More Than 30 Minnesota Water Systems Hit in Cyberattack, Investigation Underway Into Iran Link

More than 30 community water systems across Minnesota were targeted in a coordinated cyberattack this week, prompting U.S. authorities to warn water utilities nationwide about a growing threat to critical infrastructure. Investigators are examining whether Iran-linked hackers were behind the attacks, though officials have not made a formal attribution.
What happened
The attacks began the weekend of July 26 and 27, disrupting operational technology at water and wastewater facilities across the state. Minnesota officials have called it one of the largest attacks on local water infrastructure in the state's history. Four cities publicly disclosed being hit: Braham, Plymouth, South St. Paul, and Maple Plain.
In Plymouth, officials discovered compromised programmable logic controllers, or PLCs, at two water towers and fourteen sewer lift stations, and disconnected the devices from their cellular network. In South St. Paul, public works staff switched to manual operations after detecting the intrusion, and the city says drinking water treatment, quality, pressure and delivery were never affected.
That distinction matters most for residents: no drinking water was contaminated or made unsafe. What hackers disrupted were the digital systems operators use to monitor and control physical equipment, forcing several utilities to fall back on manual procedures.
How they got in
Investigators say the hackers exploited internet-connected PLCs, some of which had retained default passwords, a vulnerability Iran-linked actors used in a similar 2023 campaign against U.S. water utilities. The Cybersecurity and Infrastructure Security Agency had updated a warning about Iranian hackers targeting these exact devices just four days before the Minnesota attacks began.
Is Iran responsible?
No state or federal agency has formally attributed the attack. But a senior law enforcement official told NBC News the intrusion bears the hallmarks of Iran-backed hackers, and U.S. intelligence agencies reportedly assess Iran as the likely source. Security researchers at Tenable point to CyberAv3ngers, a hacking group the U.S. Treasury has tied to the IRGC's Cyber-Electronic Command, citing similarities to the group's past operations.
The timing adds weight to the suspicion: the U.S. and Iran have been in an active, ongoing conflict since the U.S. joined Israel's war against Iran in February, and a ceasefire agreement broke down again this month, with both sides resuming strikes. Some officials have raised the possibility that attackers deliberately mimicked Iranian tactics to inflame tensions, though former intelligence officials say that kind of false-flag operation is considered less likely here.
Why it matters beyond Minnesota
The FBI says related activity has reached utilities in at least seven states. Federal officials are now urging water and wastewater providers nationwide to check for internet-exposed control systems, particularly PLCs still running on default credentials.
Water infrastructure is a case study in invisible dependency: nobody thinks about the computers running a treatment plant until they stop working properly. This week's incident didn't need to touch the water supply to cause disruption. It only needed to touch the systems operators rely on to run it. That's the vulnerability now under a national microscope.