Coordinated Cyberattacks on US Municipal Water Systems: PLC Exploitation Hits Minnesota and 6 Other States in July 2026

Coordinated Cyberattacks on US Municipal Water Systems: PLC Exploitation Hits Minnesota and 6 Other States in July 2026

Executive Summary

In the week of July 31, 2026, a series of coordinated cyberattacks targeted at least 30 municipal water facilities in Minnesota, with similar incidents reported in at least six other states. These attacks prompted urgent advisories from the FBI, Environmental Protection Agency (EPA), and Cybersecurity and Infrastructure Security Agency (CISA), highlighting the ongoing threat to critical water infrastructure across the United States. The attackers exploited internet-facing programmable logic controllers (PLCs), changing device IP addresses and passwords to lock out legitimate operators, resulting in operational disruptions such as loss of monitoring and control, and in some cases, boil water notices and a shift to manual operations. No evidence of water contamination or data exfiltration has been reported. While attribution remains unconfirmed, multiple officials and technical patterns suggest possible involvement of Iranian-linked threat actors. The incident underscores the urgent need for improved security controls, segmentation, and monitoring within the water and wastewater sector.

Technical Information

The July 2026 cyberattacks on US municipal water systems represent a significant escalation in the targeting of operational technology (OT) within critical infrastructure. The attackers focused on remotely accessible, internet-facing PLCs—devices that control and monitor water treatment and distribution processes. By exploiting exposed PLCs, the attackers were able to change device IP addresses and passwords, effectively locking out legitimate operators and causing a loss of visibility and control over affected systems.

The technical tactics observed align with several MITRE ATT&CK techniques. Initial access was achieved through exploitation of public-facing applications (T1190) and external remote services (T1133), as attackers leveraged the lack of segmentation and direct internet exposure of PLCs. Once inside, the attackers escalated privileges and maintained persistence by manipulating valid accounts (T1078) and changing credentials (T1098). The operational impact included resource hijacking (T1496) and service stop (T1489), resulting in the need for manual operations and, in some cases, boil water notices.

No specific malware or tool names have been disclosed in public advisories or news reports as of July 31, 2026. The attacks appear to have relied on direct manipulation of control systems rather than the deployment of custom malware. This approach is consistent with previous campaigns attributed to Iranian-linked actors, who have historically targeted US critical infrastructure, including water and wastewater systems, as part of broader geopolitical cyber operations.

The attacks highlight several sector-specific vulnerabilities. Many water utilities operate legacy OT environments that were not designed with modern cyber threats in mind. The lack of network segmentation, insufficient access controls, and the continued exposure of critical devices to the public internet significantly increase the risk of successful cyberattacks. Experts emphasize the need for a layered resilience strategy, including stronger network segmentation, continuous monitoring, offline recovery options, and sustained investment in hardening OT environments.

Attribution for the July 2026 attacks remains unconfirmed. While multiple US officials and technical patterns suggest possible Iranian involvement, no direct technical evidence (such as malware samples or forensic artifacts) has been made public. The FBI, EPA, and CISA have focused their advisories on mitigation and defense rather than attribution, urging all water utilities to take immediate action to secure their systems.

Affected Versions & Timeline

The attacks occurred on Sunday and Monday of the week of July 31, 2026, with federal advisories and public disclosures issued on July 31, 2026. At least 30 municipal water facilities in Minnesota were confirmed to be affected, with similar incidents reported in at least six other states. The specific brands and versions of PLCs targeted have not been publicly disclosed, but advisories indicate that multiple vendors' devices may be at risk due to common exposure and configuration weaknesses.

The timeline of events is as follows: initial attacks were detected in Minnesota, prompting state and federal agencies to issue warnings and advisories. The Wisconsin Department of Natural Resources issued a bulletin indicating that systems within Wisconsin may be susceptible to similar attacks, though no confirmed breaches were reported in that state at the time. The FBI and EPA subsequently issued a nationwide advisory, emphasizing the need for immediate action by all water and wastewater utilities.

Threat Activity

The threat activity observed in this campaign is characterized by targeted exploitation of internet-facing PLCs and associated control systems. Attackers remotely accessed these devices, changed IP addresses and passwords, and locked out legitimate operators. This resulted in a loss of monitoring and control capabilities, triggered alarms, and, in some cases, led to boil water notices and a shift to manual operations.

The tactics used are consistent with those observed in previous campaigns attributed to Iranian-linked threat actors, particularly the focus on OT environments and the use of credential manipulation to maintain access and disrupt operations. However, as of July 31, 2026, no formal attribution has been made, and the investigation is ongoing.

The attacks did not result in water contamination or data exfiltration, according to statements from Minnesota officials and federal agencies. The primary impact was operational disruption, highlighting the potential consequences of cyberattacks on critical infrastructure even in the absence of direct physical harm.

Mitigation & Workarounds

Mitigation efforts should be prioritized as follows:

Critical: Immediately remove all PLCs and other control systems from direct internet exposure. Place these devices behind secure gateways and firewalls to prevent unauthorized remote access.

High: Implement strong, unique passwords for all control system devices and regularly update credentials. Limit communications between authorized control system devices using access control lists.

High: Conduct a comprehensive review of remote access capabilities. Where remote access is necessary, require the use of a secure VPN or gateway device, and enforce multi-factor authentication.

Medium: Increase network segmentation between IT and OT environments to limit lateral movement in the event of a breach. Regularly audit network configurations and access controls.

Medium: Establish and test offline recovery options to ensure continued operations in the event of a cyber incident. Maintain up-to-date backups of critical system configurations.

Low: Provide ongoing cybersecurity training for staff responsible for OT environments, emphasizing the risks associated with internet exposure and credential management.

All mitigation steps should be validated and tailored to the specific operational context of each utility. Federal and state advisories should be closely monitored for updates and additional guidance.

Indicators of Compromise

No public indicators of compromise were available at the time of writing. Utilities are advised to monitor for unusual remote access activity, unauthorized credential changes, and unexpected loss of monitoring or control capabilities.

References

NBC News, July 31, 2026: https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210

ABC News, July 31, 2026: https://abcnews.com/amp/US/investigators-iran-connection-minnesota-water-system-hacks-us/story?id=135237777

About Rescana

Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor cyber risks across their supply chain and critical infrastructure partners. Our platform enables continuous visibility into vendor security posture, supports rapid incident response, and facilitates compliance with sector-specific regulatory requirements. For questions or further information, contact us at info@rescana.com.