A “coordinated cyberattack” targeted more than 30 community water systems in the U.S. state of Minnesota on July 26 and July 27, the state’s information technology agency said in a statement.
Minnesota IT Services (MNIT) said on July 28 that it activated its incident response capabilities immediately after learning of the attack. MNIT said that an investigation remains active, and responders continue to “assess affected systems.”
“At this time, they are not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage,” it said.
John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer, said such attacks require “a coordinated, whole-of-government response.”
He added that the agency “is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks.”
Emily Zimmer, a spokesperson for the agency, told Reuters in an email that while the investigation remains ongoing, “the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.”
Zimmer said the agency could not yet discuss formal attribution or specifics of the incidents. She added that the agency used the term “attack“ to describe the situation ”because investigators identified unauthorized access with malicious intent directed at these systems.”
In a June 16 article about safeguarding critical water infrastructure, Microsoft said that while cyberattacks typically “wreak havoc” on digital systems, at a water utility, a network breach “can move quickly into the physical realm.”
“Online systems can give an attacker access to operational technology—physical equipment like pumps, sensors, and chemical treatment systems,” it said.
It said that local utilities make prime targets because of their size, and most U.S. water utilities are tiny operations.

According to the U.S. Environmental Protection Agency (EPA), 97 percent of the nation’s 156,000 public water systems serve fewer than 10,000 customers.
While it is not yet clear who is responsible for the attacks, Iranian-linked hackers have for years targeted U.S. water systems to varying levels of success.
Handala Warning
Iran’s state-run Press TV, which the U.S. Treasury has sanctioned for acting as a propaganda arm of the Islamic Revolutionary Guard Corps, reported on July 23 that the Handala hacking group warned it will continue targeting U.S. industrial control systems.
Handala is one of several public personas used by a hacking unit operating under Iran’s Ministry of Intelligence and Security (MOIS) as part of the agency’s psychological operations, according to the U.S. Department of Justice.
An April 7 Cybersecurity and Infrastructure Security Agency (CISA) advisory warned that Iranian-affiliated hackers were attacking internet-facing programmable logic controllers, computer devices used to interact with machinery and other critical infrastructure networks, manufactured by Rockwell Automation.
The group said on July 23 that attacks targeting programmable logic controllers and supervisory control and data acquisition systems represented only a portion of its capabilities, and warned wider campaigns could target sectors including water, electricity and transportation networks, Press TV reported.
A July 22 update to the advisory expanded the scope of the targeting to include devices manufactured by Schneider Electric, Siemens and potentially other manufacturers.
CISA said in its advisory that some hacking activity resembles operations previously attributed to CyberAv3ngers, also known as the Shahid Kaveh Group, which is affiliated with the Cyber Electronic Command of Iran’s Islamic Revolutionary Guard Corps.
The Epoch Times reached out to CISA for further comment but did not receive a response by publication time.
On June 11, 2026, the cybersecurity company Dataminr issued an alert about Handala, stating that the hacking group had claimed to have compromised California Water Service (Cal Water), one of the largest investor-owned water utilities in the United States, serving approximately 2 million customers across 100 California communities. The hackers published 5GB of data.
CyberAv3ngers struck a small water utility in Aliquippa, Pa., in November 2023, gaining control of a device at the Municipal Water Authority, according to a 2025 report by the Maryland Cybersecurity Council.
Cyberattacks on Water Systems
According to Xylem, a global water technology provider, there’s “no lack of examples” of cyberattacks involving water systems.
In October 2024, New Jersey-based American Water, the largest regulated water and wastewater utility company in the United States, which serves more than 14 million people in 14 states and on 18 military installations, had to shut down computer systems due to a cyberattack.
In January 2024, the Russian hacktivist group Cyber Army of Russia Reborn claimed responsibility for attacks on water facilities in the United States and Poland. In Muleshoe, Texas, one breach resulted in the loss of tens of thousands of gallons of water.

Authorities have assessed that a Chinese Communist Party (CCP) state-sponsored cyber group known as Volt Typhoon is seeking to pre-position itself on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure.
In a 2024 statement, CISA said that Volt Typhoon uses hacking techniques that avoid installing malware, which can be relatively easily detected, and instead rely on built-in tools that are harder to spot.
This means they exploit weak admin passwords, factory-default logins, and unpatched internet-connected devices
In a January report from the Congressional Research Service, Chris Jaikaran, a specialist in cybersecurity policy, said that the U.S. Intelligence Community (IC) assesses that China is “the most active and persistent cyber threat” to U.S. institutions.







