Cybersecurity

U.S. Investigates Possible Iranian Cyberattack on Water Systems in Seven States

Federal authorities are investigating malicious cyber activity targeting water systems in at least seven U.S. states, including Minnesota and Michigan, that disrupted control technology and forced some utilities to switch to manual operations, officials disclosed in late July 2026. The probe is focused on determining whether Iran-based hackers are responsible, although no definitive attribution has been made.

What Happened

Throughout the week ending July 30, 2026, cyber intrusions affected operational technology—specifically programmable logic controllers (PLCs)—at multiple water utilities across seven states. Michigan and Minnesota confirmed incidents impacting significant numbers of community water systems, with Minnesota reporting more than 30 utilities affected. While the FBI acknowledged incidents in at least seven states, agencies have withheld details on the exact locations outside Minnesota and Michigan.

Officials emphasized no water supply contamination or public health risks resulted from the attacks, with local operators successfully shifting to manual control methods during the disruptions. State agencies, including Minnesota’s Department of Environment, Great Lakes, and Energy, reported that systems continued to operate safely and all detected issues were promptly addressed.

The federal Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Environmental Protection Agency (EPA) have issued warnings about increased targeting of internet-exposed industrial control systems within water and wastewater sectors. CISA’s acting director, Nick Anderson, highlighted a “significant increase in cyber threat actors targeting PLCs at water utilities,” urging organizations to remove publicly accessible operational technology from internet connections.

President Donald Trump publicly rejected Iranian involvement, attributing the incident to incompetence by Minnesota’s Democratic governor Tim Walz, a sharp deviation from the ongoing federal investigation. Walz countered by blaming federal cuts to cybersecurity and stressing the seriousness of modern cyber warfare.

Key Facts

The FBI and CISA confirmed the attacks impacted water system control devices in at least seven states but have not fully attributed responsibility. Minnesota reported over 30 community water systems were affected, with no loss of water quality or supply. Michigan officials stated the systems remain operational and safe despite disruptions.

Specific incidents in Minnesota’s cities such as South St. Paul, Braham, and Plymouth involved compromised PLCs necessitating emergency manual controls and disconnection from cellular networks. Public services continued uninterrupted, and investigations have revealed no evidence of data breaches involving residents.

The Minnesota Department of Public Safety and the Bureau of Criminal Apprehension’s Minnesota Fusion Center are collaborating with state and federal partners to manage the situation.

What This Means

The investigation into the suspected Iranian cyberattack on U.S. water utilities highlights the increasing vulnerability of critical infrastructure to foreign cyber threats. The targeting of programmable logic controllers used to remotely manage water treatment and delivery systems signals attackers’ growing sophistication and the potential risks to essential public health services if defenses fail.

For communities, the incident underscores the importance of robust cybersecurity measures in public utilities and the need for contingency plans, as utilities were forced to revert to manual operations. For policymakers, it raises questions about the adequacy of federal support for infrastructure cybersecurity, especially following budget cuts to agencies like CISA. The political exchange between President Trump and Governor Walz further illustrates how cyber incidents can intensify partisan divisions, potentially complicating unified responses to cybersecurity threats.

Preventive measures advocated by federal agencies, such as removing internet exposure of critical control devices and rigorous external connection audits, are essential in minimizing the chance of successful intrusions. This episode could spur renewed federal and state focus on safeguarding industrial control systems across water utilities and other critical sectors.

Background

This is not the first instance of Iran-linked hackers targeting U.S. water utilities. In 2023, Iranian actors affiliated with the Islamic Revolutionary Guard Corps accessed similar water and wastewater infrastructure by exploiting poorly secured internet-connected controllers. Federal agencies have continuously warned about the rising threat to water systems, pointing to vulnerabilities like unchanged default passwords on operational technology.

The recent attack comes amid broader geopolitical tensions between the U.S. and Iran and follows official warnings issued by the FBI, EPA, and CISA regarding attackers’ increased focus on industrial control systems in critical infrastructure.

What Remains Unclear

Authorities have yet to conclusively attribute the attack to any specific actor, including Iranian hackers. There is also no confirmation on whether the incidents across the seven states are linked to the same perpetrator or constitute multiple separate attempts. The potential for false-flag operations—where attackers impersonate Iranian cyber actors—is being considered by investigators.

What Comes Next

Federal and state agencies continue to analyze technical forensic evidence and coordinate responses with affected utilities. CISA and the FBI are expected to issue further guidance and threat assessments as their inquiries progress. Public officials and cybersecurity experts are likely to monitor how infrastructure protections are enhanced to prevent similar attacks.

Sources

This article is based on reporting and publicly available information from the following sources:

Read more Cybersecurity stories on Goka World News.

Ethan Clarke
About the editor

Ethan Clarke

Ethan Clarke Role: Cybersecurity Editor Ethan Clarke covers cybersecurity incidents, data breaches, online threats, ransomware, software vulnerabilities, and digital safety. His reporting focuses on confirmed details, affected systems, official advisories, and practical context without making unsupported accusations.

View all posts by Ethan Clarke