AI-generated illustration

Hackers Hit More Than 30 Minnesota Water Utilities, but Officials Say Drinking Water Stayed Safe

Over two days — Sunday, July 26, and Monday, July 27, 2026 — hackers broke into the control systems of more than 30 community water systems across Minnesota, changed passwords and network settings, and locked operators out of the equipment that runs wells, pumps and treatment plants. It was a coordinated attack. Minnesota IT Services (MNIT), the state agency leading the response, says the incidents share similarities in timing and the technology targeted — and that in every confirmed case, drinking water quality was not affected.

The story has since grown well beyond Minnesota. The FBI (Federal Bureau of Investigation) and EPA (Environmental Protection Agency) said in their July 30 alert that water utilities in at least seven states had reported incidents — the count as of that alert, not necessarily today’s. Federal agencies have issued back-to-back warnings to the entire water sector, and President Trump and Governor Tim Walz are publicly at odds over who is to blame.

Key facts

  • More than 30 Minnesota community water systems were hacked over July 26–27, 2026.
  • MNIT says drinking water quality was not affected in any confirmed case in Minnesota, and that no boil-water advisories were issued there because of the attack.
  • Only four communities have confirmed disruptions publicly: Braham, Plymouth, South St. Paul, and Maple Plain.
  • Attackers targeted internet-facing controllers, mainly Rockwell Automation’s Allen-Bradley MicroLogix 1100 and 1400 series.
  • No ransom demand has been reported.
  • The FBI and EPA say utilities in at least seven states reported incidents; no one has been publicly attributed, arrested, or charged as of August 4.

How the hackers got in

The attackers went after a specific weak point: programmable logic controllers, or PLCs — the small industrial computers that switch pumps and valves on and off. Many utilities connect them to the internet so staff can monitor equipment remotely. According to a joint FBI and EPA alert, the attackers remotely accessed internet-facing devices, mainly one manufacturer’s controllers: Rockwell Automation’s Allen-Bradley MicroLogix 1100 and 1400 series. Once in, they changed the devices’ IP addresses and passwords, cutting operators off from monitoring and control. Several utilities switched to running their systems by hand. How the attackers first broke into those controllers — beyond the fact that the devices were reachable from the open internet — has not been publicly explained.

MNIT’s John Israel put the aim plainly: “All signs are pointing to disruption, not trying to get a financial gain.” One of those signs is what did not happen — no ransom demand has been reported.

Which Minnesota cities were affected

Four communities have publicly confirmed disruptions:

  • Braham, where a well and the water treatment plant went offline for about two hours on the morning of Monday, July 27 — by the city’s account, from about 9:34 to 11:30 a.m. — before public works staff brought them back. The city said there was no physical damage and no impact on water quality.
  • Plymouth, where cellular-connected equipment at two water towers and several lift stations was disconnected.
  • South St. Paul, where automated controls were affected but service continued.
  • Maple Plain, which declared a local state of emergency.

The full list of the more than 30 affected systems has not been made public.

Is the water safe to drink?

Officials say yes. MNIT says drinking water quality was not affected in any confirmed case, no boil-water advisories were issued because of the attack, and residents have not been asked to change how they use their water. One honest limit on that reassurance: only four of the more-than-30 affected communities have said anything publicly, so it rests on the state’s account and those four towns — none of which reported a drinking-water-quality problem.

Why are regulators still treating the threat seriously, then? Because of what this kind of attack could do, not what it has done here. In their nationwide warning, the FBI and EPA said utilities around the country have reported operational effects including loss of pressure and flooding — and a loss of pressure can potentially let untreated groundwater seep into pipes. That is the national picture, not a Minnesota finding. Nothing like it has been confirmed to have tainted water in Minnesota.

It did not stop at Minnesota

In their July 30, 2026 public alert, the FBI and EPA said that since July 27, water and wastewater utilities in at least seven states had reported incidents, and that some of that activity degraded water operations. The agencies did not name the states. Separately, Michigan has confirmed that nine of its municipal water systems reported activity consistent with the federal warnings.

The federal response

Around the same time, the Cybersecurity and Infrastructure Security Agency (CISA) made a second federal move: it urged water and wastewater operators to take publicly exposed PLCs off the internet as soon as possible, citing a significant increase in attacks on the devices.

The warnings did not come out of nowhere. Back in April 2026, CISA published a joint advisory, AA26-097A, warning that Iranian-affiliated hackers had been exploiting internet-connected PLCs across the U.S. water, energy and government sectors — initially Rockwell devices, and reportedly Schneider Electric and Siemens equipment as well. CISA updated that advisory on July 22, 2026. Four days after that update, the Minnesota intrusions began. Even so, no official source has tied the Minnesota attacks to that campaign.

For utilities, the FBI and EPA’s advice boils down to two things: get the controllers off the open internet and behind a firewall, and keep the ability to run systems by hand.

Who did it?

Officially, no one knows yet. No government body has publicly attributed the attack to any actor, no group has claimed responsibility, and as of August 4 no one had been arrested or charged.

U.S. officials speaking anonymously have described a preliminary assessment that Iran-linked hackers were probably responsible, pointing to the attackers’ methods and the absence of a ransom demand — but they cautioned the assessment could change, and that another actor could be trying to falsely implicate Iran. None of it has hardened into a finding. The state agency is more cautious still: MNIT says it has not determined who was responsible, and has not even established that all of the incidents were carried out by the same actor — only that they share similarities in timing and the technology targeted.

The political fight

President Trump rejected the Iran reporting at a July 31 Cabinet meeting and instead pinned the blame on Minnesota itself, calling the state “grossly incompetent.” He offered no evidence. Governor Walz pushed back and pointed to federal cybersecurity budget cuts as a contributing factor. Senator Amy Klobuchar said National Cyber Director Cairncross had told her that, at that point, there were no effects on services. The reassurance came secondhand — and it sits next to the FBI and EPA’s warning that operational effects in other states have included loss of pressure and flooding.

Timeline

  • April 2026 — CISA publishes joint advisory AA26-097A, warning that Iranian-affiliated hackers had been exploiting internet-connected PLCs across U.S. water, energy and government sectors.
  • July 22, 2026 — CISA updates that advisory.
  • Sunday, July 26, 2026 — Hackers begin breaking into control systems at more than 30 Minnesota community water systems.
  • Monday, July 27, 2026 — Intrusions continue; Braham’s well and treatment plant go offline from about 9:34 to 11:30 a.m. before staff restore access.
  • July 30, 2026 — FBI and EPA issue a joint alert reporting incidents at water utilities in at least seven states.
  • July 31, 2026 — President Trump blames Minnesota at a Cabinet meeting; Governor Walz pushes back publicly.

What happens next

The investigation is active and continuing. MNIT is working with state and federal partners, including the FBI, CISA, the EPA and the Minnesota Department of Health, on investigation, recovery and hardening the state’s water systems — and no official has declared the campaign over. Nor has anyone said publicly whether every one of the 30-plus utilities has regained full control of its systems — Braham was back up within about two hours, but there has been no statewide all-clear. Two questions are still open: who did it, and whether more states will report the same thing.

Sources and further reading

Share this article