Cyberattack on Minnesota water systems
Analysis based on 7 articles · First reported Jul 30, 2026 · Last updated Jul 31, 2026
The cyberattack on critical water infrastructure raises concerns about the vulnerability of U.S. utilities to state-sponsored hacking, potentially increasing cybersecurity spending and insurance premiums. However, the lack of confirmed service disruptions and the swift restoration of operations limit immediate market impact, though the incident may heighten scrutiny on industrial control system security.
Over the weekend of July 26-27, 2026, malicious cyber activity affected technology at more than 30 community water systems across United States — Minnesota, forcing some utilities to switch to manual operations. Investigators are probing whether the attacks were carried out by Iranian hackers, possibly linked to the CyberAv3ngers group, but attribution has not been officially confirmed. The attacks targeted programmable logic controllers (PLCs) and human-machine interfaces (HMIs) used to remotely monitor and control water equipment. Affected cities include United States — South St. Paul, Minnesota, United States — Braham, Minnesota, and United Kingdom — Plymouth, where operators transitioned to manual operations or restored backups, with no reported compromise of drinking water quality or delivery. Federal agencies including the FBI, EPA, and CISA issued warnings about increased targeting of water utilities and urged operators to remove exposed PLCs from the internet. The investigation is ongoing, with state and federal partners coordinating response.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard