What Happened
Between Sunday evening, July 26, and Monday morning, July 27, 2026, malicious cyber activity disrupted technology at more than 30 community water systems across Minnesota, forcing utilities in South St. Paul, Braham, and Plymouth to switch to manual operations. The Minnesota Information Technology (MNIT) agency released an advisory Tuesday, July 28, confirming coordination with the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Environmental Protection Agency (EPA). By Thursday, July 30, CISA acting director Nick Anderson stated the agency is "currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities" and urged immediate removal of publicly exposed PLCs and operational technology from the internet. Federal authorities reported loss of monitoring and control functionality at critical infrastructure sites in at least seven states, leading to pressure loss and flooding in some cases. No Minnesota water supply has been reported compromised, and resident data access has not been detected, according to Mike Ernster of the Minnesota Department of Public Safety.
What the Evidence Establishes
Investigators have identified similarities in the timing of incidents and the types of technology impacted — specifically internet-exposed programmable logic controllers used for remote monitoring and control of water equipment. In Plymouth, compromised PLCs at two water towers and fourteen sewer lift stations were disconnected from cellular networks Sunday evening; normal communications were restored by Tuesday afternoon. Braham public works personnel discovered a malfunctioning well pump Monday, isolated the affected system, restored a backup, and restarted the plant within 90 minutes. South St. Paul implemented contingency procedures early Monday, transitioning to manual operations without service interruption. Federal agencies confirmed that Iran-linked hackers, specifically actors affiliated with the Islamic Revolutionary Guard Corps, used a similar playbook in 2023, exploiting internet-connected controllers that retained default passwords to access multiple water and wastewater facilities. CISA's Thursday advisory explicitly noted that targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented in routine attack surface scans.
Where the Accounts Conflict
U.S. officials and sources familiar with the investigation tell CBS News they are probing whether Iranian hackers are behind the activity, but sources cautioned that attribution is not definitive and assessments could change as additional technical evidence is collected. Investigators are also examining whether the actor could have attempted to appear Iran-based as a false flag operation amid ongoing U.S.-Iran tensions. Minnesota and the federal government have not publicly attributed the activity to a particular actor. The FBI and EPA stated the issue extends beyond Minnesota to "at least seven states" but did not identify the affected states. Minnesota investigators identified similarities in timing and technology impacted but had not confirmed that every incident was carried out by the same actor. The tension between operational urgency — CISA's call for immediate PLC removal — and evidentiary caution on attribution creates a gap between defensive guidance and public accountability.
Context and Stakes
The 2023 IRGC-linked campaign established a precedent: Iranian state-affiliated actors successfully exploited default credentials on internet-exposed PLCs across multiple U.S. water utilities, demonstrating both capability and intent to target civilian critical infrastructure. The current campaign's scale — over 30 Minnesota systems plus incidents in six additional states — suggests either an expansion of that playbook or a separate actor emulating it. CISA's advisory highlights a systemic vulnerability: cellular modems installed by third-party vendors or integrators often fall outside documented attack surfaces, creating blind spots even for organizations with mature cybersecurity processes. The Water and Wastewater Systems sector, designated as critical infrastructure under Presidential Policy Directive 21, comprises approximately 153,000 public drinking water systems and 16,000 wastewater treatment systems nationwide, many operated by municipalities with limited cybersecurity resources. A successful manipulation of water treatment processes could pose direct public health risks, while pressure loss and flooding cause immediate operational and financial damage.
What to Watch Next
CISA's directive to remove publicly exposed PLCs from the internet within days will test municipal compliance capacity; many small utilities lack dedicated IT staff and rely on vendor-managed connections. The FBI and EPA's joint investigation across at least seven states may produce a joint attribution statement within 30-60 days, following historical patterns for critical infrastructure intrusions. Iran's response to any public attribution — whether denial, acknowledgment, or escalation — will signal intent. The 2023 campaign did not result in public sanctions; a repeat attribution without consequences could embolden further activity. Congress may revisit the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) implementation timeline, currently set for final rulemaking in 2025, to mandate faster reporting for water sector incidents. Water Information Sharing and Analysis Center (WaterISAC) threat bulletins and vendor advisories for PLC manufacturers (including Rockwell Automation, Schneider Electric, and Siemens) should be monitored for indicator-of-compromise releases.
Bottom Line
A coordinated cyber campaign has compromised internet-exposed programmable logic controllers at over 30 Minnesota water utilities and systems in at least six other states, forcing manual operations but not contaminating water supplies. Tactical similarities to the 2023 IRGC-linked intrusions — exploitation of default credentials on internet-connected PLCs — make Iranian attribution plausible but unconfirmed; false-flag possibilities are under active investigation. CISA's emergency directive to remove all publicly exposed PLCs and operational technology from the internet addresses the immediate attack vector but exposes a structural gap: undocumented cellular modems installed by third parties. The incident demonstrates that the water sector's attack surface remains broadly vulnerable three years after the first major IRGC campaign, and that attribution caution, while analytically sound, delays public accountability and deterrence signaling.
DECLASSIFIED SOURCE: The Hill - News (via Real-time Signal Upgrade)
No comments yet. Start the conversation.