledging revenge against US President Donald Trump along Jomhouri Street in central Tehran on July 27, 2026. (AFP Photo)

Minnesota cities detail how they responded

In South St. Paul, the city found an issue early Monday. It switched right away to manual operations, a city spokesperson told CBS News. Water and wastewater service kept running with no gaps. The city said drinking water quality, pressure and delivery were not hurt. It found no sign that resident data was accessed.

In Braham, public works staff found a problem Monday. They noticed the well that feeds the city's water tower had stopped working. Mayor Nate George said crews isolated the system, restored a backup and restarted the plant in about 90 minutes. Residents had no loss of water service, George said.

George said his city's response should be a warning to state leaders. He said local governments must defend key systems from foreign threats. He noted they often do this with few staff and old technology.

In Plymouth, officials found an outage Sunday evening. They spotted hacked PLCs at two water towers and 14 sewer lift stations, a city official told CBS News. Crews cut those devices off from the cellular network. The city moved to manual operations. Normal service came back by Tuesday afternoon. Officials said water quality and pressure were never hurt.

"I think you never expect it to happen to you," Michael Thompson, Plymouth's public works director, told CBS News.

A general view of an American flag flying above the 18th green during the second round of the 3M Open 2026 at TPC Twin Cities on July 24, 2026 in Blaine, Minnesota. (AFP Photo)
A general view of an American flag flying above the 18th green during the second round of the 3M Open 2026 at TPC Twin Cities on July 24, 2026 in Blaine, Minnesota. (AFP Photo)

Federal agencies warn of broader threat

The FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency, or CISA, issued a joint warning Thursday. They said hackers are targeting exposed industrial controls at water and wastewater utilities. The agencies said this goes beyond Minnesota. They cited incidents in at least seven states, CBS News reported.

Nick Anderson is the acting director of CISA. He confirmed the agency is seeing a sharp rise in threats to water utility controllers. "We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible," he said.

CISA also flagged a specific risk. Some water groups should check their outside connections. That is because the activity includes cell modems that may not show up in routine security scans.

Chris Butera holds the title of acting executive assistant director for cybersecurity at CISA. He told NBC News the agency "has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity."

Iran's cyber playbook dates to 2023

Federal agencies have said before that hackers tied to Iran's Islamic Revolutionary Guard Corps (IRGC) hit several U.S. water plants in 2023. Those hackers used controllers that still had default passwords, CBS News reported.

Joe Slowik leads threat research at Dataminr. He told The Washington Post that hackers have hit water and energy systems across the country since the U.S.-Iran war began on Feb. 28. He linked the Minnesota case and others to a Revolutionary Guard unit known as the Cyber Electronic Command.

Kurt Gaudette leads intelligence at Dragos. He told The Washington Post the Minnesota attack fits a pattern seen in March. Hackers are targeting small utilities that use exposed controllers with default passwords.

He pointed to a 2023 hack at a water pumping station in Aliquippa, Pennsylvania. A group tied to the Revolutionary Guard, known as CyberAv3ngers, claimed that attack.

Alex Orleans leads threat intelligence at Sublime Security. He told The Washington Post that Iran's cyberattacks aim more at psychological impact than destruction. He said the goal is to sway American opinion and to show Iran's own leaders the hackers are helping the war effort.

July 31, 2026 11:49 AM GMT+03:00
More From Türkiye Today