A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
July 30, 2026
A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don't appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota's IT Services (MNIT) unit.
The attacks come days after the US Cybersecurity and Infrastructure Security Agency (CISA) updated a warning from earlier this year about Iran-affiliated threat groups targeting programmable logic controllers (PLCs) and other Internet-connected OT devices at critical infrastructure organizations across the US, including water systems. The advisory specifically identified PLCs from Rockwell Automation/Allen Bradley, Schneider Electric, and Siemens as being of interest to the attackers, while warning that any Internet-exposed PLC could be a potential target.










