SYS::ONLINE
Wasteland.
Briefs1655
Issues21
SinceFeb 2026
LIVE
▣ Breach US-MUNICIPAL-WATER 2026-08-01

U.S. Municipal Water Utilities: Multi-State OT Attacks Linked to Iranian-Affiliated PLC Exploitation

"The FBI and the Environmental Protection Agency issued a joint public service announcement on Thursday, July 30, 2026, confirming that water and wastewater utilities in at least seven U.S. states reported cyberattacks…"

The FBI and the Environmental Protection Agency issued a joint public service announcement on Thursday, July 30, 2026, confirming that water and wastewater utilities in at least seven U.S. states reported cyberattacks to the FBI within a single week, with some of the malicious activity degrading water operations. The agencies did not name the affected states or identify a culprit. The warning followed a coordinated intrusion campaign on July 26 and 27 that hit operational technology at more than 30 Minnesota community water systems, according to Minnesota IT Services (MNIT), which activated a statewide incident response. CISA said in a separate alert that some of the larger attacks "resulted in boil water notices and sustained manual operations," without specifying locations. CNN, citing U.S. officials, called it one of the most serious cyberattacks on U.S. water systems in years. Attribution remains officially open, though a leaked WaterISAC memo obtained by WIRED links the Minnesota intrusions to Tehran.

What Happened

The clearest picture comes from Minnesota, where the campaign is best documented. MNIT confirmed that a coordinated cyberattack targeted operational technology at more than 30 community water systems over the weekend of July 26 and 27, 2026. City officials across the state discovered outages and disruptions to automated operating controls beginning Sunday night and continuing into Monday morning, per the Star Tribune, which named Plymouth and South St. Paul among the affected Twin Cities suburbs.

Specific impacts reported by Governing and the Star Tribune:

Beyond Minnesota, detail is thin. The federal PSA establishes that utilities in at least seven states reported incidents, and CNN reports that some utilities issued boil-water notices and switched to manual mode, taking systems offline. Neither the FBI, EPA, nor CISA has publicly named those utilities or states.

Accounts differ on the severity of public health impact. CISA's alert references boil water notices resulting from larger attacks, and CNN corroborates that framing. In Minnesota specifically, MNIT said the Minnesota Department of Health was "not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage" as of July 28, and affected city officials told the Star Tribune there was no impact to water quality. Braham's temporary conservation request and the unnamed city cited by Governing sit awkwardly against that statement. The most defensible reading is that boil-water notices occurred somewhere in the seven-state set, and that Minnesota's disruptions were operational rather than water-quality events.

What Was Taken

No source reports theft of customer or personal data. City officials in the affected Minnesota communities told the Star Tribune there is no indication customer data were accessed or compromised, and MNIT's statement makes no data-loss claim. This was a disruption campaign against control systems, not a data breach.

The exfiltration risk that does apply is industrial, not personal. Tenable's Research Special Operations team notes that the July 22, 2026 update to CISA Advisory AA26-097A documented PLC project file exfiltration for the first time in this activity cluster, alongside detection guidance for manipulation of reusable code modules embedded in PLC programs. Stolen project files hand an adversary the logic, tag structure, setpoints, and safety interlocks of a plant, which is reconnaissance for a future manipulation attack rather than an immediate service impact. No source states that project files were taken from Minnesota specifically; treat that as a documented technique in the campaign, not a confirmed loss here.

Why It Matters

Three things separate this from the routine drumbeat of water-sector alerts.

Scale and simultaneity. More than 30 utilities in one state inside a 36-hour window, plus reported incidents in six or more additional states in the same week, is not opportunistic scanning. It indicates a target list built in advance against a known, unpatched exposure.

The targets were small. Plymouth, South St. Paul, and a town of 1,700 are not utilities with SOCs, OT security engineers, or 24/7 monitoring. The sector's structural weakness is that thousands of independently operated systems share the same handful of internet-exposed controller platforms with none of the shared defensive capability.

Effects were physical, not informational. Water towers that could not be filled, lift stations dark to SCADA, and plants running on manual staffing are kinetic outcomes. Manual operation is a viable fallback for hours or days, not for a sustained campaign, and it consumes exactly the small-utility staff capacity that would otherwise go to remediation.

The attribution picture is genuinely contested and defenders should hold it loosely. WIRED reports that a WaterISAC memo it obtained links dozens of the Minnesota attacks to Iran. A law enforcement official told NBC News the Minnesota activity had "hallmarks of Iranian meddling." Tenable states that attribution remains pending federal investigation while noting the timing aligns closely with escalating Iranian-affiliated PLC exploitation documented in AA26-097A. MNIT, the FBI, and the EPA have made no public attribution. President Trump, speaking at Camp David on Friday, rejected the Iran framing outright and blamed Minnesota's leadership and Gov. Tim Walz, saying "Iran's got bigger problems than worrying about Minnesota." The technical indicators and the political statements are pointing in different directions; the indicators are the more useful input for defensive planning.

The Attack Technique

The documented tradecraft in this activity cluster centers on internet-exposed programmable logic controllers and HMIs rather than enterprise IT compromise.

Per Tenable's summary of CISA Advisory AA26-097A and its July 22, 2026 update:

The Minnesota field reporting is consistent with this model. Braham's compromise came through a wireless connection into the water plant that let malware shut down operating controls. Plymouth's symptom set, towers and lift stations losing communication with the remote monitoring platform, is what remote controller manipulation or denial looks like from the operator's chair. Governing notes that hackers "specifically went after technology that monitors or controls physical water system operations." No source confirms which CVE or malware family was used at any named Minnesota utility, and that link remains inferential.

What Organizations Should Do

  1. Take exposed control systems off the public internet now. Nextgov reports CISA is urging water utilities to pull internet-exposed systems down in the wake of the Minnesota hacks. This is the single highest-value action and it does not depend on attribution being resolved. Inventory every PLC, HMI, cellular modem, and remote-access appliance reachable from the internet, including vendor-installed links you did not commission.
  2. Scope beyond Rockwell. Enumerate Schneider Electric and Siemens controllers as well, per the July 22 AA26-097A update. Assume CVE-2021-22681 cannot be patched and compensate with network isolation, VPN-only access with phishing-resistant MFA, and default-credential elimination.
  3. Audit wireless and radio links into plant networks. Braham's intrusion path was a wireless connection to the water plant. Point-to-point radio, cellular backhaul to remote sites, and telemetry links to towers and lift stations are frequently outside both the IT and OT security perimeter.
  4. Hunt for logic tampering, not just malware. Compare running PLC programs against known-good offline baselines, with specific attention to reusable code modules and function blocks, per the new CISA detection guidance. Check for evidence of project file access or export.
  5. Rehearse and staff sustained manual operations. Plymouth's two-day recovery worked because it could put people at towers and lift stations quickly. Confirm you have current manual procedures, trained staff, and physical site access for a multi-day, not multi-hour, outage.
  6. Report to the FBI and coordinate through your state and WaterISAC. The seven-state picture only exists because utilities reported. Minnesota's response ran through MNIT with the Minnesota Fusion Center, Department of Health, Pollution Control Agency, CISA, EPA, and FBI; smaller utilities should assume they need that scaffolding rather than trying to triage OT compromise alone.

Sources: Hackers targeted municipal water systems in 7 states this week, FBI... | Minnesota Water Cyber Attack and CISA Advisory AA26-097A | CISA urges water utilities to take exposed systems down after Minne... | A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Ira... | Sweeping cyberattack on water systems in multiple states ... | MNIT activates statewide cybersecurity response to ... - MN.gov | Cyberattack hits water systems in several MN cities | Troubled Waters: Minnesota Cities Weather Cyber Attack