MINNESOTA — A cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth, in late July 2026. Between July 26 and July 28, 2026, local authorities in Minnesota notified citizens of problems at community water plants in locations including Braham and Maple Plain. Officials said they had found no evidence that drinking water quality was affected by the intrusions.

Water treatment plant pumps in Braham, Minnesota, failed due to a cyberattack, threatening water flow to approximately 1,700 residents. Braham workers restored water flow within a couple of hours by taking manual control of the pump and drawing on backup supply. Residents were asked to minimize water use while the plant was offline for a few hours.

\"Everything's connected to the internet in one way or another. It's not Braham in particular that's being targeted. It's the internet access points and the vulnerable technology,\" Braham Mayor Nate George said.

Officials in Maple Plain, Minnesota, declared a brief state of emergency before determining that the immediate threat to public health, safety, and welfare had been addressed. Water outages related to the cyberattacks also occurred in New Jersey and Michigan. The FBI confirmed that at least seven states suffered similar attacks on water and wastewater facilities. An anonymous cybersecurity expert stated there is intelligence indicating Iranian-linked actors were behind the coordinated intrusions.

The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued a Public Service Announcement warning that malicious cyber actors are targeting Operational Technology (OT) devices, specifically Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), MicroLogix 1100 and 1400 series. Cybersecurity firm SonicWall observed a recent spike in bad actors scanning the internet for vulnerable devices. \"I can't recall a time when there's been this many targets at once with operational impact,\" Dragos Co-founder and CEO Rob Lee said.

A senior law enforcement official familiar with the investigation said the cyberattack targeting more than 30 municipal water systems across Minnesota bears the hallmarks of Iran-backed hackers. \"It appears this is a shot across the bow from Iran,\" former White House acting principal deputy national cyber director Jake Braun said. Neither the Iranian government nor known Iranian hacktivist groups, including Cyber Av3ngers, have taken credit for the recent wave of water attacks.

\"We're seeing somebody run their proof of concept. What is it that you can do to … scare the American people? Water is one of those things. It's a necessity of life,\" SonicWall Representative Michael Crean said.

The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency published an advisory about Iranian-linked hackers targeting vulnerabilities in industrial machines in April 2026, updating it days before the recent attacks. In 2023, an Iranian-linked hacktivist group broke into and defaced industrial machines in a water facility in Aliquippa, Pennsylvania, displaying anti-Israel messages.

Why It Matters

The coordinated nature of the attacks across multiple states shows vulnerabilities in critical infrastructure that relies on internet-connected operational technology. By targeting water systems, the actors aimed to disrupt a necessity of life, raising concerns about the potential for broader physical impacts from cyber intrusions. The scale of the incident, affecting more than 30 systems in Minnesota alone and facilities in at least six other states, represents an escalation in tactics compared to previous isolated incidents.

The response includes both immediate technical warnings from federal agencies and legislative proposals to strengthen long-term defenses. The introduction of the Water Cyber Shield Act indicates a push to formalize cybersecurity standards and provide funding for improvements in the water sector. The lack of claimed responsibility by any specific group leaves open questions about the ultimate command structure behind the operations, even as intelligence assessments point to Iranian affiliation.

Timeline

In 2023, an Iranian-linked hacktivist group broke into and defaced industrial machines in a water facility in Aliquippa, Pennsylvania, displaying anti-Israel messages. The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency published an advisory about Iranian-linked hackers targeting vulnerabilities in industrial machines in April 2026, updating it days before the recent attacks. Between July 26 and July 28, 2026, local authorities in Minnesota notified citizens of problems at community water plants in locations including Braham and Maple Plain. Since July 27, 2026, Water and Wastewater Sector utility companies in at least seven states have reported incidents to the FBI, with some activity degrading water operations.

Water treatment plant pumps in Braham, Minnesota, failed due to a cyberattack, threatening water flow to approximately 1,700 residents. Braham workers restored water flow within a couple of hours by taking manual control of the pump and drawing on backup supply. Officials in Maple Plain, Minnesota, declared a brief state of emergency before determining that the immediate threat to public health, safety, and welfare had been addressed. Water outages related to the cyberattacks occurred in New Jersey and Michigan.

What's New

The cyberattacks targeted technology used by more than 30 community water systems in Minnesota on Sunday and Monday, and officials said they had found no evidence that drinking water quality was affected. A senior law enforcement official familiar with the investigation said the cyberattack targeting more than 30 municipal water systems across Minnesota bears the hallmarks of Iran-backed hackers. The city of Braham, which has a population of about 1,700 people, was directly affected by the cyberattack, as the water plant was offline for a few hours, and residents were asked to minimize water use.

Democratic Senators Adam Schiff and Amy Klobuchar unveiled the Water Cyber Shield Act on August 10, 2026, which seeks to increase drinking water and clean water state revolving funds by $300 million annually for cybersecurity improvements. Since July 27, 2026, Water and Wastewater Sector utility companies in at least seven states have reported incidents to the FBI, with some activity degrading water operations. The proposed Water Cyber Shield Act would allow the Environmental Protection Agency (EPA) to conduct cybersecurity assessments and require corrective actions, and establish baseline cybersecurity standards for drinking water systems in coordination with CISA and NIST. The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued a Public Service Announcement warning that malicious cyber actors are targeting Operational Technology (OT) devices, specifically Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), MicroLogix 1100 and 1400 series.

How Sources Differ

Regarding the targeted technology and water systems in Minnesota, Nextgov/FCW reported that the cyberattacks targeted technology used by more than 30 community water systems in Minnesota on Sunday and Monday, and officials said they had found no evidence that drinking water quality was affected. Minnesota state officials stated that a cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth, in late July 2026.

On the attribution of the cyberattack on water systems in Minnesota, that a senior law enforcement official familiar with the investigation said the cyberattack targeting more than 30 municipal water systems across Minnesota bears the hallmarks of Iran-backed hackers. Minnesota state officials stated that a cyberattack targeted the operating technology at over 30 water systems in Minnesota, including Plymouth, in late July 2026.

Regarding the role of the Environmental Protection Agency, that the proposed Water Cyber Shield Act would allow the Environmental Protection Agency (EPA) to conduct cybersecurity assessments and require corrective actions, and establish baseline cybersecurity standards for drinking water systems in coordination with CISA and NIST. The FBI noted that the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued a Public Service Announcement warning that malicious cyber actors are targeting Operational Technology (OT) devices, specifically Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), MicroLogix 1100 and 1400 series.