Iranian hackers suspected in coordinated cyberattack on more than 30 Minnesota water systems
A coordinated cyberattack struck more than 30 municipal water systems across Minnesota in late July, and a preliminary U.S. assessment points to Iranian hackers — a sign that America's smallest utilities are now on the front line.
A coordinated cyberattack struck more than 30 municipal water systems in Minnesota over two days, July 26 and 27. A preliminary assessment by American investigators indicated Iranian hackers were probably responsible, though investigators stressed their attribution findings were not final.
A coordinated cyberattack struck more than 30 municipal water systems across Minnesota over two days, on July 26 and 27. Minnesota officials described the incident as a coordinated attack, and Minnesota IT Services publicly disclosed it on Tuesday, July 28. The cities of Plymouth, South St. Paul, Maple Plain, and Braham have confirmed they were among those hit. U.S. authorities have opened an investigation into whether Iranian actors were responsible. A preliminary assessment by American investigators indicated Iranian hackers were probably behind the attack, and a memo from the water utilities information sharing group WaterISAC, obtained by WIRED, linked dozens of cyberattacks against Minnesota water utilities to Tehran. Investigators stressed, however, that their attribution assessments were not final. The targeting of water systems strikes at some of the most basic infrastructure Americans depend on, and small municipal utilities often lack the resources to defend against sophisticated attackers. If the Iranian link is confirmed, the incident would mark a significant escalation in state-linked cyber operations against civilian services in the United States.
A two-day coordinated attack on Minnesota's water systems
More than 30 municipal water systems across Minnesota came under a coordinated cyberattack over the course of two days, July 26 and July 27, in one of the largest known intrusions into American water infrastructure. State officials described the incident as a coordinated cyberattack, rather than a series of isolated incidents, pointing to a single campaign directed at dozens of community water systems at once.
Minnesota IT Services, the state's technology agency, publicly disclosed the attacks on Tuesday, July 28, a day after the intrusions ended. The disclosure brought to light an operation that had unfolded quietly over the weekend against utilities serving cities and towns across the state.
The precise scale remains uncertain. Minnesota officials and multiple accounts describe more than 30 targeted systems, while one assessment put the number of affected Minnesota water utilities at 36, according to reporting on the incident. Investigators have not published a definitive count.
There is also a discrepancy over timing. Most accounts refer only to July 26 and 27, but one source dates the attacks to July 26–27, 2026. Authorities have not clarified the discrepancy publicly.
Four cities have publicly confirmed they were among those attacked: Plymouth, South St. Paul, Maple Plain, and Braham. The full list of affected utilities has not been released, and officials have not said how many of the targeted systems suffered operational disruption as opposed to attempted intrusion. What is established is that the attackers moved against a large share of the state's municipal water infrastructure simultaneously, over a single weekend, before the state went public with the news.
Attacks begin
Coordinated cyberattack targets more than 30 Minnesota municipal water systems over two days
One source dates the attacks to this period in 2026
Minnesota IT Services publicly discloses the attacks
Investigators point toward Iran, but stop short of final attribution
The strongest indication of who carried out the attacks comes from a preliminary assessment by American investigators, which indicated that Iranian hackers were probably responsible. That assessment, however, remains just that: preliminary. Investigators have stressed that their attribution findings are not final, and U.S. authorities have opened a formal investigation into whether Iranian actors were behind the intrusions.
Further evidence pointing toward Tehran appears in a memo issued by WaterISAC, the information-sharing group serving the water utility sector. The memo, obtained by WIRED, linked dozens of the cyberattacks against Minnesota water utilities to Tehran. It represents the most detailed attribution claim to emerge so far, though it stops short of the certainty that a completed government investigation would carry.
The gap between suspicion and confirmation matters. Attribution in cyber operations is rarely straightforward, and officials familiar with such investigations caution against treating early assessments as settled conclusions. In this case, the available record supports a direction of inquiry rather than a verdict: Iranian hackers are the leading suspects, American investigators believe they were probably responsible, and an industry group's analysis ties the campaign to Tehran. But U.S. authorities have not publicly named a specific group, presented technical evidence, or announced any findings from their investigation.
What is known is that the attacks were coordinated and deliberate. What remains unconfirmed is who ordered them, who executed them, and whether the operation had the backing of the Iranian state.
How the attackers reportedly reached the utilities' control systems
The attackers appear to have gone after the machinery that runs the plants, not just office computers. According to reports, they targeted programmable logic controllers, the industrial devices that automate pumps, valves, and treatment processes at water facilities. The incident was characterized as an operational technology attack, meaning it struck the systems that control physical equipment rather than conventional IT networks.
Reports indicate that automated control systems at the targeted utilities were affected, and that cellular communications links associated with the water systems were disrupted. That disruption matters: many utilities rely on cellular connections to monitor and manage remote sites, so losing those links can leave operators blind to what is happening across their networks.
The impact was not merely digital. According to reports, operations at one water plant were disrupted to the point that it was taken offline. At other affected systems, operators noticed their control equipment had been compromised, and some utilities were forced to switch to manual operations as a result, running processes by hand that are normally handled automatically.
How the attackers gained access to the utilities' systems and their programmable logic controllers in the first place remains unknown. Investigators have not publicly described the entry point, and the technical findings are still being assessed.
Plymouth to Braham: the towns that confirmed they were hit
Four communities have publicly confirmed their water systems were among those hit. Plymouth, South St. Paul, Maple Plain, and Braham each acknowledged being targeted in the coordinated attack, which Minnesota officials said struck more than 30 municipal water systems over two days, on July 26 and July 27.
The confirmed towns span the state geographically. Plymouth is a large suburb west of Minneapolis; South St. Paul sits just southeast of the capital; Maple Plain is a small community in Hennepin County; and Braham is a rural city roughly an hour north of the Twin Cities. Together they illustrate the breadth of the campaign, which reached both sizeable municipal utilities and small-town systems.
The precise number of affected utilities remains unclear. Minnesota officials and multiple reports describe more than 30 community water systems as having been targeted. One report puts the figure higher, at 36 Minnesota water utilities affected, though that number has not been officially confirmed.
Beyond the four cities that have come forward, the full list of affected communities is not yet known. State officials have not released a comprehensive accounting of which systems were hit, and other utilities may yet confirm they were among the targets.
State and federal agencies mobilize after the disclosure
The response moved quickly once the attacks became public. Minnesota IT Services disclosed the incident on Tuesday, July 28, and according to reports the agency activated its cybersecurity incident response capabilities statewide in reaction to the intrusions. That step put the state's central technology office at the center of the effort to assist affected utilities and assess the damage.
Federal agencies also engaged, according to reports. The FBI and the Cybersecurity and Infrastructure Security Agency issued warnings to local utilities across the country following the attack, urging operators to scrutinize their own systems for signs of similar intrusions. Those warnings reflected concern that the campaign was not confined to Minnesota.
That concern appears well founded. Malicious cyber activity reportedly affected technology at water systems in at least seven states, including Minnesota, according to reports. The identities of the other states have not been disclosed, and it remains unclear how many utilities outside Minnesota were touched or how severe the impact was in each case.
The breadth of the reported activity helps explain why the warnings went national rather than remaining a regional matter. For water utilities elsewhere, the alerts served as a prompt to review defenses around the operational technology that controls treatment and distribution, even as investigators continued working to establish who was behind the campaign and how far it reached.
What the attack means for America's water utilities
The Minnesota incident lands on one of the most sensitive points in American critical infrastructure: the operational technology that keeps drinking water flowing. According to reports, the attackers did not merely breach office networks. They reached the automated control systems and programmable logic controllers that run physical processes at the utilities, and at least one water plant was reportedly taken offline. Some operators, reports suggest, were forced to switch to manual operations after noticing compromised control equipment. That combination — a coordinated, multi-target campaign against control systems rather than data — is precisely the scenario that has long worried security officials about the water sector, which is fragmented across thousands of small municipal systems with limited cybersecurity resources.
The implications extend beyond Minnesota. Malicious cyber activity reportedly affected technology at water systems in at least seven states, according to reports, suggesting the campaign was national in scope even if Minnesota bore the brunt. The FBI and CISA reportedly issued warnings to local utilities nationwide in the aftermath, a sign that federal agencies treated the incident as a live threat rather than a closed episode.
What comes next is an investigation, not a verdict. American investigators' preliminary assessment points to Iranian hackers, and a memo from the water utilities' information sharing group WaterISAC linked dozens of the attacks to Tehran. But investigators have stressed that attribution is not final, and U.S. authorities are still examining whether Iranian actors were responsible.
Several questions remain open. Investigators have not established how the attackers gained access to the utilities' systems and control equipment. The full list of affected cities is unknown, as is the identity of the other states whose water systems saw malicious activity. Until attribution is confirmed, the episode stands as a warning about vulnerability rather than a settled case of state-sponsored attack.
Frequently asked questions
What happened in the Minnesota water utilities cyberattack?
A coordinated cyberattack targeted more than 30 municipal water systems in Minnesota over two days, on July 26 and July 27. Minnesota IT Services publicly disclosed the attacks on Tuesday, July 28. The cities of Plymouth, South St. Paul, Maple Plain, and Braham confirmed they were attacked. According to reports, some utilities were forced to switch to manual operations after operators noticed compromised control equipment.
Who was behind the cyberattack on Minnesota water systems?
A preliminary assessment by American investigators indicated Iranian hackers were probably responsible, and U.S. authorities opened an investigation into whether Iranian actors carried out the attacks. A memo from the water utilities information sharing group WaterISAC, obtained by WIRED, linked dozens of the cyberattacks to Tehran. Investigators stressed, however, that their attribution assessments were not final.
How many water utilities were affected in Minnesota?
More than 30 community water systems were targeted, according to Minnesota officials. One report put the number of affected utilities at 36, though that figure has not been firmly established. Four cities have publicly confirmed they were attacked: Plymouth, South St. Paul, Maple Plain, and Braham. The full list of affected utilities has not been released.
What did the hackers target at the water utilities?
According to reports, the attackers targeted programmable logic controllers, the devices that run automated operations at the utilities, and the incident was characterized as an operational technology attack. Some facilities reportedly suffered outages, one water plant was taken offline, and cellular communications links tied to the targeted systems were disrupted. How the attackers gained access remains unknown.
How did authorities respond to the attacks?
Minnesota IT Services activated its cybersecurity incident response capabilities statewide, according to reports. The FBI and CISA reportedly issued warnings to local utilities nationwide after the attack, and reports suggest malicious cyber activity affected technology at water systems in at least seven states, including Minnesota. U.S. authorities continue to investigate whether Iranian actors were responsible.
Compiled from reporting by 9 independent outlets. How we source our reporting.




