Cyberattack hits water systems in at least seven states as feds probe possible Iran connection

By 
, July 31, 2026 
Category:

Malicious cyber activity forced water utilities in at least seven states to switch to manual operations this week, and federal investigators are now examining whether Iran is behind the breach, even as President Trump publicly disputes that theory.

The FBI, the Cybersecurity and Infrastructure Security Agency, and the Environmental Protection Agency issued a joint warning Thursday that hackers are targeting internet-exposed industrial controllers used by water and wastewater systems across the country. More than 30 community water systems in Minnesota alone lost remote monitoring and control capability after attackers compromised programmable logic controllers, the small computers that automate pumps, valves, and chemical treatment at municipal plants. Some sites reported pressure loss and flooding before operators could intervene.

The FBI confirmed incidents in at least seven states but declined to name them. Minnesota is the only state publicly identified so far. The bureau's press release offered no attribution, and investigators told CBS News that the question of who carried out the attack remains open. Sources cautioned that attribution has not been definitively established. One possibility under review: the attacker may have tried to appear Iran-based as a way of creating confusion amid the ongoing U.S. conflict with Iran.

Minnesota bore the heaviest documented blow

Minnesota IT Services said most confirmed cases involved technology used to remotely monitor and control water system equipment, including PLCs. Three cities, South St. Paul, Braham, and Plymouth, offered detailed accounts of what happened on the ground.

In Plymouth, a suburb of Minneapolis, Director of Public Works Michael Thompson told CBS News his team first noticed trouble Sunday evening when communication between devices started to drop. By just after midnight Monday, the situation was all-hands-on-deck. Attackers had compromised PLCs at two water towers and 14 sewer lift stations. The city disconnected the affected systems from its cellular network and moved to manual operations. Normal communications were not restored until Tuesday afternoon.

"I think you never expect it to happen to you," Thompson said.

South St. Paul identified its own breach early Monday and immediately switched to contingency procedures. Public works employees ran the system by hand. A city spokesperson said the incident was limited to technology supporting portions of its water utility; drinking water treatment, quality, pressure, and delivery were not affected. The city found no indication that resident or customer data had been accessed.

In Braham, a rural town north of Minneapolis, public works personnel discovered Monday that the well supplying the city's water tower had malfunctioned. Mayor Nate George confirmed that workers isolated the compromised system, restored a backup, and restarted the plant in about 90 minutes. The tower typically holds enough drinking water to last roughly two days, and residents experienced no interruption in service.

Mike Ernster, a public information officer for the Minnesota Department of Public Safety, told CBS News that none of Minnesota's water supply had been reported compromised. The Bureau of Criminal Apprehension's Minnesota Fusion Center was working with municipalities and state and federal partners to address the situation. Investigators noted similarities in timing and the types of technology affected across the incidents.

CISA warned utilities to pull controllers offline immediately

Nick Anderson, acting director of CISA, said the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities." The advisory issued July 30 urged critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.

The advisory stressed that the targeting includes "water entities of all sizes", not just large municipal systems. CISA also flagged a risk many operators may not have considered: cellular modems installed by vendors or system integrators that may not be documented or included in routine security scans. Those devices can create an internet-facing entry point that the utility itself does not know about.

The warning carries extra weight because of precedent. Federal agencies previously confirmed that in 2023, actors affiliated with Iran's Islamic Revolutionary Guard Corps accessed multiple water and wastewater facilities by exploiting internet-connected controllers that still used default factory passwords. That episode demonstrated how little effort a hostile actor needs when basic cybersecurity hygiene is neglected.

Trump pointed the finger at Minnesota, not Iran

At a televised Cabinet meeting at Camp David on Friday, President Trump dismissed the Iran theory and blamed Minnesota's state government directly.

"I think that Minnesota is behind it. You know who's behind it? Minnesota. Because they're grossly incompetent. I think the governor's behind it. I don't think there was an Iranian cyberattack. I think that Minnesota ought to get its act together."

He continued:

"They like to say, 'Oh, it was Iran.' Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."

The president's remarks placed blame squarely on Governor Tim Walz, a Democrat who is no stranger to criticism from Trump. Walz fired back on social media. In a post on X, the governor wrote:

"Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."

In a separate post, Walz accused the Trump administration of having "took an axe" to CISA and "left the U.S. exposed to cyber attacks." The full text of that post was not available, but the accusation fits a pattern of Democratic governors blaming federal cuts when state-level systems fail.

Whatever the source of the attack, the political blame game obscures a practical question that matters far more to the people who turn on their taps every morning: why were so many water utilities still running internet-exposed controllers with known vulnerabilities years after the 2023 breaches showed exactly how attackers get in?

Open questions dwarf the available answers

Investigators have not publicly identified which six states beyond Minnesota were hit. They have not disclosed the total number of affected water systems nationwide. No arrests have been announced, and no suspects have been formally named. The technical evidence collected so far, and how far it points toward Iran, another state actor, or a different kind of threat, remains undisclosed.

The scope of the vulnerability is not a mystery, though. CISA's own advisory makes clear that PLCs remain exposed at water systems of every size across the country. Cellular modems that operators may not even know exist are creating entry points for attackers. The policy debate over how to fight back against foreign hackers has been going on for years, and the infrastructure keeps getting hit anyway.

Iran's IRGC exploited default passwords in 2023. Three years later, the same class of equipment at the same class of facility got compromised again. Whether Tehran ordered this latest wave or someone else did, the pattern is the same: critical systems that should never be reachable from the open internet were reachable, and someone walked right in.

The broader Iranian cyber threat is real and well-documented. But so is the failure of local utilities and their state and federal partners to harden the most basic points of entry. A hostile actor does not need a sophisticated exploit when the front door is unlocked.

Meanwhile, the foreign cyber threat landscape is growing more complex by the month. State-backed hackers from multiple countries are probing American infrastructure, and the targets are not military installations or classified networks, they are the water plants that serve small towns and suburbs.

Blame Iran. Blame Minnesota. Blame whoever you want. But the PLCs were on the internet, the passwords were weak, and the water systems went down. That part is not a mystery, it is a choice somebody keeps making.

About Charles McAdams

STAY UPDATED

Subscribe to our newsletter and receive exclusive content directly in your inbox