Back to Feed
Nation-stateJul 31, 2026

Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers

Over 30 Minnesota water systems targeted in cyberattacks, with Iranian hackers suspected.

Summary

Over 30 water systems in Minnesota were targeted by cyberattacks on Sunday and Monday. While no impact on water quality or service was reported for residents, investigators are looking into the incidents. Officials have warned that Iranian hackers have been increasingly targeting water and wastewater systems, citing geopolitical motivations and a history of similar attacks.

Full text

Authorities were working Thursday to find the source of cyberattacks that targeted over 30 water systems in Minnesota and came amid warnings that Iranian hackers have been focused on such systems. Minnesota IT Services said state officials had yet to identify who was behind the attacks that took place Sunday and Monday. There were no reports that residents had been impacted by the attacks, though one city asked residents to conserve water for a couple hours while they tried to determine what was wrong. The FBI, which is investigating, has not publicly identified a culprit and a spokesperson declined to say Thursday who the bureau thought might be responsible. The FBI, Cybersecurity and Infrastructure Security Agency and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls other critical infrastructure sectors. Digital warfare has become ingrained in military conflict, and local water plants or healthcare facilities often lack the funds and know-how to install the latest software patches or take other security steps. That has made them a favorite target, both because of the relative ease of penetrating them and because of the panic such disruptions can cause. [ Read: CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs ] Iran has the “geopolitical motivations” and a recent history of targeting water systems, said Cynthia Kaiser, the former deputy assistant director of the FBI’s cyber division who has been closely monitoring threats to critical infrastructure from hackers linked to the country.Advertisement. Scroll to continue reading. “I think most credible researchers and responders would be right to treat it like it’s Iran until proven otherwise,” added Kaiser, who is now the senior vice president of Halcyon’s Ransomware Research Center. “When it walks like a duck and talks like a duck, it’s really important to call it out.” Iran’s interest in the operations of water systems inside the U.S. dates back years. In 2016, the Justice Department charged a group of Iranian hackers in connection with a cyberattack targeting a small dam near New York City. Minnesota IT Services said that as of Thursday, there were no active requests from Minnesota communities for residents to modify usage of their drinking water. The state agency said most of the confirmed attacks involved technology that water systems use to remotely monitor and control equipment. It said that being impacted meant investigators confirmed there was malicious activity involving the system’s technology and didn’t mean every impacted community had their water service disrupted. The state agency said there are similarities among the incidents, including timing and the types of technology used, but investigators haven’t determined if the same culprit was behind each one. For a few hours on Monday, the city of Braham asked residents to minimize water use as they tried to determine why the water plant was offline. The city of about 1,700 people, located about 70 miles (113 kilometers) north of Minneapolis, said in a news release that the water plant outage was due to a cyberattack, but it didn’t cause any issue with water quality. The city said the attackers shut down the operating controls that shut down the well and water treatment plant. That left the city for a time only able to provide residents with the water held in the water tower. In Plymouth, a city of about 80,000 located outside of Minneapolis, officials said on social media that their water infrastructure communications had been restored by Tuesday afternoon following a cyberattack. The city said crews were able to continue operating the system during the outage and it didn’t have any impact on water levels or quality. Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Written By Associated Press Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Associated Press US Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a StartupEU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying CampaignTrump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity AlarmSupreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location HistoryOpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity ReviewAnthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official SaysFrench President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation Latest News In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsCritical Flaw Allowed to Azure Cosmos DB PwnageCareCloud Data Breach Impacts Over 350,000Critical Code Execution Vulnerability Patched in TeamCity CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Iranian hackers (threat_actor)Halcyon (vendor)Operational Technology (technology)