Drooid Logo
Back to story perspectives

Full Breakdown

Coordinated Cyberattack Disrupts U.S. Water Utilities Across Multiple States

8/4/2026, 11:57:39 PM

Core Event: Multi-State Intrusion of Operational Technology

On July 26-27, 2026, attackers accessed operational technology controlling pumps, valves and treatment machinery at more than 30 community water systems in Minnesota. Similar activity was identified in at least six additional states, bringing the total to a minimum of seven states. The FBI and EPA warned on July 30, 2026 that water and wastewater systems had been targeted, causing operational disruptions and forcing some utilities to revert to manual controls. No public-health emergency was confirmed; water quality remained within safe limits.

Background & Context: Growing Target of Industrial Control Systems

The attacks followed CISA’s expanded April warning about internet-exposed programmable logic controllers (PLCs) from manufacturers such as Rockwell, Allen-Bradley, Schneider Electric and Siemens. Iranian-linked hacking groups have increasingly targeted PLCs, a pattern noted since 2016.

Data & Statistics: Scope and Technical Impact

  • 30+ Minnesota water systems experienced malicious activity; four communities (Braham, Plymouth, South St. Paul, Maple Plain) described specific effects.
  • At least seven states reported incidents; some outlets cited “a dozen.”
  • Manual procedures restored service in Braham within hours; Plymouth and South St. Paul used contingency protocols to maintain water pressure and wastewater lift-station operation.

Official Statements & Responses

  • Minnesota IT Services confirmed the intrusion, noting that “impacted” means activity was detected, not that every community suffered an outage. No active requests to reduce water use were issued.
  • The FBI, EPA and CISA issued joint alerts urging utilities to disconnect internet-facing PLCs, employ VPNs or gateway devices, and replace default passwords.
  • John Israel, Minnesota’s chief information security officer, said the state has provided information to the federal government for attribution analysis.

Criticism & Opposition

President Donald Trump rejected the emerging attribution to Iran, blaming Minnesota’s leadership. Governor Tim Walz responded on X, stating, “This is what modern warfare looks like,” and criticized the president’s dismissal.

On-the-Ground Reports

Operators in Braham, Plymouth and South St. Paul activated manual procedures, allowing treatment to continue while compromised devices were isolated. Residents received no boil-water notices, and testing showed no contamination.

Conflicting Reports & Gaps

  • Number of affected states: Sources vary between “at least seven” and “12.” No definitive list has been released.
  • Attribution: Preliminary suspicion points to Iranian hackers based on similarities to prior campaigns, but no formal attribution has been issued.

Verbatim Quotes

  • “I think that Minnesota is behind it,” — Donald Trump
  • “This is what modern warfare looks like,” — Gov. Tim Walz

What’s Next: Guidance and Ongoing Investigation

CISA’s July 28 “CI Fortify” guidance recommends removing unnecessary internet exposure for PLCs, implementing network segmentation, and regularly testing manual fallback procedures. Federal agencies continue forensic analysis of compromised devices and are assessing whether the techniques match known Iranian-linked operations or represent a new threat actor. Utilities are urged to adopt layered resilience strategies to protect critical water infrastructure.