US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Iran-linked hackers targeted water systems across at least 7 US states in July cyberattacks.
Summary
Iran-linked threat actors conducted a coordinated campaign targeting operational technology (OT) systems at water and wastewater facilities across at least seven US states, including Minnesota, Michigan, South Dakota, and Georgia, on July 26-27. The attacks primarily exploited cellular-connected equipment and vulnerable industrial control systems made by Siemens, Schneider Electric, and Rockwell Automation. While no operational impact or public health concerns were reported, CISA and federal agencies have warned of ongoing Iranian targeting of critical water infrastructure.
Full text
The recent cyber campaign targeting the water and wastewater sector in the United States has hit at least seven states as more information has come to light regarding Iran’s connection to the hacker attacks. Minnesota reported last week that operational technology (OT) systems at more than 30 water and wastewater facilities were targeted in a cyberattack on July 26 and 27. Only a handful of cities issued public statements about the attack. One city briefly took down its water plant in response, but most reported no operational impact, reassuring citizens that drinking water remains safe. As expected, the campaign was not limited to Minnesota, and several mainstream media outlets reported learning from sources that at least seven states are impacted. Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity, noting that all systems continued to operate safely and there were no public health concerns. Rapid City in South Dakota also reported experiencing a cybersecurity incident, and its description suggests that it may be part of the same campaign. Advertisement. Scroll to continue reading. “Recently, the City of Rapid City experienced a cyber incident involving one of its lift stations, which is used as part of the city’s wastewater system,” the city said in a Facebook post, adding, “At no time was the city’s water or wastewater infrastructure systems placed in jeopardy and city officials assure Rapid City residents the city’s water supply remains safe and protected.” ABC News reported that Georgia is also among the seven states targeted in the water sector cyberattacks. The names of the other affected states remain unknown at the time of writing. Iran blamed for the water sector cyberattacks Iran was immediately named as the primary suspect considering that its hackers have been known to target ICS and other OT systems, including in the water sector. While the US government has not publicly blamed Iran for the attacks, several mainstream media outlets reported last week that federal investigators had been looking into Iran’s potential involvement. In addition, WaterISAC, which serves as the communications and information-sharing organization for the water sector, reportedly wrote a report revealing that Minnesota’s Fusion Center had found evidence that the attacks were “aligned” with hacking campaigns previously linked by the US to Iran. Wired obtained a copy of the report, but WaterISAC noted that it was marked TLP:Amber and was not meant for public release or broad sharing. Technical details for OT defenders Few technical details have been made available by the cities whose water facilities have been targeted by hackers. However, one city in Minnesota noted that the incident was limited to “equipment connected via cellular communications,” and industry professionals agree that OT endpoints connected to the internet via cellular networks are a potential intrusion vector. Iran-linked hackers previously targeted water facilities in Israel via vulnerable cellular routers. Infracritical has made available a continuously updated report that summarizes all of the currently known technical information for the OT security community and defenders. After the attacks on Minnesota water facilities came to light, CISA urged the sector to protect OT, specifically programmable logic controllers (PLCs). In addition, days before the Minnesota attacks, federal agencies updated an April advisory on Iranian attacks aimed at OT devices, warning that industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation have been targeted. Internet security firm Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, though it’s unclear how many are actually vulnerable to attacks. Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Semiconductor Firm Analog Devices Discloses Data Breach1 in 5 Data Center Assets Are Within Easy Reach of AttackersCisco Secure FMC Zero-Day Exploited in the WildThreatLocker Raises $190 Million in Series F FundingCritical VM Escape Vulnerability Patched in VMware ESXiOpenAI’s Rogue AI Ventured Beyond Hugging FaceDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksCyera Acquiring Oasis Security in $1 Billion Deal Latest News Russian State APT Linked to Recent Public Wi-Fi Gateway HackingBalance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity InvestmentsRuby on Rails Patches Critical VulnerabilityIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Iran-linked hackers