---
title: "A Coordinated Cyberattack Hit More Than 30 Minnesota Water Systems. Officials Suspect Iran"
description: "Attackers disrupted control systems at water utilities in more than 30 Minnesota communities over two days, briefly taking one treatment plant offline. Drinking water was never affected. Officials describe Iranian involvement as likely, not confirmed."
category: "U.S."
category_url: https://herald.la/category/us
author: "Tyler Grant"
published: 2026-07-30T22:53:20.000Z
updated: 2026-07-30T22:53:20.000Z
canonical: https://herald.la/article/a-coordinated-cyberattack-hit-more-than-30-minnesota-water-systems-officials-sus
tags: ["cybersecurity", "water", "critical-infrastructure", "iran", "minnesota"]
---
# A Coordinated Cyberattack Hit More Than 30 Minnesota Water Systems. Officials Suspect Iran

Attackers disrupted control systems at water utilities in more than 30 Minnesota communities over two days, briefly taking one treatment plant offline. Drinking water was never affected. Officials describe Iranian involvement as likely, not confirmed.

Water utilities in more than 30 Minnesota communities were disrupted by a
coordinated cyberattack on Sunday and Monday, the state announced Tuesday. No
drinking water was contaminated and no boil-water notices were issued, but the
episode is among the broadest attacks on U.S. water infrastructure to become
public.

## What happened

The attacks hit operational technology, the equipment that runs pumps and valves,
rather than office computers. In Braham, a city of about 1,700, the water plant
went offline after what the city described as
[a malicious cyberattack on its computerized operating systems by unknown actors](https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/).
Crews restored service within roughly two hours by operating manually.

In Plymouth, a Minneapolis suburb of about 80,000, the targets were equipment
connected by cellular links at two water towers and several lift stations. The
city's IT division disconnected the affected equipment from the network to stop
the attack. Officials in both cities said the water remained safe and that
residents did not need to change their consumption.

Minnesota IT Services is leading the response, working with the state health and
public safety departments, a state fusion center, and federal agencies including
the Cybersecurity and Infrastructure Security Agency, the EPA and the FBI. John
Israel, the state's chief information security officer, said the whole-of-government
response had worked as intended.

## How confident is the attribution

Less than the headlines suggest, and officials have been careful about it. State
and federal officials
[have characterized Iranian involvement as likely rather than established](https://www.washingtonexaminer.com/policy/technology/4669373/iran-cyberattack-minnesota-water-systems/),
and cautioned that the assessment could change as technical evidence is collected.
No formal attribution had been announced as of Thursday.

Outside researchers have pointed in the same direction. Analysts
[suspect the group known as CyberAv3ngers](https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/5280357),
which U.S. authorities have tied to the Islamic Revolutionary Guard Corps, based
on the pattern of the operation: disruption rather than extortion, aimed at small
utilities with exposed industrial controllers. The reasoning is inference from
method, not evidence of who typed the commands.

Officials also acknowledged the possibility, which they consider unlikely, that
another actor was posing as an Iranian group.

## The precedent

CyberAv3ngers is not a new name. In late 2023 the group compromised programmable
logic controllers at the Municipal Water Authority of Aliquippa, Pennsylvania,
part of a campaign against Unitronics devices that reached utilities in several
countries, largely by exploiting default passwords. In February 2024 the Treasury
Department sanctioned six IRGC cyber officials over those operations, and the
State Department posted a reward for information leading to their arrest.

The vulnerability is structural. Small water systems run industrial equipment that
was designed for reliability rather than for exposure to the internet, and they
run it with staff counted in single digits and no dedicated security budget. The
Aliquippa breach and the Minnesota attacks both hit that same soft layer.

## The California question

California's utilities sit in the same position. In June, a separate group
claiming Iranian affiliation said it had breached customer billing systems at
California Water Service, which serves communities across the state. That claim
concerns business IT rather than the systems that treat water, which is a
meaningful distinction, but the exposure it points to is the same one Minnesota
just demonstrated at scale.

## Sources

- [Coordinated cyberattack disrupts water utilities in 30 Minnesota communities](https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/)
- [Coordinated cyberattack hits more than 30 Minnesota water utilities](https://www.helpnetsecurity.com/2026/07/30/minnesota-water-utilities-coordinated-cyberattack/)
- [Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems](https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/5280357)
- [Officials say Iran was likely behind cyberattack targeting Minnesota water systems](https://www.washingtonexaminer.com/policy/technology/4669373/iran-cyberattack-minnesota-water-systems/)

