Coordinated cyberattack hits 30+ Minnesota water systems
A coordinated cyberattack disrupted automated controls and cellular links at Minnesota water systems on July 26 and 27, 2026. Minnesota IT Services later said more than 40 communities reported impacts, but all resolved the problems quickly and no drinking water was unsafe. By late August, CISA said more than 100 internet-exposed U.S. water and wastewater systems across roughly a dozen states had been targeted during July, and the Iran-linked group CyberAv3ngers publicly claimed responsibility. No U.S. agency has publicly attributed the campaign on the record. In early September, NBC News reported that Iranian-affiliated hackers have continued probing U.S. water, energy, telecommunications, and government systems, though the recent attempts have not succeeded.
- Started
- Jul 26, 2026
- Latest activity
- Sep 3, 2026
- Attributed to
- Iran (state-linked), CyberAv3ngers / APT IRAN (group claimed responsibility)Likely
- Where
- United States
- Sectors
- Water, Government
- Scale
- CISA's guidance, revised August 21 and reported August 26
Current status
On September 3, reporting said Iranian-affiliated groups were still probing U.S. infrastructure, but recent attempts had been unsuccessful.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
CyberAv3ngers and APT IRAN claimed responsibility, but no U.S. agency has publicly confirmed the attribution.
Impact
Attackers disrupted control equipment at more than 30 Minnesota water utilities, cutting cellular links used for remote monitoring and interfering with automated controls. Braham crews took its treatment plant offline after a pump stopped working, then restored flow under manual control within hours. Maple Plain briefly declared a state of emergency. Some utilities in other states lost remote control and switched to manual operations. Clayton County Water Authority experienced a pressure drop and issued a boil-water advisory but restored service within hours. Columbus Water Works in Georgia detected and contained an attack from July 27 with no impact on water quality. Cape May and Woodbine, New Jersey confirmed attacks with no reported water-safety impact.
What to do
Readers do not need to act unless their utility issues an advisory. Water utility operators should disconnect control equipment from the internet where possible, route needed remote access through a firewall, secure gateway, or VPN, change default passwords, install available updates, and prepare to use manual controls. Texas utilities can also seek free help through the new Project Watershed 250 program launched by the state and federal government in late August.
Timeline
-
Sep 3, 2026
Reporting citing NBC News said Iranian-affiliated groups continued probing U.S. water, energy, telecommunications, and government systems, but recent attempts had been unsuccessful.
Containedyahoo.com -
Sep 3, 2026
Reporting on the NBC News findings said CISA, the FBI, EPA, and DOE have jointly warned that the intrusions have resulted in operational disruption and financial loss across affected sectors, while noting no formal government attribution has been made.
Containedyahoo.com -
Sep 2, 2026
NBC News reported that Iranian-affiliated hackers have continued probing U.S. water, energy, telecommunications, and government systems in a campaign that accelerated through mid-2026, though the recent attempts have not succeeded; a Telegram channel calling itself APT IRAN separately threatened further attacks on U.S. water, energy, and telecom targets.
Containednbcnews.com -
Aug 31, 2026
Texas and the federal government launched Project Watershed 250 to provide participating Texas water utilities with free cybersecurity support.
Activegov.texas.gov -
Aug 31, 2026
Cybersecurity experts said the water-sector intrusions relied on scale rather than sophisticated techniques and that the responsible threat actor remained officially unnamed; separately, Texas and the White House launched Project Watershed 250 to give water utilities free cyber defense help.
Containedgovtech.com -
Aug 26, 2026
CISA reporting put the number of U.S. water and wastewater systems targeted during July at more than 100 across roughly a dozen states.
Activetechcrunch.com -
Aug 26, 2026
CISA said it observed malicious cyber activity in July targeting more than 100 internet-exposed U.S. water and wastewater systems, most commonly via PLCs connected to cellular modems.
Containedsecurityweek.com -
Aug 26, 2026
Reuters reported the FBI is investigating a data breach at a small Kansas company that builds water-system control technology, noting the company was apparently not part of the Iran-linked campaign against Minnesota and other states that began in July.
Containednypost.com -
Aug 26, 2026
The Register reported CISA's national count of more than 100 targeted systems and said the federal government had not publicly attributed the campaign.
Containedtheregister.com -
Aug 26, 2026
The FBI confirmed a separate ransomware attack and data leak at Micro-Comm, a small Kansas maker of wastewater PLCs, claimed by a criminal group calling itself Barracuda; the company and the FBI said the breach was an opportunistic, financially motivated attack unrelated to the Iran-linked water-utility campaign.
Containednypost.com -
Aug 26, 2026
CISA said in an advisory that hackers had targeted more than 100 internet-exposed U.S. water and wastewater systems during July, giving the government's first broad count of the campaign's scale, while stopping short of formally attributing the attacks to Iran.
Containedtechcrunch.com -
Aug 24, 2026
Iran-linked hackers were reported to have taken a UK power plant offline for four days by targeting its programmable logic controller, in what researchers described as the same kind of attack used against U.S. water utilities.
Containedyahoo.com -
Aug 24, 2026
A separate report said Iran-linked hackers were suspected of forcing a UK power plant offline for four days, a different sector and country from the tracked water-system incidents but described as part of the same wider Iran-linked campaign.
Containedtheregister.com -
Aug 22, 2026
Local coverage in Indiana reported utilities there reviewing security in response to the FBI's water-sector PLC alert, but said no specific threats had been identified against Indiana systems; no new victim utilities were named nationally.
Containedyahoo.com -
Aug 21, 2026
CISA published updated Internet Exposure Reduction Guidance covering internet-connected IoT, SCADA, ICS, and PLC devices used across critical infrastructure sectors.
Activecisa.gov -
Aug 21, 2026
CISA revised its internet exposure guidance to say malicious activity targeted more than 100 U.S. water and wastewater organizations during July, causing lost monitoring or control and some operational disruption.
Containedcisa.gov -
Aug 20, 2026
TechCrunch reported that U.S. agencies were warning about active attempts against vulnerable Siemens equipment used by water systems and other critical infrastructure.
Activetechcrunch.com -
Aug 19, 2026
CISA, the FBI, NSA, Energy Department, and EPA warned of an active threat using AI-generated attack scripts against internet-connected Siemens S7 controllers in water and other facilities. The agencies did not name an attacker.
Containedcisa.gov -
Aug 19, 2026
Five federal agencies, including the FBI, NSA, EPA, and CISA, warned that hackers are using AI-generated exploit code against internet-exposed Siemens S7-series industrial controllers at water and energy facilities.
Activeyahoo.com -
Aug 19, 2026
CISA, the FBI, NSA, EPA, and other federal agencies issued a joint advisory warning that hackers are using AI-generated exploit code to target internet-exposed Siemens S7-series controllers used across water and energy facilities, expanding on the earlier PLC warnings.
Containedcybernews.com -
Aug 19, 2026
CISA, the FBI, NSA, the Department of Energy, and the EPA issued a joint advisory saying hackers are using AI to help write exploits for Siemens PLCs used across water, energy, manufacturing, and other critical infrastructure sectors, without formally attributing the activity to Iran.
Containedcybernews.com -
Aug 19, 2026
The NSA, CISA, and FBI issued a joint advisory warning that hackers are using AI-generated exploitation scripts to actively scan for and probe exposed Siemens S7-series PLCs across water, energy, manufacturing, and other critical infrastructure sectors.
Containedgizmodo.com -
Aug 14, 2026
MPR News reported that an Iranian-linked group had claimed direct responsibility, while no U.S. agency had publicly confirmed the claim.
Activemprnews.org -
Aug 14, 2026
A group calling itself APT IRAN claimed joint responsibility for the water-system attacks with CyberAv3ngers in a Telegram post, according to Auburn University's McCrary Institute Threat Beat, and reporting placed the total number of affected states at 12, including a first report naming Utah.
Activekstp.com -
Aug 14, 2026
The Washington Post reported, per unnamed sources, that U.S. intelligence agencies are confident Iran's Revolutionary Guard is behind the water utility attacks, though the attribution has not been made public or on the record.
Containedtechcrunch.com -
Aug 14, 2026
A group calling itself APT IRAN posted on Telegram claiming joint responsibility with CyberAv3ngers for the Minnesota water utility attack, according to Auburn University's McCrary Institute Threat Beat report.
Containedkstp.com -
Aug 13, 2026
KSTP reported that an Iran-linked hacking group claimed responsibility for the Minnesota water-system attacks.
Activekstp.com -
Aug 13, 2026
A report said a hacking group linked to Iran publicly claimed responsibility for the cyberattack on Minnesota water systems.
Activekstp.com -
Aug 13, 2026
Threat Beat, a tracker run by Auburn University's McCrary Institute, reported that the Iran-linked hacking group CyberAv3ngers had publicly claimed responsibility for the July attacks on Minnesota water systems.
Activekstp.com -
Aug 13, 2026
Minnesota IT Services said more than 40 communities had reported impacts tied to the July 26 and 27 activity. It said the investigation remained open, all communities resolved their problems quickly, and no new local issues had been reported.
Containedkstp.com -
Aug 13, 2026
Security research firm Forescout reported finding over 4,400 exposed Rockwell PLCs online, including 22 in cities that were hit by the water-system attacks, illustrating why utilities could not detect the intrusions.
Contained -
Aug 12, 2026
Threat Beat reported that APT IRAN claimed it carried out the Minnesota attacks with CyberAv3ngers. The claim did not receive public confirmation from a U.S. agency.
Containedthreatbeat.com -
Aug 12, 2026
NPR reported that Braham restored water flow under manual control within hours and that the FBI's investigation remained open. Officials said the attacks had not made drinking water unsafe.
Containednpr.org -
Aug 12, 2026
NPR examined the water-sector attacks as a possible new front in tensions with Iran, but reported no new victim utilities or operational disruptions beyond what was already known.
Containednpr.org -
Aug 10, 2026
The Washington Post reported that lawmakers were calling for stronger water-sector cybersecurity protections after incidents across 12 states, and noted a contested EPA rule that would weaken related requirements.
Containedwashingtonpost.com -
Aug 10, 2026
The Washington Post identified a water utility in western Arkansas as a victim and reported that the known campaign had reached at least 12 states.
Containedwashingtonpost.com -
Aug 10, 2026
SecurityWeek reported that Alabama had confirmed water facilities were targeted in the campaign.
Containedsecurityweek.com -
Aug 10, 2026
The Washington Post reported that a water utility in western Arkansas was attacked in late July as part of the campaign and that U.S. intelligence agencies believe Iranian regime hackers were responsible.
Activewashingtonpost.com -
Aug 10, 2026
SecurityWeek reported that Alabama had joined the states confirming water facilities were targeted in the campaign.
Activesecurityweek.com -
Aug 9, 2026
NJ.com reported that the two confirmed New Jersey water systems hit in the campaign were Cape May and Woodbine, and that officials said manual operations prevented water outages.
Activeyahoo.com -
Aug 7, 2026
Security firm Forescout reported finding more than 2,800 water-system industrial controllers exposed to the internet nationwide, underscoring the sector's lack of visibility into its own exposed equipment.
Containedtechtimes.com -
Aug 7, 2026
CNET reported that the attacks had reached at least 12 states. The public FBI and EPA alert cited in the report confirmed seven states, and no agency had publicly attributed the campaign.
Activecnet.com -
Aug 7, 2026
Follow-on reporting on the Forescout findings reiterated that federal advisories place the confirmed scope at 12 states and that no agency has formally attributed the campaign, while US intelligence officials have told NBC News they consider Iran likely responsible.
Activetechtimes.com -
Aug 7, 2026
Tech Times reported utility staff in some Minnesota cities remained on manual operations rather than automated control as researchers described the underlying visibility and exposure problems as unresolved.
Activetechtimes.com -
Aug 6, 2026
Cape May City and the Borough of Woodbine, New Jersey confirmed their water and sewer systems were hacked on July 27, forcing staff to switch to manual operations; officials said water safety and customer data were not affected.
Activenj.com -
Aug 6, 2026
News analysis explained why US water systems remain structurally vulnerable to foreign cyberattacks, without reporting any new intrusions.
Containedcnn.com -
Aug 6, 2026
Columbus Water Works said its July 27 attack was detected and contained quickly after automated monitoring systems were affected. Drinking water was never at risk.
Containedaol.com -
Aug 6, 2026
Officials told CBS News that targeted utilities had quickly regained control of their systems and that the attacks had not affected drinking water.
Containedcbsnews.com -
Aug 6, 2026
CBS News reported that water system cyberattacks had been reported in at least 12 states, citing sources familiar with the investigation.
Activeyahoo.com -
Aug 6, 2026
Forescout counted 4,407 internet-exposed Rockwell controllers worldwide and found 22 in cities hit by the water attacks. It could not confirm that any of those 22 devices were compromised.
Activethehackernews.com -
Aug 6, 2026
Follow-on reporting on the Forescout research found 4,407 internet-exposed Rockwell-family programmable logic controllers worldwide, including 22 in cities targeted by the campaign, with 86 percent of those on the same mobile carrier network and no password required to access most of them.
Activethehackernews.com -
Aug 6, 2026
Axios reported utilities nationwide, especially smaller ones, lack the staff and resources to defend against the ongoing threat, and the American Water Works Association sent Congress a letter this week urging federal cybersecurity support for the sector.
Activeaxios.com -
Aug 6, 2026
Georgia media reported Columbus Water Works and Clayton County Water Authority as the two confirmed Georgia targets, with the state's homeland security agency declining to say if other Georgia utilities were affected.
Activegovtech.com -
Aug 6, 2026
CBS News confirmed at least 12 states have now reported water-system cyberattacks possibly linked to Iran, with most states still not publicly named.
Activemsn.com -
Aug 5, 2026
Columbus Water Works in Georgia disclosed a cyberattack detected on July 27 that was quickly contained; officials said drinking water quality was never affected.
Activewrbl.com -
Aug 5, 2026
CBS News reported that water and wastewater systems in at least 12 states had been targeted. Officials said drinking water remained safe.
Activecbsnews.com -
Aug 5, 2026
Columbus Water Works said attackers targeted its systems on July 27. The utility switched to manual operations, contained the incident, and said water quality remained safe.
Activemsn.com -
Aug 5, 2026
Columbus Water Works disclosed that attackers targeted it on July 27. The utility said it detected and contained the attack quickly and that water quality was safe.
Activeledger-enquirer.com -
Aug 5, 2026
Forescout's Vedere Labs published research on water utilities in cities hit by the campaign, finding forgotten and unpatched internet-facing servers alongside the targeted industrial controllers, days after federal officials confirmed the campaign had reached at least 12 states.
Activetechtimes.com -
Aug 5, 2026
Columbus Water Works in Georgia disclosed it was hit by a cyberattack on July 27; local officials said the incident was detected and contained quickly and that water quality was never at risk.
Activeyahoo.com -
Aug 5, 2026
New Jersey officials said manual operations at its two affected municipal water systems prevented any water outage.
Activeoann.com -
Aug 5, 2026
Forescout's Vedere Labs published research finding roughly 4,400 internet-exposed Rockwell-protocol industrial controllers worldwide, including forgotten or misconfigured servers and certificates in cities hit by the campaign, and said the attack pattern looked more like mass opportunistic scanning than a targeted intrusion.
Activeforescout.com -
Aug 5, 2026
Forescout's Vedere Labs published a scan of 4,407 internet-exposed industrial controllers worldwide and found that some affected utilities had incomplete inventories of their own exposed equipment, including expired certificates and forgotten remote-access hostnames.
Activeforescout.com -
Aug 5, 2026
Columbus Water Works and Georgia officials said the cyberattack there was quickly detected and contained and water quality remained safe, while GEMA declined to say whether other Georgia cities were affected.
Activeyahoo.com -
Aug 5, 2026
Columbus Water Works in Georgia publicly disclosed it was hit by a cyberattack on July 27 that was quickly detected and contained; officials said drinking water was never at risk.
Activewrbl.com -
Aug 5, 2026
Wisconsin water utilities said they had not been affected despite being named in some reporting, and New York announced more than $9 million in grants to help 153 water systems improve cybersecurity in the wake of the campaign.
Activesecurityweek.com -
Aug 5, 2026
Security press reported that at least 12 states have now been hit by the water sector cyberattacks, citing ABC News, though only a handful of the affected states have been officially named.
Activesecurityweek.com -
Aug 4, 2026
Press reports said the water utility cyberattacks had been reported in at least 12 states, with Iran named as the leading suspect.
Activetechtimes.com -
Aug 4, 2026
Cybersecurity firm Tenable told the New York Post that the Iran-linked group Cyberav3ngers is the likely culprit, saying it tracked the group discussing plans to target US water infrastructure on the dark web since April 2026, and warned the campaign may not be finished because the group typically claims credit only after an operation ends.
Activenypost.com -
Aug 4, 2026
ABC News reported that hackers had targeted water and wastewater utilities in at least 12 states, up from the seven states named in the FBI's initial advisory.
Activeaxios.com -
Aug 4, 2026
ABC News and Axios reported the confirmed count of affected states had reached at least 12, describing it as the broadest known coordinated campaign against U.S. municipal water infrastructure.
Activeaxios.com -
Aug 4, 2026
A report put Minnesota's confirmed affected water utility count at 36, up from the 'more than 30' figure cited in earlier reporting.
Activecpomagazine.com -
Aug 4, 2026
Baltimore's Department of Public Works said it is monitoring its water infrastructure security as a precaution following the national wave of attacks, but has not reported any intrusion into its own systems.
Activebaltimoresun.com -
Aug 4, 2026
Reporting said Georgia now has at least two confirmed water-system incidents tied to the campaign, moving past the earlier 'possibly linked' characterization of the Clayton County outage.
Activemsn.com -
Aug 4, 2026
Officials said the number of states reporting cyberattacks on their water systems has grown to at least 12, up from the seven states first cited in the FBI and EPA alert.
Activemsn.com -
Aug 4, 2026
Clayton County, Georgia, in metro Atlanta, said it experienced a temporary water service disruption the prior week that could be part of the same wave of cyberattacks, though neither Georgia nor federal officials confirmed the link.
Activeajc.com -
Aug 4, 2026
New Jersey officials confirmed at least two affected utilities. Both temporarily lost some remote monitoring or control, switched to manual operations, and maintained safe water service without interruption.
Activenbcphiladelphia.com -
Aug 4, 2026
ABC News reported possible intrusions at water and wastewater utilities in at least 12 states. Its sources said Iran was the prime suspect, but the government had not confirmed that attribution and no widespread disruption was reported.
Activeabcnews.com -
Aug 4, 2026
Clayton County, Georgia disclosed that a July 27 cyberattack caused a water service disruption lasting a few hours, but state and federal officials had not confirmed that it was part of the wider campaign.
Activeajc.com -
Aug 4, 2026
Federal authorities confirmed at least two water system incidents in Georgia, not just the one previously reported in Clayton County, as part of the same multistate cyberattack wave.
Activemsn.com -
Aug 4, 2026
Reporting confirmed at least two New Jersey water systems, not just one, were targeted in the cyberattack affecting utilities across at least seven states.
Activemsn.com -
Aug 4, 2026
Clayton County, Georgia, near Atlanta, disclosed it experienced a temporary water service disruption the prior week that could be part of the same suspected cyberattack campaign; neither Georgia nor federal officials had confirmed it was among the targets.
Activeajc.com -
Aug 3, 2026
New York state announced $9 million in funding to help local water systems improve cybersecurity following the wave of attacks reported in other states.
Activegothamist.com -
Aug 3, 2026
CISA, the FBI, and partner agencies updated their joint advisory to say the attackers have expanded beyond Rockwell Automation PLCs to also target Siemens S7-1200 series and Schneider Electric Modicon M340 controllers, and warned that potentially all internet-exposed PLCs are at risk.
Activecpomagazine.com -
Aug 3, 2026
The Clayton County Water Authority in metro Atlanta said investigators now suspect the outage that hit several water pump stations was not accidental and was likely part of the broader national cyber campaign.
Activemsn.com -
Aug 3, 2026
New Jersey's Office of Homeland Security confirmed at least two state water systems were hit by cyberattacks similar to those reported in other states.
Activenj.com -
Aug 3, 2026
New Jersey confirmed its water systems were also hit by the same wave of cyberattacks targeting utilities nationwide.
Activenj.com -
Aug 3, 2026
The Register reported the cyberattacks had spread to Georgia and Michigan, with Iran-linked hackers the leading suspects, though the FBI still had not made a public attribution.
Activetheregister.com -
Aug 3, 2026
A New Jersey water system reported being hit by the same wave of cyberattacks affecting utilities nationwide, according to NJ.com, which also noted CISA's warning about a sharp rise in attacks on internet-exposed PLCs in the water sector.
Activenj.com -
Aug 2, 2026
Rapid City, South Dakota said one of its wastewater lift stations was targeted; the city isolated the affected systems and said drinking water safety was not affected.
Activenewsweek.com -
Aug 2, 2026
Michigan's environment agency confirmed hackers altered settings on equipment at a wastewater facility; officials said the incident was contained and posed no threat to drinking water.
Activenewsweek.com -
Aug 2, 2026
Newsweek reported that federal investigators are also examining whether a different actor deliberately copied Iranian hacking tactics to mislead investigators, alongside the ongoing Iran theory.
Activenewsweek.com -
Aug 1, 2026
Michigan reported that a total of nine water systems in the state had been targeted by the cyberattacks, though officials said there were no public health impacts.
Activeyahoo.com -
Aug 1, 2026
New reporting from CBS News and the New York Times said U.S. investigators, including unnamed intelligence-agency assessments, continue to view Iran-linked hackers as the likely source even though no agency has made a formal on-the-record attribution.
Activenytimes.com -
Aug 1, 2026
The FBI issued a statement saying it is aware of the public reporting and is fully engaged with interagency partners, but again declined to publicly name a responsible party.
Activedakotanewsnow.com -
Aug 1, 2026
Michigan became the second state to publicly confirm incidents, reporting activity consistent with the federal alert at nine water systems; officials said all systems continued operating safely with no known public health impact.
Activedakotanewsnow.com -
Aug 1, 2026
Michigan publicly joined Minnesota in reporting cyberattacks on water systems, disclosing that nine of its water systems were targeted; officials said the systems continued operating safely with no known health impact, and the FBI is investigating.
Activedakotanewsnow.com -
Aug 1, 2026
A cybersecurity expert told the Jewish News Syndicate the Iran-linked campaign likely extends beyond the confirmed states, noting it was unusual that Iran had not claimed credit for the attacks.
Activenypost.com -
Jul 31, 2026
Officials said investigators are also examining whether the attackers tried to make the activity appear Iranian in origin, a possible false-flag operation, with assessments described as preliminary.
Activenewsweek.com -
Jul 31, 2026
President Trump publicly rejected the Iran attribution and blamed Minnesota officials, while Minnesota IT Services said the state has not formally attributed the attacks to any specific actor and the investigation remains active.
Activenewsweek.com -
Jul 31, 2026
Federal officials said they were continuing to engage with victim utilities as more states reported similar intrusions.
Activeaol.com -
Jul 31, 2026
President Trump publicly disputed the Iran attribution during a Cabinet meeting, blaming Minnesota state government's handling of the incident instead, while Minnesota's governor and outside cybersecurity researchers said the evidence still points to Iran.
Activegizmodo.com -
Jul 31, 2026
A Minnesota law enforcement memo said the hackers appeared to be trying to contaminate drinking water by manipulating controllers to drop pipe pressure, though officials maintained no actual contamination occurred.
Activetechtimes.com -
Jul 31, 2026
The FBI and EPA issued a joint public warning saying water and wastewater utilities in at least seven states, not just Minnesota, had reported cyberattacks this week involving internet-facing industrial controllers.
Activegovtech.com -
Jul 31, 2026
A leaked WaterISAC memo citing the Minnesota Fusion Center said the attacks were consistent with an Iran-linked PLC-targeting campaign CISA had already warned about in April, becoming the first official-style document tying the Minnesota incidents to Iran, though CISA itself has not formally attributed the attack.
Activeibtimes.com -
Jul 31, 2026
President Trump publicly rejected the Iran attribution at a Cabinet meeting, blaming Minnesota state officials and Gov. Tim Walz for the attack instead; fact-checkers said his claim was not supported by evidence.
Activestartribune.com -
Jul 31, 2026
A Minnesota law enforcement memo said the attackers appeared to be trying to contaminate drinking water by manipulating pipe pressure; some victims reported flooding or loss of water pressure.
Activemsn.com -
Jul 31, 2026
The FBI and EPA warned that cyberattacks had hit water utility providers in at least seven states total, not just Minnesota, and urged utilities nationwide to disconnect internet-exposed industrial control systems.
Activemsn.com -
Jul 31, 2026
U.S. officials said a preliminary intelligence assessment points to Iran as the likely source, while stressing no water supply was found to be unsafe; CISA issued a fresh warning to water utilities nationwide.
Activenytimes.com -
Jul 30, 2026
A leaked WaterISAC memo cited a Minnesota Fusion Center assessment tying a wave of attacks on more than 30 Minnesota water systems to Iran-affiliated hackers.
Activewired.com -
Jul 30, 2026
The FBI and EPA issued a joint public service announcement confirming incidents in at least seven states, including loss of pressure and flooding at some sites.
Activeic3.gov -
Jul 30, 2026
A leaked WaterISAC memo cited a Minnesota Fusion Center finding linking the attacks to Iran, aligned with an updated CISA advisory on Iran-affiliated hackers targeting water sector PLCs.
Activewired.com -
Jul 30, 2026
A leaked WaterISAC memo obtained by Wired tied the Minnesota water utility attacks to Iran.
Activewired.com -
Jul 29, 2026
Reporting detailed that at least one treatment plant went offline and cellular links used for remote monitoring were disrupted; Tenable researchers said the Iran-linked group CyberAv3ngers was suspected.
Activetheregister.com -
Jul 28, 2026
Minnesota state IT officials publicly disclosed the coordinated cyberattack, saying more than 30 community water systems were targeted.
Activereuters.com -
Jul 28, 2026
Minnesota IT Services publicly disclosed the coordinated cyberattack, saying operations at some facilities were affected and the state was assisting impacted cities.
Activereuters.com -
Jul 27, 2026
Hackers began breaching internet-facing Rockwell Automation MicroLogix PLCs at water utilities, the first date cited in the FBI and EPA alert.
Emergingic3.gov -
Jul 26, 2026
Hackers began a coordinated attack on remotely accessible industrial controllers at Minnesota water and wastewater utilities.
Emergingreuters.com -
Jul 26, 2026
A coordinated cyberattack began hitting automated controls at more than 30 community water systems across Minnesota.
Activereuters.com -
Jul 22, 2026
CISA, the FBI, NSA, and the Department of Energy updated a joint advisory warning that Iran-linked actors were inside water and energy control systems and altering operator screens.
Activesecurityaffairs.com -
Jul 19, 2026
Security press reported an ongoing campaign by Iran-linked actors exploiting internet-exposed PLCs across U.S. water, energy, and government facilities since at least March 2026.
Emergingcybersecuritynews.com
Sources
- Minnesota IT officials disclose 'coordinated cyberattack' at more than 30 local water systems Reuters Jul 28, 2026 unverified
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline The Hacker News Jul 29, 2026
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems The Register Jul 29, 2026
- A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran Wired Jul 30, 2026
- U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems New York Times Jul 30, 2026 unverified
- Iran-linked attackers disrupting US water and energy systems SecurityAffairs Jul 25, 2026
- Iranian attackers disable US safety alarms in industrial systems Cyber Security News Jul 27, 2026
- Hackers targeted municipal water systems in 7 states this week, FBI says MSN (from AP) Jul 31, 2026
- FBI: Water hacks in seven states aimed at contaminating drinking supplies MSN Jul 31, 2026
- Trump blames 'incompetent' Minnesota, not Iran, for water system cyberattacks Star Tribune Jul 31, 2026 unverified
- Fact check: Trump baselessly claims Walz is 'behind' cyberattack, repeats debunked claims at Cabinet meeting CNN Jul 31, 2026
- CISA urges water utilities to take exposed systems down after Minnesota hacks Nextgov/FCW Jul 31, 2026
- Iranian hackers likely behind Minnesota water system attacks, but it's 'surprising' country hasn't taken credit, expert says New York Post Aug 1, 2026
- Michigan joins Minnesota in reporting cyberattacks on water systems; FBI investigating Dakota News Now (AP) Aug 1, 2026
- Hackers target Michigan water systems Detroit News Aug 2, 2026
- Michigan reports cyberattacks on water systems, FBI investigates mlive Aug 2, 2026 unverified
- Map shows states hit by cyberattacks on water systems Newsweek (via MSN) Aug 2, 2026
- Will The Cyberattacks On Water Systems In 7 States Be A Wakeup Call? Forbes Aug 1, 2026
- Georgia, Michigan say water systems hacked by Iran-tied crew The Register Aug 3, 2026
- N.J. water systems also hit by hackers in cyberattacks targeting utilities nationwide NJ.com Aug 3, 2026 unverified
- Metro Atlanta water system hit by cyberattack possibly linked to Iran Atlanta Journal-Constitution Aug 4, 2026
- Cyber attack on water systems is impacting West Michigan, FBI confirms WZZM13 via MSN Aug 3, 2026
- Scope of Hacks on U.S. Water Supply Widens as Evidence Points to Iran The New York Times Aug 1, 2026 unverified
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs CISA Jul 30, 2026
Related reports
- Minnesota water systems hit by ransomware Jul 31, 2026
- Minnesota water systems hit by PLC cyberattacks Jul 29, 2026
- Iran-linked attackers disable industrial safety alarms Jul 27, 2026
- Iran-linked attackers disrupt U.S. water, energy, and government systems Jul 19, 2026
- Minnesota water systems hit by cyberattack Jul 12, 2026
- Nation-states breach US water utilities via weak passwords Jun 17, 2026