Contained High impact Industrial control systems Checked 1d ago

Coordinated cyberattack hits 30+ Minnesota water systems

A coordinated cyberattack disrupted automated controls and cellular links at Minnesota water systems on July 26 and 27, 2026. Minnesota IT Services later said more than 40 communities reported impacts, but all resolved the problems quickly and no drinking water was unsafe. By late August, CISA said more than 100 internet-exposed U.S. water and wastewater systems across roughly a dozen states had been targeted during July, and the Iran-linked group CyberAv3ngers publicly claimed responsibility. No U.S. agency has publicly attributed the campaign on the record. In early September, NBC News reported that Iranian-affiliated hackers have continued probing U.S. water, energy, telecommunications, and government systems, though the recent attempts have not succeeded.

Started
Jul 26, 2026
Latest activity
Sep 3, 2026
Attributed to
Iran (state-linked), CyberAv3ngers / APT IRAN (group claimed responsibility)Likely
Where
United States
Sectors
Water, Government
Scale
CISA's guidance, revised August 21 and reported August 26

Current status

On September 3, reporting said Iranian-affiliated groups were still probing U.S. infrastructure, but recent attempts had been unsuccessful.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

CyberAv3ngers and APT IRAN claimed responsibility, but no U.S. agency has publicly confirmed the attribution.

Impact

Attackers disrupted control equipment at more than 30 Minnesota water utilities, cutting cellular links used for remote monitoring and interfering with automated controls. Braham crews took its treatment plant offline after a pump stopped working, then restored flow under manual control within hours. Maple Plain briefly declared a state of emergency. Some utilities in other states lost remote control and switched to manual operations. Clayton County Water Authority experienced a pressure drop and issued a boil-water advisory but restored service within hours. Columbus Water Works in Georgia detected and contained an attack from July 27 with no impact on water quality. Cape May and Woodbine, New Jersey confirmed attacks with no reported water-safety impact.

What to do

Readers do not need to act unless their utility issues an advisory. Water utility operators should disconnect control equipment from the internet where possible, route needed remote access through a firewall, secure gateway, or VPN, change default passwords, install available updates, and prepare to use manual controls. Texas utilities can also seek free help through the new Project Watershed 250 program launched by the state and federal government in late August.

Timeline

  1. Sep 3, 2026

    Reporting citing NBC News said Iranian-affiliated groups continued probing U.S. water, energy, telecommunications, and government systems, but recent attempts had been unsuccessful.

    Containedyahoo.com
  2. Sep 3, 2026

    Reporting on the NBC News findings said CISA, the FBI, EPA, and DOE have jointly warned that the intrusions have resulted in operational disruption and financial loss across affected sectors, while noting no formal government attribution has been made.

    Containedyahoo.com
  3. Sep 2, 2026

    NBC News reported that Iranian-affiliated hackers have continued probing U.S. water, energy, telecommunications, and government systems in a campaign that accelerated through mid-2026, though the recent attempts have not succeeded; a Telegram channel calling itself APT IRAN separately threatened further attacks on U.S. water, energy, and telecom targets.

    Containednbcnews.com
  4. Aug 31, 2026

    Texas and the federal government launched Project Watershed 250 to provide participating Texas water utilities with free cybersecurity support.

    Activegov.texas.gov
  5. Aug 31, 2026

    Cybersecurity experts said the water-sector intrusions relied on scale rather than sophisticated techniques and that the responsible threat actor remained officially unnamed; separately, Texas and the White House launched Project Watershed 250 to give water utilities free cyber defense help.

    Containedgovtech.com
  6. Aug 26, 2026

    CISA reporting put the number of U.S. water and wastewater systems targeted during July at more than 100 across roughly a dozen states.

    Activetechcrunch.com
  7. Aug 26, 2026

    CISA said it observed malicious cyber activity in July targeting more than 100 internet-exposed U.S. water and wastewater systems, most commonly via PLCs connected to cellular modems.

    Containedsecurityweek.com
  8. Aug 26, 2026

    Reuters reported the FBI is investigating a data breach at a small Kansas company that builds water-system control technology, noting the company was apparently not part of the Iran-linked campaign against Minnesota and other states that began in July.

    Containednypost.com
  9. Aug 26, 2026

    The Register reported CISA's national count of more than 100 targeted systems and said the federal government had not publicly attributed the campaign.

    Containedtheregister.com
  10. Aug 26, 2026

    The FBI confirmed a separate ransomware attack and data leak at Micro-Comm, a small Kansas maker of wastewater PLCs, claimed by a criminal group calling itself Barracuda; the company and the FBI said the breach was an opportunistic, financially motivated attack unrelated to the Iran-linked water-utility campaign.

    Containednypost.com
  11. Aug 26, 2026

    CISA said in an advisory that hackers had targeted more than 100 internet-exposed U.S. water and wastewater systems during July, giving the government's first broad count of the campaign's scale, while stopping short of formally attributing the attacks to Iran.

    Containedtechcrunch.com
  12. Aug 24, 2026

    Iran-linked hackers were reported to have taken a UK power plant offline for four days by targeting its programmable logic controller, in what researchers described as the same kind of attack used against U.S. water utilities.

    Containedyahoo.com
  13. Aug 24, 2026

    A separate report said Iran-linked hackers were suspected of forcing a UK power plant offline for four days, a different sector and country from the tracked water-system incidents but described as part of the same wider Iran-linked campaign.

    Containedtheregister.com
  14. Aug 22, 2026

    Local coverage in Indiana reported utilities there reviewing security in response to the FBI's water-sector PLC alert, but said no specific threats had been identified against Indiana systems; no new victim utilities were named nationally.

    Containedyahoo.com
  15. Aug 21, 2026

    CISA published updated Internet Exposure Reduction Guidance covering internet-connected IoT, SCADA, ICS, and PLC devices used across critical infrastructure sectors.

    Activecisa.gov
  16. Aug 21, 2026

    CISA revised its internet exposure guidance to say malicious activity targeted more than 100 U.S. water and wastewater organizations during July, causing lost monitoring or control and some operational disruption.

    Containedcisa.gov
  17. Aug 20, 2026

    TechCrunch reported that U.S. agencies were warning about active attempts against vulnerable Siemens equipment used by water systems and other critical infrastructure.

    Activetechcrunch.com
  18. Aug 19, 2026

    CISA, the FBI, NSA, Energy Department, and EPA warned of an active threat using AI-generated attack scripts against internet-connected Siemens S7 controllers in water and other facilities. The agencies did not name an attacker.

    Containedcisa.gov
  19. Aug 19, 2026

    Five federal agencies, including the FBI, NSA, EPA, and CISA, warned that hackers are using AI-generated exploit code against internet-exposed Siemens S7-series industrial controllers at water and energy facilities.

    Activeyahoo.com
  20. Aug 19, 2026

    CISA, the FBI, NSA, EPA, and other federal agencies issued a joint advisory warning that hackers are using AI-generated exploit code to target internet-exposed Siemens S7-series controllers used across water and energy facilities, expanding on the earlier PLC warnings.

    Containedcybernews.com
  21. Aug 19, 2026

    CISA, the FBI, NSA, the Department of Energy, and the EPA issued a joint advisory saying hackers are using AI to help write exploits for Siemens PLCs used across water, energy, manufacturing, and other critical infrastructure sectors, without formally attributing the activity to Iran.

    Containedcybernews.com
  22. Aug 19, 2026

    The NSA, CISA, and FBI issued a joint advisory warning that hackers are using AI-generated exploitation scripts to actively scan for and probe exposed Siemens S7-series PLCs across water, energy, manufacturing, and other critical infrastructure sectors.

    Containedgizmodo.com
  23. Aug 14, 2026

    MPR News reported that an Iranian-linked group had claimed direct responsibility, while no U.S. agency had publicly confirmed the claim.

    Activemprnews.org
  24. Aug 14, 2026

    A group calling itself APT IRAN claimed joint responsibility for the water-system attacks with CyberAv3ngers in a Telegram post, according to Auburn University's McCrary Institute Threat Beat, and reporting placed the total number of affected states at 12, including a first report naming Utah.

    Activekstp.com
  25. Aug 14, 2026

    The Washington Post reported, per unnamed sources, that U.S. intelligence agencies are confident Iran's Revolutionary Guard is behind the water utility attacks, though the attribution has not been made public or on the record.

    Containedtechcrunch.com
  26. Aug 14, 2026

    A group calling itself APT IRAN posted on Telegram claiming joint responsibility with CyberAv3ngers for the Minnesota water utility attack, according to Auburn University's McCrary Institute Threat Beat report.

    Containedkstp.com
  27. Aug 13, 2026

    KSTP reported that an Iran-linked hacking group claimed responsibility for the Minnesota water-system attacks.

    Activekstp.com
  28. Aug 13, 2026

    A report said a hacking group linked to Iran publicly claimed responsibility for the cyberattack on Minnesota water systems.

    Activekstp.com
  29. Aug 13, 2026

    Threat Beat, a tracker run by Auburn University's McCrary Institute, reported that the Iran-linked hacking group CyberAv3ngers had publicly claimed responsibility for the July attacks on Minnesota water systems.

    Activekstp.com
  30. Aug 13, 2026

    Minnesota IT Services said more than 40 communities had reported impacts tied to the July 26 and 27 activity. It said the investigation remained open, all communities resolved their problems quickly, and no new local issues had been reported.

    Containedkstp.com
  31. Aug 13, 2026

    Security research firm Forescout reported finding over 4,400 exposed Rockwell PLCs online, including 22 in cities that were hit by the water-system attacks, illustrating why utilities could not detect the intrusions.

    Contained
  32. Aug 12, 2026

    Threat Beat reported that APT IRAN claimed it carried out the Minnesota attacks with CyberAv3ngers. The claim did not receive public confirmation from a U.S. agency.

    Containedthreatbeat.com
  33. Aug 12, 2026

    NPR reported that Braham restored water flow under manual control within hours and that the FBI's investigation remained open. Officials said the attacks had not made drinking water unsafe.

    Containednpr.org
  34. Aug 12, 2026

    NPR examined the water-sector attacks as a possible new front in tensions with Iran, but reported no new victim utilities or operational disruptions beyond what was already known.

    Containednpr.org
  35. Aug 10, 2026

    The Washington Post reported that lawmakers were calling for stronger water-sector cybersecurity protections after incidents across 12 states, and noted a contested EPA rule that would weaken related requirements.

    Containedwashingtonpost.com
  36. Aug 10, 2026

    The Washington Post identified a water utility in western Arkansas as a victim and reported that the known campaign had reached at least 12 states.

    Containedwashingtonpost.com
  37. Aug 10, 2026

    SecurityWeek reported that Alabama had confirmed water facilities were targeted in the campaign.

    Containedsecurityweek.com
  38. Aug 10, 2026

    The Washington Post reported that a water utility in western Arkansas was attacked in late July as part of the campaign and that U.S. intelligence agencies believe Iranian regime hackers were responsible.

    Activewashingtonpost.com
  39. Aug 10, 2026

    SecurityWeek reported that Alabama had joined the states confirming water facilities were targeted in the campaign.

    Activesecurityweek.com
  40. Aug 9, 2026

    NJ.com reported that the two confirmed New Jersey water systems hit in the campaign were Cape May and Woodbine, and that officials said manual operations prevented water outages.

    Activeyahoo.com
  41. Aug 7, 2026

    Security firm Forescout reported finding more than 2,800 water-system industrial controllers exposed to the internet nationwide, underscoring the sector's lack of visibility into its own exposed equipment.

    Containedtechtimes.com
  42. Aug 7, 2026

    CNET reported that the attacks had reached at least 12 states. The public FBI and EPA alert cited in the report confirmed seven states, and no agency had publicly attributed the campaign.

    Activecnet.com
  43. Aug 7, 2026

    Follow-on reporting on the Forescout findings reiterated that federal advisories place the confirmed scope at 12 states and that no agency has formally attributed the campaign, while US intelligence officials have told NBC News they consider Iran likely responsible.

    Activetechtimes.com
  44. Aug 7, 2026

    Tech Times reported utility staff in some Minnesota cities remained on manual operations rather than automated control as researchers described the underlying visibility and exposure problems as unresolved.

    Activetechtimes.com
  45. Aug 6, 2026

    Cape May City and the Borough of Woodbine, New Jersey confirmed their water and sewer systems were hacked on July 27, forcing staff to switch to manual operations; officials said water safety and customer data were not affected.

    Activenj.com
  46. Aug 6, 2026

    News analysis explained why US water systems remain structurally vulnerable to foreign cyberattacks, without reporting any new intrusions.

    Containedcnn.com
  47. Aug 6, 2026

    Columbus Water Works said its July 27 attack was detected and contained quickly after automated monitoring systems were affected. Drinking water was never at risk.

    Containedaol.com
  48. Aug 6, 2026

    Officials told CBS News that targeted utilities had quickly regained control of their systems and that the attacks had not affected drinking water.

    Containedcbsnews.com
  49. Aug 6, 2026

    CBS News reported that water system cyberattacks had been reported in at least 12 states, citing sources familiar with the investigation.

    Activeyahoo.com
  50. Aug 6, 2026

    Forescout counted 4,407 internet-exposed Rockwell controllers worldwide and found 22 in cities hit by the water attacks. It could not confirm that any of those 22 devices were compromised.

    Activethehackernews.com
  51. Aug 6, 2026

    Follow-on reporting on the Forescout research found 4,407 internet-exposed Rockwell-family programmable logic controllers worldwide, including 22 in cities targeted by the campaign, with 86 percent of those on the same mobile carrier network and no password required to access most of them.

    Activethehackernews.com
  52. Aug 6, 2026

    Axios reported utilities nationwide, especially smaller ones, lack the staff and resources to defend against the ongoing threat, and the American Water Works Association sent Congress a letter this week urging federal cybersecurity support for the sector.

    Activeaxios.com
  53. Aug 6, 2026

    Georgia media reported Columbus Water Works and Clayton County Water Authority as the two confirmed Georgia targets, with the state's homeland security agency declining to say if other Georgia utilities were affected.

    Activegovtech.com
  54. Aug 6, 2026

    CBS News confirmed at least 12 states have now reported water-system cyberattacks possibly linked to Iran, with most states still not publicly named.

    Activemsn.com
  55. Aug 5, 2026

    Columbus Water Works in Georgia disclosed a cyberattack detected on July 27 that was quickly contained; officials said drinking water quality was never affected.

    Activewrbl.com
  56. Aug 5, 2026

    CBS News reported that water and wastewater systems in at least 12 states had been targeted. Officials said drinking water remained safe.

    Activecbsnews.com
  57. Aug 5, 2026

    Columbus Water Works said attackers targeted its systems on July 27. The utility switched to manual operations, contained the incident, and said water quality remained safe.

    Activemsn.com
  58. Aug 5, 2026

    Columbus Water Works disclosed that attackers targeted it on July 27. The utility said it detected and contained the attack quickly and that water quality was safe.

    Activeledger-enquirer.com
  59. Aug 5, 2026

    Forescout's Vedere Labs published research on water utilities in cities hit by the campaign, finding forgotten and unpatched internet-facing servers alongside the targeted industrial controllers, days after federal officials confirmed the campaign had reached at least 12 states.

    Activetechtimes.com
  60. Aug 5, 2026

    Columbus Water Works in Georgia disclosed it was hit by a cyberattack on July 27; local officials said the incident was detected and contained quickly and that water quality was never at risk.

    Activeyahoo.com
  61. Aug 5, 2026

    New Jersey officials said manual operations at its two affected municipal water systems prevented any water outage.

    Activeoann.com
  62. Aug 5, 2026

    Forescout's Vedere Labs published research finding roughly 4,400 internet-exposed Rockwell-protocol industrial controllers worldwide, including forgotten or misconfigured servers and certificates in cities hit by the campaign, and said the attack pattern looked more like mass opportunistic scanning than a targeted intrusion.

    Activeforescout.com
  63. Aug 5, 2026

    Forescout's Vedere Labs published a scan of 4,407 internet-exposed industrial controllers worldwide and found that some affected utilities had incomplete inventories of their own exposed equipment, including expired certificates and forgotten remote-access hostnames.

    Activeforescout.com
  64. Aug 5, 2026

    Columbus Water Works and Georgia officials said the cyberattack there was quickly detected and contained and water quality remained safe, while GEMA declined to say whether other Georgia cities were affected.

    Activeyahoo.com
  65. Aug 5, 2026

    Columbus Water Works in Georgia publicly disclosed it was hit by a cyberattack on July 27 that was quickly detected and contained; officials said drinking water was never at risk.

    Activewrbl.com
  66. Aug 5, 2026

    Wisconsin water utilities said they had not been affected despite being named in some reporting, and New York announced more than $9 million in grants to help 153 water systems improve cybersecurity in the wake of the campaign.

    Activesecurityweek.com
  67. Aug 5, 2026

    Security press reported that at least 12 states have now been hit by the water sector cyberattacks, citing ABC News, though only a handful of the affected states have been officially named.

    Activesecurityweek.com
  68. Aug 4, 2026

    Press reports said the water utility cyberattacks had been reported in at least 12 states, with Iran named as the leading suspect.

    Activetechtimes.com
  69. Aug 4, 2026

    Cybersecurity firm Tenable told the New York Post that the Iran-linked group Cyberav3ngers is the likely culprit, saying it tracked the group discussing plans to target US water infrastructure on the dark web since April 2026, and warned the campaign may not be finished because the group typically claims credit only after an operation ends.

    Activenypost.com
  70. Aug 4, 2026

    ABC News reported that hackers had targeted water and wastewater utilities in at least 12 states, up from the seven states named in the FBI's initial advisory.

    Activeaxios.com
  71. Aug 4, 2026

    ABC News and Axios reported the confirmed count of affected states had reached at least 12, describing it as the broadest known coordinated campaign against U.S. municipal water infrastructure.

    Activeaxios.com
  72. Aug 4, 2026

    A report put Minnesota's confirmed affected water utility count at 36, up from the 'more than 30' figure cited in earlier reporting.

    Activecpomagazine.com
  73. Aug 4, 2026

    Baltimore's Department of Public Works said it is monitoring its water infrastructure security as a precaution following the national wave of attacks, but has not reported any intrusion into its own systems.

    Activebaltimoresun.com
  74. Aug 4, 2026

    Reporting said Georgia now has at least two confirmed water-system incidents tied to the campaign, moving past the earlier 'possibly linked' characterization of the Clayton County outage.

    Activemsn.com
  75. Aug 4, 2026

    Officials said the number of states reporting cyberattacks on their water systems has grown to at least 12, up from the seven states first cited in the FBI and EPA alert.

    Activemsn.com
  76. Aug 4, 2026

    Clayton County, Georgia, in metro Atlanta, said it experienced a temporary water service disruption the prior week that could be part of the same wave of cyberattacks, though neither Georgia nor federal officials confirmed the link.

    Activeajc.com
  77. Aug 4, 2026

    New Jersey officials confirmed at least two affected utilities. Both temporarily lost some remote monitoring or control, switched to manual operations, and maintained safe water service without interruption.

    Activenbcphiladelphia.com
  78. Aug 4, 2026

    ABC News reported possible intrusions at water and wastewater utilities in at least 12 states. Its sources said Iran was the prime suspect, but the government had not confirmed that attribution and no widespread disruption was reported.

    Activeabcnews.com
  79. Aug 4, 2026

    Clayton County, Georgia disclosed that a July 27 cyberattack caused a water service disruption lasting a few hours, but state and federal officials had not confirmed that it was part of the wider campaign.

    Activeajc.com
  80. Aug 4, 2026

    Federal authorities confirmed at least two water system incidents in Georgia, not just the one previously reported in Clayton County, as part of the same multistate cyberattack wave.

    Activemsn.com
  81. Aug 4, 2026

    Reporting confirmed at least two New Jersey water systems, not just one, were targeted in the cyberattack affecting utilities across at least seven states.

    Activemsn.com
  82. Aug 4, 2026

    Clayton County, Georgia, near Atlanta, disclosed it experienced a temporary water service disruption the prior week that could be part of the same suspected cyberattack campaign; neither Georgia nor federal officials had confirmed it was among the targets.

    Activeajc.com
  83. Aug 3, 2026

    New York state announced $9 million in funding to help local water systems improve cybersecurity following the wave of attacks reported in other states.

    Activegothamist.com
  84. Aug 3, 2026

    CISA, the FBI, and partner agencies updated their joint advisory to say the attackers have expanded beyond Rockwell Automation PLCs to also target Siemens S7-1200 series and Schneider Electric Modicon M340 controllers, and warned that potentially all internet-exposed PLCs are at risk.

    Activecpomagazine.com
  85. Aug 3, 2026

    The Clayton County Water Authority in metro Atlanta said investigators now suspect the outage that hit several water pump stations was not accidental and was likely part of the broader national cyber campaign.

    Activemsn.com
  86. Aug 3, 2026

    New Jersey's Office of Homeland Security confirmed at least two state water systems were hit by cyberattacks similar to those reported in other states.

    Activenj.com
  87. Aug 3, 2026

    New Jersey confirmed its water systems were also hit by the same wave of cyberattacks targeting utilities nationwide.

    Activenj.com
  88. Aug 3, 2026

    The Register reported the cyberattacks had spread to Georgia and Michigan, with Iran-linked hackers the leading suspects, though the FBI still had not made a public attribution.

    Activetheregister.com
  89. Aug 3, 2026

    A New Jersey water system reported being hit by the same wave of cyberattacks affecting utilities nationwide, according to NJ.com, which also noted CISA's warning about a sharp rise in attacks on internet-exposed PLCs in the water sector.

    Activenj.com
  90. Aug 2, 2026

    Rapid City, South Dakota said one of its wastewater lift stations was targeted; the city isolated the affected systems and said drinking water safety was not affected.

    Activenewsweek.com
  91. Aug 2, 2026

    Michigan's environment agency confirmed hackers altered settings on equipment at a wastewater facility; officials said the incident was contained and posed no threat to drinking water.

    Activenewsweek.com
  92. Aug 2, 2026

    Newsweek reported that federal investigators are also examining whether a different actor deliberately copied Iranian hacking tactics to mislead investigators, alongside the ongoing Iran theory.

    Activenewsweek.com
  93. Aug 1, 2026

    Michigan reported that a total of nine water systems in the state had been targeted by the cyberattacks, though officials said there were no public health impacts.

    Activeyahoo.com
  94. Aug 1, 2026

    New reporting from CBS News and the New York Times said U.S. investigators, including unnamed intelligence-agency assessments, continue to view Iran-linked hackers as the likely source even though no agency has made a formal on-the-record attribution.

    Activenytimes.com
  95. Aug 1, 2026

    The FBI issued a statement saying it is aware of the public reporting and is fully engaged with interagency partners, but again declined to publicly name a responsible party.

    Activedakotanewsnow.com
  96. Aug 1, 2026

    Michigan became the second state to publicly confirm incidents, reporting activity consistent with the federal alert at nine water systems; officials said all systems continued operating safely with no known public health impact.

    Activedakotanewsnow.com
  97. Aug 1, 2026

    Michigan publicly joined Minnesota in reporting cyberattacks on water systems, disclosing that nine of its water systems were targeted; officials said the systems continued operating safely with no known health impact, and the FBI is investigating.

    Activedakotanewsnow.com
  98. Aug 1, 2026

    A cybersecurity expert told the Jewish News Syndicate the Iran-linked campaign likely extends beyond the confirmed states, noting it was unusual that Iran had not claimed credit for the attacks.

    Activenypost.com
  99. Jul 31, 2026

    Officials said investigators are also examining whether the attackers tried to make the activity appear Iranian in origin, a possible false-flag operation, with assessments described as preliminary.

    Activenewsweek.com
  100. Jul 31, 2026

    President Trump publicly rejected the Iran attribution and blamed Minnesota officials, while Minnesota IT Services said the state has not formally attributed the attacks to any specific actor and the investigation remains active.

    Activenewsweek.com
  101. Jul 31, 2026

    Federal officials said they were continuing to engage with victim utilities as more states reported similar intrusions.

    Activeaol.com
  102. Jul 31, 2026

    President Trump publicly disputed the Iran attribution during a Cabinet meeting, blaming Minnesota state government's handling of the incident instead, while Minnesota's governor and outside cybersecurity researchers said the evidence still points to Iran.

    Activegizmodo.com
  103. Jul 31, 2026

    A Minnesota law enforcement memo said the hackers appeared to be trying to contaminate drinking water by manipulating controllers to drop pipe pressure, though officials maintained no actual contamination occurred.

    Activetechtimes.com
  104. Jul 31, 2026

    The FBI and EPA issued a joint public warning saying water and wastewater utilities in at least seven states, not just Minnesota, had reported cyberattacks this week involving internet-facing industrial controllers.

    Activegovtech.com
  105. Jul 31, 2026

    A leaked WaterISAC memo citing the Minnesota Fusion Center said the attacks were consistent with an Iran-linked PLC-targeting campaign CISA had already warned about in April, becoming the first official-style document tying the Minnesota incidents to Iran, though CISA itself has not formally attributed the attack.

    Activeibtimes.com
  106. Jul 31, 2026

    President Trump publicly rejected the Iran attribution at a Cabinet meeting, blaming Minnesota state officials and Gov. Tim Walz for the attack instead; fact-checkers said his claim was not supported by evidence.

    Activestartribune.com
  107. Jul 31, 2026

    A Minnesota law enforcement memo said the attackers appeared to be trying to contaminate drinking water by manipulating pipe pressure; some victims reported flooding or loss of water pressure.

    Activemsn.com
  108. Jul 31, 2026

    The FBI and EPA warned that cyberattacks had hit water utility providers in at least seven states total, not just Minnesota, and urged utilities nationwide to disconnect internet-exposed industrial control systems.

    Activemsn.com
  109. Jul 31, 2026

    U.S. officials said a preliminary intelligence assessment points to Iran as the likely source, while stressing no water supply was found to be unsafe; CISA issued a fresh warning to water utilities nationwide.

    Activenytimes.com
  110. Jul 30, 2026

    A leaked WaterISAC memo cited a Minnesota Fusion Center assessment tying a wave of attacks on more than 30 Minnesota water systems to Iran-affiliated hackers.

    Activewired.com
  111. Jul 30, 2026

    The FBI and EPA issued a joint public service announcement confirming incidents in at least seven states, including loss of pressure and flooding at some sites.

    Activeic3.gov
  112. Jul 30, 2026

    A leaked WaterISAC memo cited a Minnesota Fusion Center finding linking the attacks to Iran, aligned with an updated CISA advisory on Iran-affiliated hackers targeting water sector PLCs.

    Activewired.com
  113. Jul 30, 2026

    A leaked WaterISAC memo obtained by Wired tied the Minnesota water utility attacks to Iran.

    Activewired.com
  114. Jul 29, 2026

    Reporting detailed that at least one treatment plant went offline and cellular links used for remote monitoring were disrupted; Tenable researchers said the Iran-linked group CyberAv3ngers was suspected.

    Activetheregister.com
  115. Jul 28, 2026

    Minnesota state IT officials publicly disclosed the coordinated cyberattack, saying more than 30 community water systems were targeted.

    Activereuters.com
  116. Jul 28, 2026

    Minnesota IT Services publicly disclosed the coordinated cyberattack, saying operations at some facilities were affected and the state was assisting impacted cities.

    Activereuters.com
  117. Jul 27, 2026

    Hackers began breaching internet-facing Rockwell Automation MicroLogix PLCs at water utilities, the first date cited in the FBI and EPA alert.

    Emergingic3.gov
  118. Jul 26, 2026

    Hackers began a coordinated attack on remotely accessible industrial controllers at Minnesota water and wastewater utilities.

    Emergingreuters.com
  119. Jul 26, 2026

    A coordinated cyberattack began hitting automated controls at more than 30 community water systems across Minnesota.

    Activereuters.com
  120. Jul 22, 2026

    CISA, the FBI, NSA, and the Department of Energy updated a joint advisory warning that Iran-linked actors were inside water and energy control systems and altering operator screens.

    Activesecurityaffairs.com
  121. Jul 19, 2026

    Security press reported an ongoing campaign by Iran-linked actors exploiting internet-exposed PLCs across U.S. water, energy, and government facilities since at least March 2026.

    Emergingcybersecuritynews.com

Sources

Related reports