MINNESOTA — More than 30 community water systems in Minnesota were targeted in a coordinated cyberattack on July 26 and 27, 2026. The Federal Bureau of Investigation is investigating the cyberattack as state and federal authorities respond to the incident.

The cyberattack targeted operational technology, including control valves, pumps, and cellular communications. Unnamed state and federal officials they believe the cyberattack was likely the work of Iranian hackers. Officials cautioned that assessments attributing the attack to Iran are preliminary and could change as more data becomes available.

Officials noted that attackers may have posed as Tehran-aligned hackers to ratchet up tensions with the US. The attack had minimal impact, and there are no indications that the water supply was rendered unsafe to drink. No ransom was detected in the cyberattack, and service to residents continued.

Only four of the estimated 30 affected systems have been publicized: Braham, Maple Plain, Plymouth, and South St. Paul. The rest of the affected systems are classified as nonpublic according to Minnesota IT Services. Minnesota IT Services stated that the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents involving critical infrastructure.

In Braham’s wastewater treatment plant, the wells that pump water to the local water tower were shut off. A technician in Braham discovered the problem on Monday morning and alerted city officials. Braham officials sent out a city-wide alert telling residents to refrain from non-essential water usage. Braham's water system was back online by Monday night.

Braham city administrator Kevin Stahl said the attack came from the outside. "You physically have to be in the plant to change chemical feed rates," Stahl said. "There was no compromise to any of the flow rates of chemicals or anything like that… they just shut the water off to the well." He added that the city takes its infrastructure seriously despite the breach.

"We take our water and sewer infrastructure pretty seriously. And we thought all of our bases were covered, but bad actors, they also have a plan." Braham revealed that the attackers shut down the operating controls, which shut down the well and water treatment plant.

The attack affected certain automated control functions in Maple Plain's water utility system. A local state of emergency was declared in Maple Plain to expedite the city’s response to the attack. Similar automated functions were affected at South St. Paul’s drinking water system, requiring manual operation. South St. Paul officials wrote in a statement that while the incident affected certain automated controls, established contingency procedures were immediately implemented, allowing Public Works staff to maintain normal water and wastewater operations.

The Plymouth attack affected cellular communications at two water towers and several lift stations, requiring manual procedures. Plymouth noted that the issue is limited to equipment connected via cellular communications within the system. The Minnesota Bureau of Criminal Apprehension is working to determine what happened in the cyberattack. The Bureau of Investigation is a state police force in Minnesota, which was established in 1858.

The Federal Bureau of Investigation stated it is aware of recent public reporting around Water and Wastewater sectors. The Federal Bureau of Investigation emphasized its joint commitment to support critical infrastructure entities against malicious cyber actors attempting to harm the United States. John Israel, Minnesota IT Services assistant commissioner and Minnesota chief information security officer, said cyberattacks against critical infrastructure require a coordinated, whole-of-government response. "MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks," Israel said.

The Water Information Sharing and Analysis Center circulated a memo linking the attacks to Iran. The Minnesota Fusion Center issued an alert regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota. The Minnesota Fusion Center found that the attacks were aligned with a hacking campaign first described in April by the US Cybersecurity and Infrastructure Security Agency as having been carried out by Iran-affiliated hackers. The US Cybersecurity and Infrastructure Security Agency released an advisory warning that threat actors are targeting water entities of all sizes.

The US Cybersecurity and Infrastructure Security Agency advisory initially released in April warned that Iran-linked actors were targeting programmable logic controllers used for automation and coordination in critical infrastructure. The US Cybersecurity and Infrastructure Security Agency advisory noted that CyberAv3ngers specifically had carried out similar targeting of PLCs. Cybersecurity firm Tenable reported that signs suggested CyberAv3ngers, an Iranian hacker group tied to the Iranian Revolutionary Guard Corps, may be responsible for the water utility breaches. The WaterISAC memo states that hackers compromised remotely accessible PLCs, with the likely desired impact to cause loss of system pressure and potential contamination of the water supply.

The US Cybersecurity and Infrastructure Security Agency advised utilities to disconnect PLCs from the internet, password-protect access with strong passwords, and allow-list only trusted devices. The US Cybersecurity and Infrastructure Security Agency advisory noted that the attacks have resulted in boil-water notices and sustained manual operations. Denis Calderone, CTO of Suzu Labs, pointed to Plymouth’s statement that the impact is limited to equipment connected via cellular communications. In 2020, threat actors linked to the Iranian government exploited vulnerable cellular routers as a point of entry in attacks targeting water facilities in Israel.

In 2022, Governor Tim Walz issued an executive order stating that critical infrastructure is facing increasingly sophisticated cyberattacks. The 2022 executive order required annual assessments certified by the Minnesota Department of Health, mandated reporting, and other response plans. According to an annual report from Minnesota IT Services, there were a total of nine cyberattacks on critical infrastructure in Minnesota in 2025. A 2023 investigation by the Environmental Protection Agency found over 70% of inspected community drinking water systems throughout the country lack basic emergency response plans for cyberattacks.

The coordinated nature of the attack on more than 30 systems shows vulnerabilities in operational technology across critical infrastructure. The attribution to Iran-affiliated actors, specifically the CyberAv3ngers group, aligns with previous campaigns targeting programmable logic controllers and cellular communications in water facilities. While the immediate impact was minimal due to manual overrides and contingency plans, the incident reflects the need for the security measures outlined in federal advisories and state executive orders.

The response involves multiple layers of government, from local public works departments maintaining service to federal agencies like the FBI and CISA providing intelligence and technical guidance. The preliminary nature of the attribution and the potential for false flag operations remain areas of ongoing investigation. The incident serves as a practical test of the resilience protocols established since the 2022 executive order and the gaps identified in the 2023 EPA investigation.