More than 30 community water systems in Minnesota were targeted in a coordinated cyberattack in late July, raising fresh concerns about the security of critical U.S. infrastructure. The attacks reportedly disrupted computerized controls at several facilities, with some operators temporarily switching to manual systems while authorities investigated the incident.
U.S. officials and cybersecurity researchers suspect the Iran linked hackers may be responsible for the Minnesota attacks, although the Iranian government has not publicly acknowledged involvement. The incidents come as tensions between Washington and Tehran remain extremely high, adding another layer of concern to a cyber campaign that officials say has been targeting American infrastructure for months.
Minnesota Water Systems Hit in Coordinated Attack
The Minnesota cyberattack took place on July 26 and 27 and affected more than 30 community water systems across the state. Some facilities experienced operational disruptions, although state officials said there was no evidence that drinking water quality had been compromised and no boil water advisories were issued as a result of the attacks.
In Braham, a community of roughly 1,700 people, an attack disrupted the computerized controls of the city’s well and water treatment plant. Local crews were able to restore operations within about two hours. In Plymouth, officials disconnected cellular connected equipment at water towers and wastewater lift stations as a precaution, while Maple Plain declared a local state of emergency to strengthen its response.
The attacks focused on technology used to operate water infrastructure, including programmable logic controllers and the computer interfaces used by employees to monitor and manage equipment. These systems can be essential to controlling pumps, treatment processes, pressure and other functions, meaning disruptions can force facilities to rely on manual procedures until their digital systems are secured.
The incidents came shortly after the Cybersecurity and Infrastructure Security Agency, or CISA, updated a warning about Iran affiliated actors targeting internet connected industrial control equipment. The updated guidance expanded the range of potentially targeted devices to include equipment made by major manufacturers such as Rockwell Automation, Schneider Electric and Siemens.
Security researchers have pointed toward the Iran linked group CyberAv3ngers as a possible suspect. The group has previously been associated with attacks against industrial control systems, and researchers have said the timing and techniques observed in Minnesota appear consistent with the broader campaign described by U.S. authorities.
Growing Concerns Over Critical Infrastructure Security
The Minnesota attacks are part of a wider pattern of cyber activity targeting U.S. critical infrastructure. Earlier warnings from federal agencies described incidents in which Iran linked actors allegedly compromised programmable logic controllers and interfered with industrial processes. In some cases, attackers were able to manipulate system settings or interfere with safety functions, potentially creating dangerous operating conditions.
Federal officials have increasingly warned that water and wastewater facilities are particularly vulnerable because the sector is highly fragmented. The United States has more than 150,000 public drinking water systems, and the vast majority are small facilities serving fewer than 10,000 people. Many smaller operators have limited cybersecurity resources and may not have dedicated personnel to monitor sophisticated cyber threats.
The situation has also attracted attention because the latest attacks occurred against the backdrop of escalating conflict between the United States and Iran. Cyber operations have increasingly become part of broader geopolitical confrontations, with critical infrastructure often viewed as a potential target because disruptions can affect communities even when physical facilities are not directly damaged.
CISA has urged water and wastewater operators to take immediate steps to reduce their exposure, including removing vulnerable industrial control devices from the public internet where possible. Authorities have also warned that attackers may attempt to change passwords, lock legitimate operators out of systems or disconnect equipment, potentially forcing facilities into prolonged manual operation.
For Minnesota communities, the immediate impact appears to have been contained, but the incident highlights a much larger challenge facing the United States. Water infrastructure is essential to public health and everyday life, yet many facilities operate with limited budgets and aging technology. Protecting these systems against sophisticated, potentially state linked attackers will require stronger cybersecurity practices, better monitoring and greater investment.
The investigation into the Minnesota cyberattack is continuing, and attribution has not been publicly established as a definitive finding. However, the suspected involvement of Iran linked hackers demonstrates how geopolitical tensions can increasingly reach local communities through attacks on essential infrastructure. As federal and state authorities work to strengthen defenses, the Minnesota incident could serve as another warning that cybersecurity is now an essential part of protecting America’s water supply.




