Feds Issue Warning About Hackers Targeting Water Systems

Major water systems were alerted of an increased risk to exposed technology after Minnesota’s water systems were attacked.
Feds Issue Warning About Hackers Targeting Water Systems
A water tower is seen in Plymouth, Minn., on July 30, 2026. A cyberattack targeted the operating technology at more than 30 water systems in Minnesota, including Plymouth's, earlier in the week, state officials said. Ellen Schmidt/AP Photo
|Updated:
0:00

A federal cybersecurity agency warned water systems throughout the United States on July 30 of an increase in threats to water and wastewater systems.

“These threat actors are targeting water entities of all sizes,” the Cybersecurity and Infrastructure Security Agency (CISA) stated in the alert.
CISA, the agency that coordinates national responses to cyber and physical threats, issued the notice after more than 30 community water systems in Minnesota were hit with a coordinated cyberattack.

Minnesota IT Services activated emergency protocols immediately after the attacks on July 26 and July 27, and began an investigation that continues this week.

Among the communities affected by the breach was the city of Braham, also known as the “Homemade Pie Capital of Minnesota.” City officials announced its water plant was “offline for an unknown reason” at about 9:30 a.m. on July 27. The water was back online two hours later.

“Crews identified that the water plant outage was a result of a malicious cyber-attack of computerized operating systems by unknown actors,” the city said in a release.

The FBI is investigating this week’s cyberattack in Minnesota but has not publicly identified what organization was responsible.

The FBI, CISA, and other federal agencies warned last week that Iranian hackers were targeting water and wastewater systems and operational controls of other critical infrastructure.

The agencies advised water systems to check operation programs manufactured by Rockwell Automation, Schneider Electric, Siemens, and other manufacturers.

In its latest alert July 30, CISA urged critical infrastructure owners, operators, and integrators to remove computer-automated systems and other technology from the internet as soon as possible.

Hackers targeting the systems have changed passwords to lock out operators and disconnected the systems by changing their IP addresses. The activity resulted in boil water notices and manual operations, CISA warned.

Water systems with proven cybersecurity systems were still encouraged to validate their external connections.

Targets for the threat actors include cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine scans, the agency said.

Tenable, a security exposure management company, theorized the cyberattack in Minnesota related to the escalating Iran conflict.

“Federal and state officials have not publicly attributed the Minnesota attacks to any specific actor,” Tenable stated in a July 28 post on its website. “However, the operational pattern is consistent with the CyberAv3ngers threat ecosystem, a state-directed group the U.S. government has formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command.”
Google LogoMark Us Preferred on Google
Jill McLaughlin
Jill McLaughlin
Author
Jill McLaughlin is an award-winning journalist covering politics, environment, and statewide issues. She has been a reporter and editor for newspapers in Oregon, Nevada, and New Mexico. Jill was born in Yosemite National Park and enjoys the majestic outdoors, traveling, golfing, and hiking.