Cyberattack Wave Disrupts More Than 30 U.S. Water Systems as Federal Investigation Expands


A coordinated series of cyberattacks has targeted more than 30 community water systems across Minnesota, raising fresh concerns about the security of America’s critical infrastructure. The incidents, which unfolded over July 26 and 27, disrupted operational technology responsible for monitoring and controlling water treatment facilities, forcing several communities to switch to manual operations while cybersecurity teams raced to contain the attacks. Although officials say drinking water remains safe and there is currently no statewide advisory for residents to reduce water use, the scale and coordination of the attacks have prompted an extensive response involving state and federal agencies.

The investigation is still unfolding, and many questions remain unanswered. Authorities have not identified who carried out the attacks, how the systems were compromised, or whether sensitive operational data was stolen. What investigators have confirmed, however, is that the attacks followed strikingly similar patterns across multiple locations, suggesting they were carefully coordinated rather than isolated incidents. As cyber threats increasingly shift toward essential public services, the attacks serve as another reminder that digital security has become just as important as physical security for the infrastructure millions of Americans depend on every day.

More Than 30 Water Systems Came Under Attack

Minnesota IT Services (MNIT) confirmed that more than 30 community water systems experienced some form of impact during the coordinated attacks. While every utility was affected differently, investigators said the incidents shared common characteristics, including the timing of the attacks, the methods used to gain access, and the type of operational technology that was targeted. Those similarities ultimately led officials to classify the activity as a coordinated cybersecurity event.

The attacks primarily targeted operational technology, the specialized computer systems that monitor and control water treatment processes, pumping stations, storage tanks, and wastewater facilities. Unlike traditional office networks, these industrial control systems are directly connected to the physical infrastructure responsible for delivering clean drinking water. Disrupting them can interfere with monitoring capabilities, automated controls, and communication between critical components, even if the water supply itself remains safe.

Officials emphasized that the impact varied significantly from one community to another. Some utilities experienced communication failures that interrupted remote monitoring, while others temporarily lost automated control functions and had to rely on manual operations. Despite those disruptions, state officials said responders were able to contain the incidents before they escalated into more severe service interruptions.

MNIT also stressed that there is currently no evidence suggesting a statewide threat to drinking water quality. As of July 29, investigators said they were unaware of any active requests asking residents to change how they use their drinking water. Instead, response efforts remain focused on understanding exactly how the attackers gained access and whether additional systems may have been compromised.

Communities Were Forced To Respond Quickly

Several Minnesota communities have publicly described how the cyberattacks disrupted their utility operations, illustrating just how differently each system was affected. While some cities experienced relatively minor communication issues, others temporarily lost key automated functions that normally keep water infrastructure operating around the clock.

One of the most significant disruptions occurred in the city of Braham, where the municipal water treatment plant was forced offline during the incident. Local officials asked residents to minimize water usage while crews worked to restore treatment operations. Although service was eventually restored, the outage demonstrated how quickly a cyberattack can interrupt essential public utilities that communities depend on every day.

Plymouth also experienced operational challenges after cellular communications were disrupted at two water towers and several wastewater lift stations. Rather than shutting down service, city personnel switched to manual operations to keep the system functioning while technicians investigated the communication failures. Officials said drinking water service continued despite the loss of automated monitoring capabilities.

Other cities, including South St. Paul and Maple Plain, reported that automated utility controls had been affected but continued delivering water without interruption. Maple Plain declared a local state of emergency to support its response efforts, allowing local officials to coordinate resources more effectively as cybersecurity specialists worked alongside utility operators to stabilize affected systems.

Investigators Say The Attacks Shared The Same Pattern

Although investigators have not publicly identified the attackers, officials believe the incidents were far from random. According to MNIT, the attacks displayed consistent characteristics across multiple water systems, including similar methods of access and the same type of industrial infrastructure being targeted. Those similarities strongly suggest a coordinated campaign rather than unrelated cybersecurity incidents occurring at the same time.

Officials have deliberately withheld many of the technical details while the investigation remains active. They have not disclosed which software, hardware, or vulnerabilities may have been exploited, arguing that releasing those details prematurely could interfere with both the investigation and ongoing defensive efforts. They have also not confirmed whether any sensitive operational data was stolen during the attacks.

MNIT said investigators are working closely with cybersecurity experts to determine whether a single threat actor is responsible or whether multiple groups independently carried out similar attacks. At this stage, officials say attribution has not been finalized, even though the operational patterns closely resemble activity previously observed by federal cybersecurity partners in other industries and states.

The state’s response has expanded into a coordinated effort involving Minnesota IT Services, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), the Federal Bureau of Investigation (FBI), and affected local utilities. According to John Israel, MNIT’s assistant commissioner and Minnesota’s chief information security officer, “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response.”

Experts See Similarities To Earlier Critical Infrastructure Threats

Although investigators have not publicly identified who was responsible for the Minnesota attacks, cybersecurity experts have pointed to similarities with previous campaigns targeting industrial control systems. Just four days before the Minnesota incidents, U.S. agencies expanded an advisory warning that Iranian-affiliated threat actors had been targeting internet-facing programmable logic controllers (PLCs) manufactured by companies including Rockwell Automation, Schneider Electric, and Siemens. Those systems are widely used to automate operations in water treatment plants, power facilities, and other essential infrastructure.

Federal officials have not linked the Minnesota attacks to that campaign, and they continue to caution against drawing conclusions before the investigation is complete. Even so, the timing of both events has attracted attention within the cybersecurity community. Investigators noted that the tactics used in Minnesota were consistent with activity federal agencies have observed across other industries, although they stopped short of naming a specific group.

Security researchers at Tenable also highlighted the operational similarities. Scott Caveza, senior staff research engineer at the cybersecurity firm, said the methods seen during the attacks resemble techniques previously associated with CyberAv3ngers and other groups linked to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. He noted that those organizations have repeatedly targeted critical infrastructure since at least 2023, particularly facilities responsible for water and wastewater management.

Despite those observations, attribution remains one of the most challenging parts of any cyber investigation. Attackers often route their operations through compromised systems in multiple countries, making it difficult to determine exactly who is responsible. For that reason, Minnesota officials continue to emphasize that no organization or nation has been officially blamed for the attacks.

FBI And EPA Issue Separate Warning After Similar Incidents

As investigators continued examining the Minnesota attacks, the FBI and Environmental Protection Agency released a separate warning involving additional cyber incidents affecting water and wastewater utilities in at least seven states. According to the agencies, those reports began arriving on July 27 and involved internet-facing programmable logic controllers manufactured by Rockwell Automation, specifically the Allen-Bradley MicroLogix 1100 and 1400 models.

Federal investigators found that attackers remotely altered PLC IP addresses and passwords, effectively locking operators out of the devices responsible for monitoring and controlling essential equipment. Some affected utilities experienced degraded operations, including reduced water pressure and localized flooding after losing visibility into portions of their systems. At least one organization also discovered unauthorized modifications to PLC project files, indicating that attackers had manipulated operational logic rather than simply gaining access.

The FBI stressed that it has only observed this activity on those particular controller models so far, but advised operators using other industrial control systems to strengthen their defenses as well. Officials also made it clear that the incidents reported across seven states have not been connected to the Minnesota attacks, and no public attribution has been announced for either investigation.

The back-to-back incidents nevertheless illustrate the growing attention cybercriminals and nation-state actors are giving to operational technology. Unlike traditional data breaches that focus on stealing information, attacks against industrial control systems have the potential to interfere directly with physical infrastructure, creating disruptions that extend beyond computer networks into everyday public services.

CISA Urges Water Utilities To Strengthen Their Defenses

While investigators continue searching for answers, the Cybersecurity and Infrastructure Security Agency has issued updated guidance designed to help utilities reduce the risk of future attacks. The recommendations focus on improving visibility into industrial control systems while limiting opportunities for unauthorized remote access.

Among the agency’s recommendations are restricting controller access to authorized systems, maintaining detailed logs of cellular modem connections, and regularly inspecting controller project files for unauthorized changes. CISA also advises utilities to verify backup integrity before restoring compromised systems and to confirm that controller configurations have not been altered before placing equipment back into normal operation.

Officials have not disclosed whether the Minnesota attacks exploited a specific vulnerability, software flaw, or hardware weakness. They also have not identified which programmable logic controller family, if any, was involved. That information remains part of the active investigation as responders continue examining affected facilities throughout the state.

For water utilities across the country, the attacks serve as another warning that cybersecurity is now inseparable from public infrastructure. Systems once designed primarily for efficiency and automation are increasingly becoming targets for sophisticated threat actors seeking to disrupt essential services.

A Growing Challenge For America’s Critical Infrastructure

The investigation into the Minnesota cyberattacks remains ongoing, with state and federal authorities continuing to analyze forensic evidence and monitor affected systems for additional signs of compromise. While drinking water services have largely remained operational and officials say there is no current need for residents to change their water usage, many of the key questions surrounding the attacks remain unanswered.

What is already clear is that cyber threats against critical infrastructure continue to evolve in both scale and sophistication. As water treatment facilities, power grids, transportation systems, and other essential services become increasingly connected, defending those networks has become a national security priority. The events in Minnesota demonstrate how quickly coordinated cyberattacks can test emergency response systems, even when their full origin and objectives have yet to be determined.

Loading…