Contained High impact Industrial control systems Checked 14h ago

Coordinated hacking campaign hits US water utilities in 12 states

Starting in late July 2026, hackers broke into the control systems of Minnesota water utilities, shutting down one plant and forcing others onto manual operation. Minnesota's state IT office later raised its count to more than 40 affected communities. The confirmed footprint reached at least 12 states. CISA said more than 100 internet-exposed water and wastewater systems nationwide were targeted in July. Alpena Township restored remote monitoring by August 28. No newer source confirmed fresh attacks or closure.

Started
Jul 26, 2026
Latest activity
Aug 28, 2026
Attributed to
Iran (suspected, CyberAv3ngers / APT IRAN)Suspected
Where
United States
Sectors
Water
Scale
more than 40 community water utilities in Minnesota, with confirmed incidents in at least 12 states total including Utah

Current status

A September 9 DarkOwl analysis reported no new confirmed US water victim or attack, but cited an August 30 APT IRAN threat.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

A leaked WaterISAC memo and attacker claims point to Iran, but the US government has not formally attributed this campaign.

Impact

Hackers accessed internet-exposed industrial computers that control water equipment, shutting down operations at one Minnesota plant and forcing many other utilities to switch to manual control. Minnesota's count of affected communities grew to more than 40. CISA said attackers disabled shutdown alarms and safety protections in some intrusions. Officials reported no effect on public drinking water quality. Alpena Township restored remote monitoring while its water and sewer service continued safely.

What to do

This is not something the public needs to act on; it is a call for water utility operators to take exposed control systems off the public internet and follow CISA, FBI and EPA advisories, including the August 19 warning about AI-assisted scanning of Siemens industrial controllers. Congress is considering the Water Cyber Shield Act to fund and require these fixes. Volunteer groups such as DEF CON Franklin are also pairing cybersecurity experts with small water utilities that cannot afford their own security staff.

Timeline

  1. Sep 9, 2026

    DarkOwl published an analysis reporting no new confirmed US water victims or formal group claim, while citing an August 30 APT IRAN threat against US energy, water and telecommunications sectors.

    Containeddarkowl.com
  2. Sep 8, 2026

    The Idaho Statesman reported that Idaho water systems were not targeted in the summer campaign and identified no later attack in the state.

    Containedidahostatesman.com
  3. Sep 4, 2026

    A Federal News Network interview reviewed the attacks and said drinking water quality was not harmed, but added no new victims, attacker activity, or attribution.

    Containedfederalnewsnetwork.com
  4. Aug 28, 2026

    The Alpena News identified Alpena Township as an affected Michigan utility and reported that workers restored remote monitoring by reprogramming controllers. Water and sewer service continued safely, but trustees delayed a proposed modem replacement until September.

    Containedthealpenanews.com
  5. Aug 26, 2026

    CISA said in an advisory that more than 100 internet-exposed US water and wastewater systems were targeted during the July attacks, and that in some cases attackers disabled shutdown alarms and safety protocols on affected equipment.

    Containedtechcrunch.com
  6. Aug 25, 2026

    A Facilities Dive review said the known footprint remained at least 12 states while authorities continued investigating and had not formally attributed the campaign.

    Containedfacilitiesdive.com
  7. Aug 22, 2026

    A local Indiana TV investigation found no confirmed attacks in that state but reported utilities there stepping up precautions; it reiterated the national tally as at least 12 states, unchanged from prior reporting.

    Containedwishtv.com
  8. Aug 19, 2026

    The FBI, NSA and CISA warned of a separate AI-assisted campaign probing internet-exposed Siemens S7 series PLCs across water, energy, manufacturing, agriculture and possibly defense; Siemens said no new vulnerabilities were involved, only new exploitation techniques for a misconfiguration flagged in July.

    Containedcybersecuritydive.com
  9. Aug 18, 2026

    CSIS published an analysis mapping the scope and timeline of the water utility intrusions, drawing on press reporting rather than new incident data.

    Containedcsis.org
  10. Aug 16, 2026

    Cybersecurity experts publicly debated whether the newly introduced Water Cyber Shield Act goes far enough to protect small water utilities.

    Containedmsn.com
  11. Aug 15, 2026

    Utah was reported as one of the roughly 12 states whose water infrastructure was targeted, with state officials saying local systems lack foundational protections.

    Containedyahoo.com
  12. Aug 13, 2026

    Senators Klobuchar and Schiff introduced the Water Cyber Shield Act to give the EPA oversight authority over state water system cybersecurity.

    Activevalleynewslive.com
  13. Aug 12, 2026

    Minnesota's state IT agency said more than 40 communities have now reported impacts, up from the original count of more than 30, and that no new incidents have been reported since the initial wave.

    Containedkaaltv.com
  14. Aug 11, 2026

    A Telegram account for a group calling itself APT IRAN claimed direct responsibility for the Minnesota attacks together with CyberAv3ngers, describing the intrusions as only a warning.

    Activethreatbeat.com
  15. Aug 10, 2026

    New Jersey and Alabama were confirmed added to the list of affected states, bringing the total to at least 12.

    Activesecurityweek.com
  16. Aug 5, 2026

    Two New Jersey municipal water systems were confirmed targeted as the known footprint grew to seven-plus states; manual operation prevented outages.

    Activenjbiz.com
  17. Aug 1, 2026

    Federal officials confirmed they were investigating an Iran link after malicious activity was found at water systems in at least seven states, including Michigan.

    Activeyahoo.com
  18. Jul 31, 2026

    CISA urged water utilities nationwide to take internet-exposed control systems offline.

    Activenextgov.com
  19. Jul 30, 2026

    A leaked WaterISAC memo cited a Minnesota Fusion Center alert tying the intrusions to Iran-affiliated hackers.

    Activewired.com
  20. Jul 26, 2026

    A coordinated attack disrupted automated controls at more than 30 Minnesota community water systems.

    Emergingesecurityplanet.com

Sources

Related reports