A multi-day coordinated cyber attack has hit more than 30 water utilities in Minnesota by targeting operational technology, prompting the activation of statewide incident response protocols.
The Feds are coordinating with local authorities to investigate and respond to the cyber attack. They have linked the cyber attack to Iranian hackers, who have stepped up attacks on U.S. critical infrastructure amid the ongoing conflict.
Coordinated cyber attack hits Minnesota water utilities
The attack occurred on July 26 and 27, resulting in some water utilities going offline. The downtime forced the City of Braham, Minnesota, to issue a notice urging residents to minimize water use, especially for watering lawns or recreational purposes, until the problem was rectified.
Three hours later, the City of Braham reported it had resolved the cyber attack and that water filtration and flow were operating as usual.
City of Maple Plain, MN, also reported system outages resulting from the coordinated cyber attack. However, it implemented contingency measures to ensure normal operations.
“While the incident affected certain automated control functions, established contingency procedures were immediately implemented. As a result, Public Works staff have been able to maintain normal water and wastewater operations without interruption,” it stated.
City of South St. Paul, MN, also applied contingency measures to ensure that water filtration and flow and wastewater treatment services were unaffected.
“The targeting of multiple water utilities illustrates several ongoing trends in the cyber threat landscape,” said Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova. “First, threat actors are increasingly focusing on essential infrastructure providers, not just private companies. These organizations are often targeted not because they are uniquely valuable, but because they fit a broader target profile.”
Meanwhile, U.S. federal agencies assessed that water quality was not affected. Similarly, Minnesota IT Services (MNIT) said it was working with federal, state, local, and tribal authorities, water utilities, and private partners to investigate and respond to the incident.
“MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks,” said John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer.
Water utilities with vulnerabilities targeted during the coordinated cyber attack were advised to remain on high alert to prevent similar incidents. Mr. Israel warned that the hackers would continue to target vulnerable critical infrastructure in the foreseeable future. The EPA had previously assessed that hundreds of critical infrastructure systems contained high-severity vulnerabilities in their operational technology.
“A rural or municipal service provider may reasonably assume it is unlikely to be targeted, but attackers are often looking for organizations with the right vulnerabilities, regardless of size or location,” added Perry. “This also demonstrates how broadly and indiscriminately threat actors can operate. Victims are increasingly being targeted as part of larger campaigns against groups of similar organizations rather than as isolated targets. The goal does not always need to be immediate disruption. Gaining access to operational environments can provide attackers with visibility into systems, reveal weaknesses, and create opportunities for future action.”
Iranian hackers linked to coordinated cyber attack on Minnesota water utilities
So far, MNIT has not attributed the cyber attack to any threat actor. However, the coordinated cyber attack on water utilities bears the hallmarks of a state-sponsored activity. The lack of ransom demands or political messages seemingly excludes financially motivated threat actors or hacktivist groups.
Similarly, federal investigators have preliminarily linked the cyber attack to Iranian hackers. However, they warned that full attribution was still in progress and could change after complete analysis of the collected technical data.
False flags by third-party actors to inflame the conflict with Tehran were also possible. President Donald J. Trump also cast doubt on whether Iran, which has bigger problems, was involved and instead pointed a finger at Minnesota authorities. Additionally, although initial assessments usually turn out to be correct, full attribution remains a complicated matter.
Nevertheless, Iran has a history of targeting U.S. critical infrastructure. In April 2026, hackers linked to the Iranian Revolutionary Guard Corps targeted gas stations across the United States by altering automatic tank gauge (ATG) readings. In November 2023, Iranian hacktivist group CyberAv3ngers breached Pennsylvania Municipal Water Authority of Aliquippa by targeting Israeli-made PLCs.
“The specific actor matters for attribution, but the broader trend is what should concern us,” said Matt Hartman, Chief Strategy Officer at Merlin Group. “Under-resourced municipal utilities have become recurring targets for cyber adversaries because they provide an opportunity to disrupt essential services and expose systemic weaknesses. Every disruption like this chips away at public trust, which is exactly why operational resiliency has to reach the communities that need it most.”
Meanwhile, in July 2026, the FBI, CISA, and partner agencies warned about Iranian hackers expanding the list of targeted programmable logic controllers to compromise U.S. critical infrastructure. The joint cybersecurity advisory warned that all internet-exposed PLCs were potential targets. The agencies also published a list of mitigations to help critical infrastructure operators thwart Iranian-linked cyber attacks.

