KEMETIC MINDS
National Security & Cybersecurity | July 31, 2026
Federal investigators are examining whether Iran was behind a coordinated cyberattack that hit more than 30 community water systems across Minnesota the week of July 26-30, 2026. No water supply was compromised and no boil-water notices were issued — but the attack exposed how exposed small water utilities still are, and it landed in the middle of an active U.S.-Iran military conflict. Here is what actually happened, what officials have and haven’t confirmed, and what it does and doesn’t mean for your tap water.
Photo by K via Pexels · Photo by Sergey Sergeev via Pexels · AI image generated with Sana (via pollinations.ai)
What Actually Happened
Starting the weekend of July 26, more than 30 municipal water and wastewater systems across Minnesota reported malicious cyber activity hitting the programmable logic controllers (PLCs) — the small industrial computers that remotely monitor and run pumps, valves, wells and lift stations[1]. Several cities have gone public:
- Plymouth — compromised PLCs found at two water towers and 14 sewer lift stations Sunday evening; crews switched to manual operation and had normal communications restored by Tuesday afternoon.
- Braham — a well system malfunctioned Monday; backup restored service within 90 minutes.
- South St. Paul — detected an issue Monday and moved to manual operations; officials said no resident data was accessed.
- Maple Plain — also confirmed it was hit, though it did not release the same level of detail as the other cities.[2]
State officials confirmed more than 30 systems total but declined to name all of them, citing state law. Federal agencies said the same pattern of PLC targeting has now turned up in at least seven states beyond Minnesota[1].
Your water is safe.
Minnesota’s Bureau of Criminal Apprehension stated plainly: “None of Minnesota’s water supply has been reported compromised as a result of the attack.” No boil-water notices are in effect, and Minnesota IT Services confirmed there are no active requests for residents anywhere in the state to change how they use their water[2]. The attackers got into the control systems that operators use to monitor and adjust equipment — not the treatment process itself — and every affected city caught it and switched to manual operation before service was disrupted.
Who Investigators Think Did It — And What They’re Not Yet Saying
The FBI, EPA and Cybersecurity and Infrastructure Security Agency (CISA) are investigating, with Minnesota’s BCA Fusion Center coordinating between municipalities and federal partners. The Washington Post reported that U.S. intelligence agencies now suspect Iran was behind the attack[3]. But that is an assessment, not a confirmed finding: the FBI has said only that it is aware of the intrusions, without assigning responsibility, and Minnesota IT Services said it is “not attributing this activity to a specific threat actor at this time,” deferring the question to federal partners[2].
Investigators are also weighing a second possibility worth taking seriously: that whoever did this deliberately mimicked known Iranian tactics to manufacture the appearance of a state-linked attack and stir up geopolitical alarm[1].
The Group Investigators Are Looking At: CyberAv3ngers
Security researchers at Tenable point to CyberAv3ngers, a hacking group widely assessed to be linked to Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber-Electronic Command[4]. This isn’t the group’s first run at American water infrastructure:
- In November 2023, the same group compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, and defaced them with anti-Israel messages — part of a campaign that hit at least 75 Unitronics Vision Series controllers across the U.S., Israel, the U.K. and Ireland by exploiting factory-default passwords that operators never changed.
- Since then, the group has built out more capable malware (tracked as IOCONTROL) and started using ordinary remote-access tools like TeamViewer and AnyDesk to slip past security controls, while targeting equipment from Rockwell Automation, Allen-Bradley, Schneider Electric and Siemens.[4]
Experts quoted in the coverage note that small and rural water utilities are the “lowest-hanging fruit” in critical infrastructure — most don’t have a dedicated cybersecurity staff and don’t segment their business network from the operational systems that actually run pumps and valves, so one weak password can expose the whole plant.
The Federal Warning That Came Just Before This
This didn’t come out of nowhere. CISA had already updated Advisory AA26-097A on July 22 — four days before Minnesota’s attacks began — warning that Iranian-affiliated actors were exploiting internet-exposed PLCs across U.S. critical infrastructure, and expanding the warning beyond Rockwell Automation devices to include Schneider Electric and Siemens equipment. The advisory described attackers pulling PLC project files out of victim systems and manipulating code to disable safety functions[5].
After Minnesota, CISA Director Nick Anderson put the guidance to utilities bluntly: “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”[1] The advisory’s fuller recommendations for utility operators include[5]:
- Disconnect internet-exposed PLCs entirely, or put them behind a secure gateway with multifactor authentication
- Physically set controller mode switches to “Run” so logic can’t be remotely rewritten
- Segment IT networks from operational technology networks
- Audit for undocumented cellular modems vendors may have installed, which routine scans can miss
- Keep offline backups of PLC configurations
- Watch for connections from foreign IP addresses on industrial-protocol ports
Why the Timing Matters
This is landing in the middle of an active military conflict between the United States and Iran that has been running since February 2026[6]. Tenable’s writeup of the CISA advisory notes that Iranian-linked exploitation techniques have proliferated well beyond a single state-run team — more than 60 affiliated hacktivist groups are now said to be operating through a shared “Electronic Operations Room,” which is part of why attribution here is harder than pointing to one actor[5]. Minnesota Sen. Amy Klobuchar has requested a formal briefing from CISA and said she is in contact with state officials about what resources are available to affected cities[2].
What Americans should actually take from this:
- Your water is safe. Multiple officials on the record confirmed no water supply was compromised and no boil-water advisories are in effect anywhere in Minnesota.
- This is not confirmed to be Iran. It’s the leading working theory among U.S. intelligence agencies, but the FBI and CISA have not made a formal attribution as of publication.
- This is a national pattern, not a Minnesota-only event. Federal agencies say similar PLC targeting has shown up in at least seven states.
- The vulnerability is old and well-documented. The same group is suspected of doing nearly the same thing to a Pennsylvania water utility in 2023 — this is a known gap in small-utility cybersecurity, not a new kind of attack.
- If you work for or sit on the board of a small utility — water, electric, or otherwise — CISA’s advisory above is the checklist to hand to whoever manages your operational technology.
Kemetic Minds Analysis
The most important fact in this story isn’t attribution — it’s that more than 30 water systems in one state could be touched by the same class of attack in the same week, and every single one of them was only saved by an operator noticing and flipping a system to manual. That’s not a Minnesota problem or an Iran problem; it’s the state of cybersecurity at thousands of small public utilities across the country that have never had the budget for it. Whether this specific incident turns out to be Iran, an Iran-aligned hacktivist crew, or someone borrowing Iran’s playbook to cause panic during an active war matters for foreign policy. It changes nothing about what every water utility in America should already be doing: getting these controllers off the open internet.
References
- CBS News. (2026, July 30). U.S. investigating whether Iran was behind cyberattack on Minnesota water systems. cbsnews.com ↩a ↩b ↩c ↩d
- KSTP 5 Eyewitness News. (2026, July 30). Cyberattack on over 30 Minnesota water systems may be linked to Iran. kstp.com ↩a ↩b ↩c ↩d
- The Washington Post. (2026, July 30). U.S. spy agencies suspect Iran launched cyberattack on Minnesota water facilities. washingtonpost.com ↩
- The Register. (2026, July 29). Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems. theregister.com ↩a ↩b
- Tenable. (2026, July). Minnesota Water Cyber Attack and CISA Advisory AA26-097A: What You Need to Know. tenable.com ↩a ↩b ↩c
- ABC News. (2026, July 30). Feds issue warning to local water systems over increased cyberattacks, following Minnesota incident. abcnews.com ↩
Methodology: Every fact in this piece is sourced to on-the-record reporting from CBS News, The Washington Post, The Register, KSTP (local Minnesota coverage), ABC News, and Tenable’s technical breakdown of CISA Advisory AA26-097A. As of publication, no U.S. agency — not the FBI, CISA, or Minnesota’s Bureau of Criminal Apprehension — has formally attributed the attack to Iran; that remains an active assessment, and this piece treats it as such throughout rather than stating it as settled fact.
📱 Stay Connected

