A single exposed control surface can let one disruptive campaign reach dozens of small water systems at once. The standard response would treat this as a local utility incident, but the real problem is that internet-facing PLCs give attackers a shared way into separate OT environments that were never meant to be managed as one target set.
MNIT says more than 30 Minnesota community water utilities were hit over July 26-27, and reporting now points to a likely Iran-affiliated actor behind the activity. CISA’s updated guidance also puts Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs in scope, and warns that any internet-exposed PLC can be a target.
That changes the containment problem. Even when drinking water and wastewater service keep running, the blast radius now includes manual operation, cross-site response coordination, and the possibility that one weak OT footprint can be used again across many small utilities.
A likely Iran-backed actor targeted over 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
Investigators are chasing two open questions in the coordinated attack on Minnesota water systems: who was behind it, and whether a shared vulnerability in widely used industrial controllers made dozens of small utilities exploitable at once.
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in
Tenable's RSO discusses the coordinated cyber attack disrupting 30+ Minnesota water utilities and 12+ other states, and the July 2026 CISA Advisory AA26-097A
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau.