WASHINGTON: Hackers have launched a coordinated wave of cyberattacks against water and wastewater utilities across the United States, forcing some systems offline, triggering boil-water notices and exposing how fragile the digital controls behind the world’s drinking water have become.
Federal officials confirmed that water utilities in at least seven U.S. states have reported cyber incidents since late July, in what analysts describe as one of the most serious cyberattacks on American water systems in years. The FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency (EPA) have spent the past week helping secure water facilities. No water contamination has been reported.
What happened
The first public signs of the attack emerged from Minnesota, where state authorities said more than 30 community water systems were targeted in a “coordinated cyberattack” over the night of Sunday, July 26, through Monday, July 27. Four cities publicly confirmed attacks:
- Braham (population ~1,700): unknown malware disabled the computerized operating controls at the water plant, leaving the city’s water tower unable to be refilled for more than an hour. Public works crews restored the plant within roughly two hours.
- Plymouth (population ~80,000): IT staff disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the attack and prevent retargeting. The city switched to manual operations.
- South St. Paul: also forced to operate its water system manually.
- Maple Plain: Mayor Julie Maas-Kusske declared a local state of emergency and deployed crews to restore service.
Minnesota’s chief information security officer, John Israel, later confirmed that about 36 municipal water systems in the state were affected. The attacks then spread. The FBI said utilities in at least seven states reported incidents, including Wisconsin, where officials urged utilities to take “immediate action,” and Michigan, where hackers altered settings on wastewater equipment. In South Dakota, the city of Rapid City said one of its wastewater lift stations was targeted; it isolated the systems and said drinking water and public safety were unaffected.
How the attacks worked
Investigators say the attackers targeted internet-facing programmable logic controllers (PLCs), the industrial computers that monitor water pressure, chemical dosing and other functions that keep drinking water safe. The intrusions were described as “not complicated”: hackers broke into PLCs left exposed online, often with default or no passwords.
- Changed passwords to lock operators out of their own systems
- Altered device IP addresses, cutting monitoring and control capabilities
- Disconnected devices from networks entirely
The “likely desired impact” of the intrusions, according to a Minnesota Bureau of Criminal Apprehension memo obtained by CNN, was “to cause loss of system pressure and subsequent potential contamination of water supply.” The FBI said some victims reported operational effects including lost water pressure and flooding in certain locations. CISA warned that hackers “are targeting water entities of all sizes.”
Who is responsible
No formal attribution has been made, and officials caution the assessment is preliminary. The New York Times reported that investigators reviewing the attacks believe Iranian-linked hackers were probably responsible, a finding that comes amid the escalating 2026 war between the United States and Iran. Investigators stressed the report is preliminary and subject to change, and U.S. officials also warned of the risk of false flags.
President Donald Trump, at a cabinet meeting Friday, blamed Minnesota authorities for the hack and cast doubt on whether Iran was involved: “They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”
The timing fits a documented pattern. A joint advisory from CISA, the FBI and the NSA, issued in April 2026, documented Iranian-affiliated actors exploiting internet-exposed Rockwell Automation (Allen-Bradley) PLCs to cause disruptions across government services, water and wastewater, and energy sectors. The advisory was updated July 22, 2026, days before the Minnesota attacks, to add Schneider Electric and Siemens devices and document project-file exfiltration for the first time.
“Water systems have enjoyed the benefits of remote access, but now those who wish us harm have it, too.”
Joshua Corman, co-founder, I Am The Cavalry
The federal response
- CISA alert (July 30): warned of a “significant increase” in threat actors targeting PLCs in the Water and Wastewater Systems sector, and urged utilities to remove vulnerable equipment from the internet as soon as possible.
- FBI / EPA warning (July 30): confirmed incidents at utilities in about seven states and noted some activity had degraded water operations.
- CISA guidance: disconnect PLCs, access systems only through VPNs, replace default passwords, and allow access only from known engineering laptops. CISA specifically flagged undocumented cellular modems installed by operators or vendors as a risk.
- WaterISAC, the water sector’s threat-sharing hub, urged utilities to shore up their systems, calling the scale and coordination of the Minnesota attacks “unprecedented.”
Why it matters beyond the U.S.
The attack is a global wake-up call. Water and wastewater utilities in Africa, South Asia and the Middle East are particularly vulnerable, experts say, because many have leapt from manual systems to highly digital ones in a very short time, installing remote monitoring and automated controls without corresponding cybersecurity investment.
In Kenya, cyber threat intelligence firms have already documented ransomware groups, including Qilin, RansomHub and Lynx, showing growing interest in East African critical infrastructure, with energy and water utilities among the sectors targeted between 2025 and 2026. Kenya’s National KE-CIRT, alongside sector regulators, has repeatedly urged operators of essential services to harden their systems.
The lesson from the U.S. incidents applies to utilities everywhere: if you cannot protect an internet-connected control system, take it offline until it can be secured.
If you run a water utility, an energy plant, or any critical service in Africa, audit your exposure today
This campaign is the clearest proof yet that industrial control systems are in attackers’ crosshairs, and that many operators are unknowingly exposing PLCs and SCADA interfaces to the open internet, sometimes with default credentials.
Start with three questions: Is any control equipment reachable from the internet? Are default passwords still in use? Who has remote access, and through what? VUNVAULT runs external attack-surface mapping and OT/IT assessments to answer exactly these questions before an attacker does.
Key facts at a glance
| First attacks | July 26 to July 27, 2026 |
|---|---|
| Initial target | 30+ community water systems in Minnesota (~36 confirmed) |
| Current scope | Utilities in at least 7 U.S. states |
| Method | Exploiting internet-exposed programmable logic controllers (PLCs) |
| Effects | Boil-water notices, manual operation, lost pressure, flooding in some areas |
| Contamination | None reported |
| Suspected actor | Iranian-linked hackers (preliminary, unconfirmed) |
| Response | CISA alert, FBI/EPA warning, WaterISAC advisory, ongoing federal investigation |
Note: This is a developing story. Attribution and impact figures are based on preliminary reporting and may change as the federal investigation progresses. Article first published by VUNVAULT, August 3, 2026.