A coordinated cyberattack hit operational technology at more than 30 Minnesota community water systems on July 26–27, according to Minnesota IT Services. The New York Times reported that water utilities in at least seven states had reported similar incidents to the FBI. Authorities have publicly detailed incidents only in Minnesota and Michigan, where nine systems reported malicious activity. No unsafe drinking water has been reported.
The Cybersecurity and Infrastructure Security Agency (CISA) said attackers in the wider campaign have targeted internet-exposed controllers made by Rockwell Automation, Schneider Electric and Siemens, manipulating passwords, network settings and control logic to disrupt operations, according to advisory AA26-097A, first issued April 7 and updated July 22.
U.S. intelligence agencies assess that Iran was likely responsible for the Minnesota campaign, though the FBI has not made a formal public attribution.
The vulnerability is not specific to Iran. Russian government hackers have penetrated American energy-sector networks, while hackers from North Korea’s military intelligence service have used ransomware against U.S. hospitals and healthcare providers.


