Federal authorities are investigating a cyberattack aimed at community water systems in Minnesota and six other states. The FBI, CISA, and the EPA are involved in the investigation, warning that attackers linked to Iran are targeting crucial infrastructure.
The incident occurred on July 26 and July 27, affecting operational technology in over 30 community water systems. Minnesota IT Services, or MNIT, initiated a cybersecurity response and sought help from federal agencies. Although one water plant temporarily ceased operations, disruptions were managed with manual or backup procedures, ensuring no requests were made for residents to alter their water use.
“Some of that activity degraded water operations,” the FBI reported.
This attack raises serious concerns for towns across America, questioning their resilience against hackers accessing their computer-controlled utilities.
Details of the Minnesota Cyberattack
The attack targeted systems known as operational technology (OT), controlling equipment like pumps and treatment machinery. Braham officials temporarily shut down a water plant, later attributing the outage to a cyberattack. Plymouth experienced communication issues in water towers and lift stations, but maintained water quality. South St. Paul managed an incident with automated controls, while Maple Plain confirmed a technology-targeted event.
A New York Times report on July 30 suggested Iranian hackers might be responsible, though the attribution remains speculative pending more evidence. President Trump rejected the idea of Iranian involvement.
Iranian Hacker Suspicions
CISA issued warnings in April about Iranian-affiliated groups targeting systems controlling critical infrastructure. The agency highlighted vulnerabilities in programmable logic controllers across various manufacturers, but hasn’t explicitly linked this campaign to Minnesota’s incidents.
Risks of Water System Cyberattacks
The U.S. hosts roughly 170,000 water systems, many of which are now operatively linked to internet technology, creating potential access points for hackers if connections aren’t secured. Smaller communities face challenges due to their varied cybersecurity capabilities and outdated technology. Limited budgets often restrict cybersecurity upgrades.
Foreign entities target weak spots known for exposed equipment, outdated systems, or unprotected remote access.
Impact on Drinking Water
A cyberattack doesn’t necessarily taint drinking water, as Minnesota’s situation showed no quality impact. However, the EPA warns there’s potential for disruptions affecting treatment processes.
Manual operations can serve as a fallback, but efficacy relies on employees knowing how and when to deploy these backups.
Recommendations from CISA
CISA released guidance to separate critical operational technology from less secure networks to maintain essential services if compromised.
Recommended actions include restricting internet exposure and employing security controls on necessary remote accesses, altering default passwords, and assigning individual credentials.
What Residents Can Do During a Cyberattack
- Follow official updates from local authorities for instructions regarding water use.
- Do not automatically assume water contamination unless instructed.
- Ensure emergency alerts via mobile or local systems are active.
- Keep a minimal emergency water supply as advised by health authorities.
- Beware of scams utilizing outages as a guise.
Minnesota successfully navigated this attack without a large-scale water quality emergency, using manual operations and contingency methods. However, the scale of systems targeted should concern public officials nationwide and prompt reviews of cybersecurity practices.

Compensation Available in Labcorp Data Breach Settlement
Understanding the Rise of AI-Powered Phishing Scams
Cyberattacks on U.S. Water Infrastructure
Cyberattacks Highlight Vulnerability of U.S. Water Systems
Rethinking the Perception of AI Threats
Cyber Threats Target US Water Infrastructure