Minnesota IT Services says a "coordinated cyberattack" targeted more than 30 community water systems on July 26-27. Officials report unauthorized access with malicious intent but say no cities have asked residents to change water use. The FBI is involved and investigators note similarities to prior Iran-linked intrusions. CISA advisories in April and July warned that attackers were targeting PLCs from Rockwell, Schneider Electric and Siemens, raising concerns about potential physical impacts.
Coordinated Cyberattack Strikes 30+ Minnesota Water Systems; Officials Investigate Possible Iran-Linked Intrusions

State IT officials in Minnesota say a "coordinated cyberattack" targeted more than 30 community water systems on July 26 and July 27, according to a statement from Minnesota IT Services.
What Officials Are Saying
Minnesota IT Services said it was not aware of any active city requests asking residents to change their drinking water usage. Local media had earlier reported that four Minnesota cities issued notices about cyber intrusions on their networks.
"The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure," Minnesota IT Services spokesperson Emily Zimmer said in an email to Reuters. She added investigators found "unauthorized access with malicious intent" and therefore described the incidents as "attacks."
Federal Response and Background
The FBI said it is aware of the incidents and is communicating with victims to help resolve the matter. The Cybersecurity and Infrastructure Security Agency (CISA) did not respond to a request for comment for this report.
While formal attribution has not been announced, the incidents resemble prior intrusions into U.S. water infrastructure that U.S. authorities and analysts have previously linked to Iranian-affiliated actors.
On April 7, CISA issued an advisory warning that Iranian-affiliated hackers were targeting internet-facing programmable logic controllers (PLCs) produced by Rockwell Automation. A July 22 update broadened that advisory to include devices from Schneider Electric and Siemens, and potentially other vendors.
"CISA's updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States," Joe Slowik, director of threat research and cyber engineering at Dataminr, wrote in a July 27 blog. He warned that expanding access to more equipment lines and combining it with process manipulation or safety degradation increases the risk of real-world physical impacts.
Implications and Next Steps
The incidents underscore persistent vulnerabilities in local utilities that serve millions of people. Minnesota IT Services and federal partners are continuing their investigation. Residents should follow guidance from local authorities and utilities; at the time of the agency statement, there were no active requests to change water usage.
Reporting: This article is based on reporting by AJ Vicens and additional reporting by Raphael Satter, with editing by Sanjeev Miglani.
Help us improve.




























