Theme:
Light Dark Auto
GeneralPoliticsBusinessEconomyTechnologyEnvironmentScienceSportsHealthEducationEntertainmentLifestyleGeneralNationWorld
ENVIRONMENT
Negative Sentiment

Iran-Linked Hackers Target 30+ Minnesota Water Systems

Read, Watch or Listen

Iran-Linked Hackers Target 30+ Minnesota Water Systems
Media Bias Meter
Sources: 21
Center 100%
Sources: 21

Authorities are investigating a coordinated cyberattack that targeted more than 30 community water systems in Minnesota over the weekend of July 26 and 27. U.S. and state officials believe Iranian-linked hackers are likely responsible, though the assessment remains preliminary. The FBI and Environmental Protection Agency (EPA) issued a joint warning Thursday that "malicious cyber actors" are targeting internet-facing operational technology used by U.S. water and wastewater utilities. The attackers targeted Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), remotely changing IP addresses and passwords. This resulted in the loss of monitoring and control functions at affected facilities. Reported operational effects included pressure loss and flooding. In some cases, hackers locked out operators by changing passwords and disconnected equipment from networks, forcing some systems to switch to manual operation. At least one city asked residents to conserve water for several hours while officials worked to determine the scope of the problem. Minnesota IT Services confirmed Thursday that state officials have not yet identified the specific perpetrators behind the Sunday and Monday attacks. The FBI, which is leading the investigation, has not publicly named a culprit and a spokesperson declined to comment on who the bureau believes might be responsible. However, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and other agencies warned last week that Iranian hackers have been actively targeting water and wastewater systems as well as operational controls in other critical infrastructure sectors. The FBI and EPA urged utility operators to disconnect PLCs from direct internet exposure immediately. They also recommended strengthening authentication measures, strictly controlling network access, and maintaining the ability to operate systems manually in the event of cyber incidents. The agencies warned of a significant increase i

Prepared by Olivia Bennett and reviewed by editorial team.

Timeline of Events

  • · On October 16, 2024, FBI warned Iranian actors compromised critical US infrastructure.
  • · On February 28, 2026, US-Israeli offensive against Iran began in Middle East.
  • · On March 12, 2026, Iranian Handala Hack group hit medical supplier Stryker.
  • · On April 2026, CISA first warned of Iranian PLC attacks on US infrastructure.
  • · On July 22, 2026, CISA, FBI, EPA updated Iran-affiliated threat actor advisory.
  • · On July 26, 2026, coordinated cyberattacks first detected on Minnesota water systems.
  • · On July 27, 2026, attacks continued; Braham water system knocked offline briefly.
  • · On July 29, 2026, Tenable linked attack pattern to Iran-linked CyberAv3ngers group.
  • · On July 30, 2026, NYT reported US officials see Iran as likely behind attack.
  • · On July 31, 2026, CISA urged water utilities to remove PLCs from internet.
  • · On July 30, 2026, FBI confirmed it is investigating but has not attributed.
  • · On July 30, 2026, Minnesota IT Services said no definitive culprit identified yet.
  • · On July 30, 2026, CISA observed significant increase in threats targeting water PLCs.
  • · On July 30, 2026, multiple cities switched to manual operations to maintain service.
  • · On July 31, 2026, AP reported officials warn Iranian hackers targeting water systems.
  • · Attribution to Iran may be formally announced within days.
  • · More states may report similar water system intrusions soon.
  • · Federal mandates for water system cybersecurity upgrades could follow.
  • · Iran-linked cyber activity against US infrastructure is likely to escalate.
  • · Water rates may rise to fund mandatory cybersecurity improvements nationwide.

News Intelligence

Immediate US impact: Foreign hackers disrupted water controls across over 30 Minnesota communities.

Possible long-term US impact: Widespread water system cybersecurity mandates and higher consumer costs expected.

Most affected groups: Rural Minnesota communities, water utility operators, and critical infrastructure agencies.

What readers should prioritise: Official agency updates, not social media speculation about water safety.

Media Bias
Articles Published:
21
Right Leaning:
0
Left Leaning:
0
Neutral:
21

Explain Framing

Left: Emphasizes vulnerability of public infrastructure and need for federal protection. Center: Reports facts: attack occurred, Iran suspected, investigation ongoing, water safe. Right: Highlights national security failure, inadequate local resources, and foreign aggression.

Original Source

Minnesota IT Services disclosed coordinated cyber activity on July 26-27, 2026. https://mn.gov/mnit/media/blog/?id=38-761869

Media Bias
Articles Published:
21
Right Leaning:
0
Left Leaning:
0
Neutral:
21
Distribution:
Left 0%, Center 100%, Right 0%
Explain Framing

Left: Emphasizes vulnerability of public infrastructure and need for federal protection. Center: Reports facts: attack occurred, Iran suspected, investigation ongoing, water safe. Right: Highlights national security failure, inadequate local resources, and foreign aggression.

Original Source

Minnesota IT Services disclosed coordinated cyber activity on July 26-27, 2026. https://mn.gov/mnit/media/blog/?id=38-761869

Coverage of Story:

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET