U.S. Probes Cyberattack On Minnesota Water Systems For Possible Iran Link
U.S. investigators are probing whether Iran was behind a cyberattack on more than 30 Minnesota community water systems discovered Monday, July 27, 2026.[1]
The attack targeted remote-monitoring and control technology, including programmable logic controllers, forcing some utilities to switch to manual operations without disrupting water service.[1]
The Cybersecurity and Infrastructure Security Agency (CISA) warned of a significant increase in cyber actors targeting programmable logic controllers at water utilities and urged removing publicly exposed operational technology from the internet.[1]
The FBI is aware of the incident and has been in contact with affected utilities, while Minnesota's Fusion Center is coordinating with local, state and federal partners.[1] Investigators are probing whether the attacker is Iran-based or merely spoofing an Iran link, but they have not yet formally attributed the incident.[1]
Show source details & analysis (1 source)
📌 Key Facts
- Malicious cyber activity affected technology at more than 30 community water systems across Minnesota discovered on Monday, July 27, 2026.
- Investigators are probing whether the attacker is Iran-based or spoofing an Iran link but have not yet formally attributed the incident.
- The attack targeted remote-monitoring and control technology, including programmable logic controllers, forcing some utilities to switch to manual operations without disrupting water service.
- CISA warned of a significant increase in cyber actors targeting PLCs at water utilities and urged removal of publicly exposed operational technology from the internet.
- The FBI is aware of the incident and in contact with victims, while Minnesota’s Fusion Center is coordinating with local, state and federal partners.
📰 Source Timeline (1)
Follow how coverage of this story developed over time