A coordinated cyberattack disrupted water utility operations in Minnesota and six other states, prompting a state cybersecurity response and a federal investigation. The FBI said water or wastewater utility companies in seven states were affected, adding that some of that activity degraded water operations.
Minnesota IT Services, known as MNIT, said the attack targeted operational technology at more than 30 community water systems on July 26 and 27. Operational technology, commonly called OT, controls physical equipment such as pumps, valves and treatment machinery. The agency activated the state's cybersecurity response and brought in federal agencies to investigate. One water plant temporarily went offline, and several other communities reported problems involving automated controls or communications equipment. Workers switched to manual operations or used backup procedures to keep essential services running.
Four Minnesota communities have publicly described specific effects. Braham city officials first reported that the water plant had gone offline for an unknown reason. Crews restored the facility within hours and said it was again filtering and treating water as expected. Officials later blamed a malicious cyberattack against computerized operating systems. While the plant was down, the city relied on water already stored in its tower.
Plymouth reported communications problems involving two water towers and several wastewater lift stations, but officials said water levels and water quality remained unaffected. South St. Paul identified a cybersecurity incident involving automated water utility controls, and Public Works employees used established contingency procedures to maintain normal water and wastewater operations. Maple Plain also publicly confirmed that its water utility technology had been targeted. State officials said no active requests were made for residents to reduce or change their drinking water use.
No definitive attribution has been announced. The New York Times reported on July 30, citing U.S. and state officials familiar with the investigation, that investigators preliminarily believe Iranian hackers were probably responsible. President Donald Trump rejected the suggestion that Iran was behind the breaches. Investigators cautioned that the assessment could change as more technical evidence is collected, and they have not ruled out the possibility that attackers attempted to make the activity appear Iranian.
The Cybersecurity and Infrastructure Security Agency warned in April that Iranian-affiliated hackers were targeting internet-exposed programmable logic controllers. These devices help control machinery and other equipment at water systems and additional critical infrastructure facilities. The agency initially highlighted certain Rockwell Automation and Allen-Bradley controllers, and on July 22 it expanded the warning to include equipment from Schneider Electric, Siemens and potentially other manufacturers. Federal officials have not publicly tied that campaign to the Minnesota incidents.
The United States has close to 170,000 drinking water and wastewater systems. Many now connect physical equipment to internet-enabled technology, allowing workers to monitor facilities remotely. Remote access helps utilities manage equipment spread across wide service areas, but it may also give attackers a route into vital controls when connections are not secured. Smaller communities often face the greatest challenge.
The Government Accountability Office has said water systems have widely different cybersecurity capabilities, and many use older technology that can be difficult to update. Utilities must also stretch limited budgets across essential repairs and regulatory requirements. Cybersecurity upgrades may compete with work that residents can see, such as replacing aging equipment. A large utility may employ dedicated security professionals, while a small town may rely on plant operators who already handle daily operations and after-hours problems.
Water systems remain attractive targets because even a limited disruption can create fear far beyond the equipment involved, and the Minnesota experience shows the risk could reach any state. Authorities have not released a full list of affected utilities or their recovery status, and the investigation is expected to continue for weeks.
