Hackers are going after our water now — over 30 Minnesota utilities hit in coordinated cyberattack by apparent Iranian attackers
- Cyberattack hits operational technology at more than 30 Minnesota community water systems, briefly taking treatment plant offline and forcing several towns onto manual operations
- A leaked WaterISAC memo obtained by WIRED relays a state fusion center assessment tying the intrusions to Iranian-affiliated hackers, but no US agency has formally attributed the attack yet
- The CISA had warned four days earlier that Iranian-affiliated actors were compromising internet-facing PLCs, repeating guidance that has mostly fallen on deaf ears
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack, targeting the operational technology running pumps, wells, water towers, and wastewater lift stations rather than the office networks behind them.
Minnesota IT Services disclosed the attack on July 28 2026 and activated a statewide incident response, stating that it wasn’t aware of any Minnesota city asking residents to change their drinking water use just yet.
A memo obtained by Wired, circulated by the water sector information-sharing group WaterISAC and carrying a restricted TLP: AMBER handling marking, relays a Minnesota state fusion center assessment that ties the intrusions to Iranian-affiliated hackers.
Latest Videos FromTechRadar
A warning that was more or less ignored
Four days before the attacks, CISA updated an advisory, AA26-097A, warning that Iranian-affiliated actors were compromising internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens, and possibly others across the US water, energy, and government sectors. It documented confirmed disruptions and financial losses.
This drew no immediate response from state functionaries, and it is easy to see why: the US has tens of thousands of community water systems that serve small populations and lack budgets for dedicated cybersecurity staff.
This is despite there being a precedent: Iranian-linked actors hit the Municipal Water Authority of Aliquippa in Pennsylvania in November 2023, defacing a Unitronics controller with an anti-Israel message. CISA said at the time those devices were exposed to the internet with default passwords still in place. The advice issued then is the same advice being issued this week, which is telling about how little has changed since.
The WaterISAC memo, dated the day the attacks concluded, passes on a state fusion center report linking the activity to Iranian-affiliated actors. That memo was not meant to be public, but it has been corroborated by The New York Times and The Washington Post, which reported that they spoke to federal officials and US intelligence agencies, respectively, lending credence to the claims.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
CISA later warned that attackers are changing PLC passwords to lock operators out of their own equipment, and repeated the advice that has been unchanged for years: get PLCs off the public internet and put remote access behind a VPN or gateway.
Who was affected?
The worst of the cyberattack hit Braham, a town of roughly 1,700 people, where the city said attackers shut down the operating controls, taking the water treatment plant and the well offline. Crews restored it manually within a couple of hours, and residents were told to minimize water use in the meantime.
Plymouth, a Minneapolis suburb of about 80,000, found the problem confined to equipment connected over cellular links at two water towers and several wastewater lift stations. Its IT division disconnected the affected kit from the network entirely to stop the attack and prevent retargeting during reconfiguration.
Maple Plain declared a local state of emergency to manage its response, and South St. Paul reported that some automated controls were compromised. In most cases, contingency procedures held and water and wastewater operations continued.
None of this is happening in a vacuum, however. The June memorandum that paused fighting between the US and Iran has broken down, and both are trading strikes, including recent US attacks near the Strait of Hormuz that destroyed a water facility and cut supply to more than 20,000 people. Whoever carried out the Minnesota attacks, the symbolism of targeting municipal water is unlikely to be accidental.
The damage that these intrusions caused was limited; they produced brief outages that trained staff fixed by hand. That is an outcome with a silver lining, and it depended on utilities having people who knew how to run a treatment plant without its automation, even if its digital defenses collapsed outright.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Cyberattack hits operational technology at more than 30 Minnesota community water systems, briefly taking treatment plant offline and forcing several towns onto manual operations A leaked WaterISAC memo obtained by WIRED relays a state fusion center assessment tying the intrusions to Iranian-affiliated hackers, but no US agency has formally attributed…
Recent Posts
- HP’s HyperX Omen 15 isn’t quite the budget-friendly gaming laptop its predecessor was
- ‘The next major music platform should give people something to do with the music’: Spotify’s former Head of Innovation on his plans to launch an interactive music service, and whether AI features will help or hinder streaming
- Hackers are going after our water now — over 30 Minnesota utilities hit in coordinated cyberattack by apparent Iranian attackers
- Is paying artists enough to convince them to embrace AI?
- Foldables are sort of boring now — and that’s great news for Apple
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023