The water came out of the tap on Monday morning. That's the most important sentence in this story, and, depending on where you sit professionally, either a reassurance or a warning about how close the outcome could have been.
Between the nights of Sunday, July 26, and Monday, July 27, 2026, a coordinated cyberattack struck the operational technology (OT) of more than 30 Minnesota community water systems simultaneously. By Monday morning, city officials across the state discovered outages and disruptions to some of their water utilities' automated operating controls.
Four communities have been publicly confirmed as affected: Braham, Plymouth, South St. Paul, and Maple Plain. The remaining 26-plus systems are classified as nonpublic by Minnesota IT Services (MNIT), per state agency policy on active investigations.
The attack is now known to be part of a wider campaign affecting seven U.S. states. Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure.
And a Minnesota law enforcement memo has since revealed what the attackers were actually trying to accomplish: not just knocking systems offline, but contaminating the drinking water supply by dropping pipe pressure below safe levels.
What actually happened: city by city
The attack targeted programmable logic controllers (PLCs) and human-machine interfaces (HMIs)—the devices that water operators use to remotely monitor and control pumps, wells, pressure, and chemical treatment systems. Here's what the operational picture looked like on the ground in the four confirmed cities.
Braham (population ~1,700)
Unknown malware shut down operating controls to the water plant, leaving the water tower unable to be filled for more than an hour. The incident disabled operating controls, causing a well and the plant to go offline for less than two hours. Water stored in the city's tower continued supplying residents, and officials said water quality and safety were not affected. To protect their drinking water, Braham officials simply shut their whole computer system down, cutting off external access to it.
City Administrator Kevin Stahl summed up the broader problem bluntly: "We take our water and sewer infrastructure pretty seriously. And we thought all of our bases were covered, but bad actors, they also have a plan."
Plymouth (population ~80,000)
The affected assets were equipment connected over cellular communications at two water towers and multiple lift stations. The city IT division disconnected that equipment from the network to stop the attack and prevent retargeting while it was reconfigured. Plymouth also had to switch to manual operations.
South St. Paul (population ~21,000)
A cybersecurity incident affected technology supporting parts of its water utility system. Some automated controls were affected, but the city said drinking water remained safe and water and wastewater operations continued normally.
Maple Plain (population ~1,800)
Maple Plain declared a local state of emergency to expedite the city's response to the attack, which affected certain automated control functions in its water utility system.
Braham officials confirmed that at least four other communities beyond the publicly named cities were attacked "with the same result."
How close did this come to contaminating the water?
This is the question that matters most to the public, and the answer deserves precision.
No city reported that an attacker had changed chemical levels, contaminated the water supply, or caused a prolonged interruption of service. No boil-water advisories were issued. The Minnesota Department of Health, working alongside MNIT, confirmed it was not aware of any active requests from Minnesota cities for residents to modify their drinking water usage.
But the attackers' stated goal was not simply disruption. A Minnesota law enforcement memo obtained by TechTimes reveals that the hackers intended to contaminate drinking water by dropping pipe pressure. The significance of that detail is technical and serious. A water tower is a system's pressure reservoir and its buffer—the thing that keeps taps flowing and, more importantly, keeps the distribution system pressurized while pumps are down. Sustained loss of the ability to refill a tower is precisely the condition that produces the pressure drop, back-siphonage, and precautionary boil advisory sequence. Braham caught it in time. Elsewhere in the country, according to U.S. officials briefed on the wider campaign, some utilities did issue boil-water notices and took systems offline.
The water was safe in Minnesota. It was a narrow margin, built primarily on stored water in towers, quick operator response, and the ability to switch to manual procedures before the attacks achieved their intended effect. It was not a comfortable margin.
The wider campaign: seven states, one playbook
In a July 30th warning, the FBI and EPA said water and wastewater utilities in at least seven states had reported incidents since July 27 involving internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs.
The FBI described attackers targeting OT devices including Rockwell Automation/Allen-Bradley PLCs. "After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality," the FBI said.
The playbook is consistent and simple: find water utility industrial controllers directly exposed to the internet, often with default or unchanged credentials, and take control of them. This is not a sophisticated zero-day campaign. It is a campaign of opportunistic exploitation against a sector that has historically deprioritized cybersecurity investment, connected its operational technology to the internet for remote management convenience, and often lacks the staff or budget to maintain basic hygiene on those systems.
The FBI is now providing defenders with a list of steps to harden these critical systems, starting with "disconnecting PLCs from the public-facing internet."
Is Iran truly to blame?
Attribution is preliminary. The official position from both state and federal agencies is that the investigation is ongoing and conclusions remain subject to change. That caveat is genuine; early attribution in industrial control system incidents has been revised before, and investigators have also noted the possibility that a threat actor deliberately mimicked Iranian tradecraft to inflame tensions during an already active geopolitical conflict. Still, the weight of intelligence and technical evidence is pointing in one direction.
U.S. intelligence agencies have assessed that Iran was likely behind a coordinated cyberattack on more than 30 municipal water systems in Minnesota this week, according to several U.S. officials, as a five-month-old military conflict between the United States and Iran threatens to escalate.
The suspected operational group is CyberAv3ngers, a known Iranian state-linked threat actor. First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber-Electronic Command division (IRGC-CEC). Its first sustained campaign came in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them with anti-Israel messages. Tenable said CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the U.S., Israel, the United Kingdom, and Ireland as part of that campaign. The U.S. Treasury Department sanctioned the group in February 2024.
The July 22, 2026, update to CISA Advisory AA26-097A expanded the scope of observed PLC exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation, documented project file exfiltration for the first time, and added detection guidance for manipulation of reusable code modules embedded in PLC programs. CVE-2021-22681 (CVSS 9.8), a critical authentication bypass in Rockwell Automation Logix controllers with no available vendor patch, was added to CISA's Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors.
That update was issued four days before the Minnesota attacks began. Three days before the Minnesota attacks, the Handala threat group—attributed to Iran's Ministry of Intelligence—issued explicit warnings that U.S. water, electricity, and transportation networks would be targeted. The warning was public. The attack followed on schedule.
Tenable's Scott Caveza, senior staff research engineer, was direct about the technical alignment: "The tactics mirror the group's known capabilities: exploiting internet-facing PLCs and native vendor engineering software to bypass authentication and extract project files. The timing of the attack, which occurred days after an update to a CISA advisory warning of active Iranian targeting of U.S. water sector PLCs, is also indicative of a possible Iranian connection. Unlike financially motivated actors whose attacks might spillover into OT environments, Iranian state-directed groups like CyberAv3ngers specifically target the OT environment. They invest in understanding PLC protocols, use the same vendor engineering tools as legitimate operators, and build purpose-specific capabilities."
The geopolitical context adds weight. The U.S. entered open armed conflict with Iran on February 28, 2026. A ceasefire took effect in April. Iranian cyber operations against U.S. critical infrastructure have continued and escalated since. The Minnesota attacks were not a random probe. They were timed, targeted, and consistent with a multi-year campaign that the U.S. government has been formally tracking, warning about, and—until now—watching happen to smaller utilities in other states.
The government response: state and federal
MNIT activated its statewide incident response capabilities immediately upon learning of the attacks and coordinated across a broad interagency coalition. MNIT is working closely with the Minnesota Department of Public Safety, Bureau of Criminal Apprehension's Minnesota Fusion Center, Minnesota Department of Health, Minnesota Pollution Control Agency, U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. Environmental Protection Agency, Federal Bureau of Investigation, and local water utilities throughout the response.
Minnesota's Chief Information Security Officer, John Israel, issued a statement that acknowledged both the severity of the attack and the value of the state's preparedness: "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response. MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."
CISA confirmed it is observing a significant increase in threat actors targeting PLCs. Acting Director Nick Anderson confirmed the agency's active involvement in the investigation and coordination with water sector utilities nationwide.
The FBI and EPA issued a joint public service announcement on July 30—FBI PSA I-073026-PSA—confirming the seven-state scope of the campaign and issuing specific technical guidance to utilities: disconnect internet-facing PLCs, place them behind secure gateways and firewalls, require strong authentication, and limit inter-device communications to authorized sources through access control lists.
At the political level, the attack broke into open confrontation on July 31. David Sacks, White House AI and tech adviser, used the attacks to frame the broader national security case for AI investment and infrastructure hardening. Congressional members from Minnesota's delegation have called for emergency federal funding for municipal water utility cybersecurity, particularly for small and rural communities.
Braham's mayor, Nate George, stated the problem as clearly as any policy document could: "Minnesota's local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals." A city of 1,700 people, with a public works team of a handful of employees and a technology budget sized for routine operations, is now expected to defend its water supply against the Iranian Revolutionary Guard Corps.
Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including programmable logic controllers. Many of these PLCs were connected directly to the internet—not through secure VPNs or industrial firewalls, but via cellular modems purchased for the convenience of remote monitoring and never hardened after installation. The attack didn't require a sophisticated zero-day exploit; it required finding equipment that was connected to the internet with default or weak credentials, which automated scanning tools do in minutes.
John Bruggeman, virtual CISO at CBTS, put the stakes plainly: "Attackers are targeting operational technology environments that are publicly exposed, and the concern is not just exposed information, but whether the attackers can gain control of the technology—before security teams can contain it."
The gap between what small municipalities can afford to do and what nation-state adversaries are capable of is not a gap that any individual city can close on its own. Minnesota's Whole-of-State Cybersecurity Program—the framework that allowed MNIT to rapidly coordinate response across state, local, tribal, and federal partners—is one of the more mature examples of how states can try to bridge it. It worked in this instance. It did not prevent the attack.
The OT/IT convergence risk is no longer theoretical. Water utilities connected their operational technology to the internet for legitimate operational reasons: remote monitoring, reduced site visits, faster response times. That connectivity created the attack surface that made this campaign possible. Any organization running industrial control systems, building automation, or other OT environments that have internet-facing components for remote access should be reviewing those exposures immediately.
The CISA advisory was a countdown, not a warning. CISA Advisory AA26-097A was updated on July 22, four days before the attacks. It named the threat actors, described the tactics, and listed the specific devices being targeted. Utilities that read that advisory and disconnected their internet-facing PLCs before July 26 were protected; those that didn't were hit. Intelligence-driven action has a short window, and this incident documents in operational terms what it looks like when that window closes.
CVE-2021-22681 has no patch and is being actively exploited. The critical authentication bypass in Rockwell Automation Logix controllers—CVSS 9.8, no available vendor patch—was added to CISA's Known Exploited Vulnerabilities catalog in March 2026. If your organization runs Rockwell Automation Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 series, and those devices have any internet-facing exposure, that is the immediate operational priority.
Geopolitical conflict has a direct OT security timeline. The February 2026 U.S.-Iran military conflict, the April ceasefire, and the continued escalation of Iranian cyber operations are not background context—they are a predictive signal for defenders. When the U.S. enters a conflict with a nation-state that has a documented history of targeting water utilities, electric grids, and transportation networks, the attack surface for those sectors expands immediately and measurably.
The water was safe. That is true and it matters. The successful use of stored water, manual procedures, and contingency plans prevented a more serious emergency.
But the stated goal of the attack was contamination, not disruption. The mechanism—dropping pipe pressure to create conditions for back-siphonage—is a real and documented risk. The attacks in other states did produce boil-water advisories. Minnesota avoided that outcome by approximately 90 minutes in Braham's case, and through manual intervention by public works employees who were, by luck and good instinct, in a position to respond quickly.
The public should understand that the systems delivering water to their taps are increasingly networked, that the operators of those systems are often small municipal departments with limited cybersecurity resources, and that nation-state adversaries are actively targeting those systems with the specific goal of reaching the water supply. That is not a reason for alarm—Braham's operators demonstrated that manual procedures work. It is a reason to follow local emergency management guidance, know how to reach your local water utility, and understand that "no boil-water advisory has been issued" and "water is safe" are statements that can change.
For residents in communities affected by this attack or future ones: follow your local utility's guidance. If an advisory is issued, boil water before drinking, cooking, or brushing teeth. Do not assume the faucet is safe if your utility is communicating about a water system incident.

