Home Technology Cybersecurity Cyberattack Hits Minnesota Water Systems

Cyberattack Hits Minnesota Water Systems

Cyberattack Hits Minnesota Water Systems

By July 30, 2026, more than 30 community water systems in Minnesota faced a cyberattack. As technology disruptions spread, utilities had to switch to manual operations. Authorities, both state and federal, are investigating the source of this attack. There is speculation about possible Iranian hacker involvement, but no definite attribution has been made yet. This uncertainty continues as more evidence is gathered.

The cyberattack primarily impacted systems used to monitor and control water equipment. According to Minnesota IT Services, the attack targeted programmable logic controllers (PLCs). Despite the intrusion, Minnesota’s water supply has not been reported as compromised, confirmed Mike Ernster of the Minnesota Department of Public Safety. The Bureau of Criminal Apprehension’s Minnesota Fusion Center is collaborating with state, municipal, and federal partners to address the issue.

Nick Anderson, acting director of the federal Cybersecurity and Infrastructure Security Administration (CISA), noted a significant increase in threats targeting PLCs at water utilities. Anderson urged owners and operators to remove these devices and other exposed technology from the internet promptly. Investigators found some common factors in the incidents’ timing and affected technology types, but no single actor’s involvement has been confirmed.

In response to the attack, the city of South St. Paul quickly identified the issue and implemented alternative procedures. Manual operations ensured water and wastewater services continued uninterrupted. South St. Paul officials confirmed that drinking water treatment, quality, and delivery were not impacted, and no resident or customer data was accessed.

Braham, a rural city north of Minneapolis, also confronted the disruption. Public works staff corrected a malfunctioning water tower well, restoring service within 90 minutes. Mayor Nate George emphasized that residents did not lose water service. Steps were taken to disconnect the system from public internet exposure, and meetings with technology providers ensued to plan for remediation.

The FBI is aware of the incidents and remains in contact with impacted parties, without additional information disclosed. CISA, part of the Department of Homeland Security, reiterated the need for infrastructure owners and operators to ensure PLCs and operational technology are shielded from public internet access. Even water organizations with robust cybersecurity protocols need to validate external connections to prevent attacks.

This cyber threat echoes previous incidents where Iran-linked hackers targeted U.S. water utilities. Agencies reported that such actors, affiliated with Iran’s Islamic Revolutionary Guard Corps, exploited poorly protected internet-connected controllers in 2023. These events highlight the ongoing cybersecurity challenges in protecting critical infrastructure.

Leave a Reply

Your email address will not be published.