Drooid Logo
Back to story perspectives

Full Breakdown

Minnesota Water Systems Cyberattack Sparks Attribution Fight

8/2/2026, 5:50:46 AM

Coordinated Attack on Water Utilities

In late July 2026, malicious cyber activity struck operational technology at more than 30 municipal water and wastewater systems across Minnesota. The intrusion disabled remote monitoring and control functions—primarily programmable logic controllers (PLCs) and human-machine interfaces—forcing several utilities to shift to manual operation. No water-quality or pressure issues were reported, and no public-health advisories were issued. The same week, Michigan reported similar activity at nine of its water systems, and federal agencies noted comparable incidents in at least seven states.

Background and Context

Federal alerts issued in April 2024 and again on July 22 warned that Iranian-affiliated hackers were targeting internet-exposed PLCs used by water utilities. The United States has been at war with Iran since February 28, 2026, after launching airstrikes in response to Iranian actions. Iranian cyber groups have a documented history of probing U.S. water infrastructure, including a 2016 indictment for a dam-related intrusion.

Timeline

  • July 26–27 – Minnesota IT Services (MNIT) confirms the coordinated cyberattack on over 30 water systems.
  • July 27 – The FBI reports “malicious criminal actors” have disrupted water utilities in at least seven states.
  • July 30 – Michigan joins Minnesota in reporting attacks on nine water systems; officials say all are operating safely.
  • July 31 – President Donald Trump, at a Camp David cabinet meeting, blames Minnesota’s governor for the attacks and rejects the notion of Iranian involvement.
  • July 31 – Governor Tim Walz responds on social media, asserting that the attacks align with Iranian-linked campaigns.

Data and Statistics

  • 30+ Minnesota water and wastewater facilities experienced the intrusion.
  • 9 Michigan water systems reported similar activity.
  • Federal advisories cite incidents in at least 7 states.
  • Compromised technology includes PLCs from Rockwell Automation, Schneider Electric, and Siemens.

Official Statements & Responses

The agency is coordinating with CISA, the EPA, and the FBI, all of which have issued alerts urging utilities to remove PLCs from direct internet exposure and to strengthen authentication.

President Trump stated he does not believe Iran was behind the incidents and attributed responsibility to Minnesota’s state government, describing the governor as “grossly incompetent.”

John Israel, Minnesota’s chief information security officer, said the state has supplied relevant data to federal partners for broader analysis.

Criticism & Opposition

State officials and cybersecurity experts have challenged the president’s dismissal of Iranian involvement, noting that the attack’s tactics match those previously linked to Iran-affiliated actors. Critics argue that politicizing the incident hampers coordinated defensive measures.

Conflicting Reports & Gaps

Federal agencies have not publicly attributed the attacks to a specific actor, describing the assessment as “preliminary.” Some officials cite technical similarities to known Iranian campaigns, while others stress the need for further forensic evidence. No public evidence has been released confirming the perpetrators’ identity.

What’s Next

MNIT, CISA, and the FBI continue to investigate, with plans to issue further technical guidance on securing PLCs and other operational technology. State and local utilities are urged to implement network segmentation, strong password policies, and offline backups while the attribution analysis proceeds.