U.S. intelligence and law enforcement agencies are investigating whether Iran-backed hackers orchestrated a coordinated cyberattack that hit operational technology at more than 30 municipal water systems across Minnesota, forcing several utilities to briefly switch to manual operations without disrupting public drinking water supplies.
Federal authorities and intelligence officials are probing a digital assault that struck critical infrastructure across at least seven states, with Minnesota emerging as one of the primary targets. The incident began over the weekend of July 26 and 27, 2026, when malicious cyber actors targeted programmable logic controllers used by local water operators.
Federal Probes and the Iran Connection
U.S. spy agencies and law enforcement have tentatively assessed that Iran was likely behind the coordinated breach, according to officials familiar with the ongoing investigation. The assessment remains preliminary while investigators await deeper forensic evidence from the affected systems. U.S. officials are also evaluating whether the hackers might have attempted to mask their origins or mimic an Iran-based actor to ratchet up geopolitical tensions amid the ongoing five-month military conflict between the United States and Iran.
Security experts note that Iran possesses both the geopolitical motive and a documented history of targeting water and critical infrastructure facilities. Cynthia Kaiser, senior vice president at Halcyon’s Ransomware Research Center and former deputy assistant director of the FBI’s cyber division, pointed out that Iran has the most motive here still to do it
for disruption rather than financial gain.
Federal agencies including the FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency issued warnings highlighting that malicious actors were actively scanning and targeting internet-exposed operational technology within the water sector.
Local Impacts Across Minnesota Municipalities
While more than 30 community water systems were compromised by malicious activity, state officials emphasized that no public drinking water supplies were contaminated or compromised. Minnesota IT Services reported that the intrusions primarily affected remote monitoring and control equipment, causing isolated pressure losses and flooding in some jurisdictions before operators intervened.
- In Braham, public works personnel discovered that the well supplying the city’s water tower had been shut off by the intrusion.
- Maple Plain was among the cities notified that they were impacted.
State officials confirmed that as of Thursday afternoon, no active requests had been issued asking residents to alter or restrict their drinking water consumption.
Vulnerabilities in Critical Infrastructure
The cyberattack underscores long-standing vulnerabilities within municipal utilities. Cybersecurity analysts note that local water and wastewater facilities frequently lack the financial resources, staffing, and advanced software patching mechanisms common in other critical sectors. This operational gap makes internet-exposed industrial control devices attractive targets for foreign adversaries seeking to sow panic and test defensive boundaries.

Minnesota’s Chief Information Security Officer, John Israel, noted that the state shared technical data with federal partners to evaluate the incidents within a broader national context. Since learning of this activity, we have assessed its impact, identified methods of access and worked with local partners to better protect Minnesota systems,
Israel stated.
Congressional Response and Ongoing Investigation
Federal lawmakers have stepped up scrutiny following the breach. U.S. Senator Amy Klobuchar announced she requested a formal briefing from the Cybersecurity and Infrastructure Security Agency to examine the investigation and potential foreign actor involvement.

“I’ve requested a briefing from the Cybersecurity and Infrastructure Security Agency on the ongoing investigation and the potential involvement of foreign actors. I’m also in communication with state officials to help make sure they have the resources they need. Protecting our critical infrastructure and the safety of Minnesotans remains a top priority.”
Senator Amy Klobuchar, U.S. Senate
Investigators continue to collect forensic artifacts across the affected states, and federal agencies have reiterated guidance urging municipal operators to audit remote access configurations and disconnect vulnerable programmable logic controllers from direct internet exposure.
Worth a look