Someone turned off the taps, metaphorically speaking. Between July 28 and July 31, 2026, malicious cyber actors targeted water and wastewater utilities across at least seven US states, forcing some facilities to abandon digital controls entirely and revert to manual operations.

Minnesota bore the heaviest damage, with disruptions reported across more than 30 municipal water systems.

What happened and who is responsible

The FBI and the Environmental Protection Agency issued a joint advisory on the attacks, flagging the incidents as unusual for one specific reason: no ransom demands were made.

Federal investigators are exploring links to Iranian-backed hackers, citing identifiable tradecraft patterns consistent with prior Iranian cyber operations. Attribution has not been formally confirmed, and investigators say evidence collection is ongoing.