Since July 26-27, 2026, cyberattacks have targeted over 30 community water systems in Minnesota and at least nine systems in Michigan, with incidents reported in seven US states overall, disrupting water operations and requiring manual controls in some cases [1, 2, 3, 4]. Hackers infiltrated water and wastewater facilities by exploiting internet-connected operational technology, specifically programmable logic controllers (PLCs). They changed IP addresses and passwords, which disrupted monitoring and control functions vital to water system operations [1, 3, 4].
The cyberattacks caused a range of operational effects, including loss of water pressure, flooding events, boil water advisories, and forced water utilities to switch to manual operation modes [1, 3, 4]. Michigan officials reported that while nine water systems were targeted, “all systems continued to operate safely following the attacks,” according to Dale George, Director of Communications for Michigan’s Department of Environment, Great Lakes and Energy [2].
Federal agencies including the FBI, EPA, CISA, and NSA have issued multiple warnings urging water system operators to disconnect controllers from the internet, strengthen authentication methods, control network access, and maintain manual operations capability [1, 2, 5, 6, 3, 4]. A statement from the FBI said the agency “and our interagency partners are fully engaged to protect critical infrastructure, and we remain well-equipped to protect against cyber threats of all varieties” [2].
U.S. officials and cybersecurity reports attribute the attacks to hacking groups linked to Iran, though definitive attribution remains under investigation [1, 3, 4]. Iranian cyber activity targeting U.S. water infrastructure predates recent tensions but has intensified amid ongoing missile exchanges between the countries [1, 5, 6]. In April 2026, the EPA, FBI, CISA and NSA jointly issued an urgent advisory about Iranian-affiliated threats aimed at water and wastewater operational technology [5, 6].
Water utilities in the U.S. remain vulnerable due to outdated industrial control systems and weak cybersecurity practices. The EPA reports that 70% of federally inspected water utilities fail to meet cybersecurity standards [5, 6]. In March 2024, EPA Administrator Michael Regan and White House National Security Advisor Jake Sullivan urged states to implement cybersecurity plans protecting water infrastructure. Regan and Sullivan noted, “Drinking water and wastewater systems are an attractive target for cyberattacks because they are a lifeline critical infrastructure sector but often lack the resources and technical capacity to adopt rigorous cybersecurity practices” [5].
Investigations into the Minnesota attacks are ongoing. State officials have reported no current threats to water safety but confirmed some systems needed to be manually reset after being taken offline [1, 2]. The Cybersecurity and Infrastructure Security Agency issued a public warning about the increased cyberattacks on water systems on July 30, 2026 [1].