Cyberattacks targeting U.S. water systems prompt renewed focus on utility cybersecurity

A series of cyberattacks targeting municipal water systems across the Midwest disrupted automated controls but maintained water safety, prompting federal and state investigations into potential nation-state involvement.

Key Highlights

  • Over 30 Minnesota water systems were targeted, with some experiencing temporary shutdowns of treatment plants due to cyberattacks on operational technology.
  • Most utilities managed to continue operations manually, demonstrating the importance of operational redundancy and emergency response planning.
  • Federal agencies, including the FBI and CISA, are investigating the incidents, which may be linked to Iranian-affiliated cyber activity targeting critical infrastructure.

A coordinated wave of cyberattacks targeting municipal water systems across the Midwest has renewed concerns about the cybersecurity of U.S. drinking water and wastewater infrastructure, even as utilities report that public health and water quality were not compromised.

More than 30 community water systems in Minnesota were targeted during a two-day campaign in late July, according to Minnesota IT Services. The attacks affected operational technology used to monitor and control water infrastructure, prompting state and federal agencies to launch a coordinated response.

Several Minnesota communities experienced coordinated cyberattacks that temporarily disrupted automated water and wastewater systems.
July 28, 2026

Among the affected utilities, the city of Braham reported that attackers temporarily disabled computerized operating controls, shutting down its well and water treatment plant until operators restored service. Other communities, including Plymouth, South St. Paul and Maple Plain, reported disruptions to automated controls or communications but maintained water and wastewater operations through manual procedures. Officials in each community said drinking water remained safe and no contamination occurred.

The incidents have since expanded beyond Minnesota. Michigan officials recently disclosed that nine water systems in the state also experienced cyberattacks, although operators maintained safe service and no public health impacts were reported. The FBI, the U.S. Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency (CISA) are investigating the incidents alongside state agencies.

Operational technology remains a target

The attacks primarily targeted operational technology (OT) systems, including remote monitoring and programmable logic controllers (PLCs) used to manage pumps, wells, lift stations and water towers, rather than enterprise information technology systems. Federal officials have warned that internet-connected industrial control equipment continues to present an attractive target for nation-state actors and cybercriminals, particularly at smaller utilities with limited cybersecurity resources.

While investigators have not publicly attributed the attacks, federal officials are examining whether they are connected to previously identified Iranian-affiliated cyber activity targeting critical infrastructure. Authorities caution that the investigation remains ongoing and no official attribution has been announced.

Manual operations limit service disruptions

Although the cyberattacks disrupted portions of automated control systems, most affected utilities were able to continue operations by switching to manual control procedures. The incidents underscore the importance of maintaining operational redundancy and emergency response plans alongside investments in cybersecurity.

Federal agencies have advised water utilities to review remote access practices, disconnect unnecessary internet-exposed control systems, implement multifactor authentication and ensure operators can safely transition facilities to manual operation if automated systems are compromised.

The recent attacks are the latest reminder that cybersecurity has become a core component of utility resilience. As drinking water and wastewater systems continue adopting digital monitoring, automation and remote operations, utilities face growing pressure to strengthen cyber defenses while ensuring reliable service and protecting public health.

This piece was created with the help of generative AI tools and edited by our content team for clarity and accuracy.

About the Author

Alex Cossin

Associate Editor

Alex Cossin is the associate editor for Waterworld Magazine, Wastewater Digest and Stormwater Solutions, which compose the Endeavor Business Media Water Group. Cossin graduated from Kent State University in 2018 with a Bachelor of Science in Journalism. Cossin can be reached at [email protected].

Sign up for our eNewsletters
Get the latest news and updates