The small city of Braham, Minnesota – population just under 1,500 – had its water treatment plant go completely offline on the night of July 26, 2026. Residents were asked to minimize water use while operators worked to bring the system back manually. What happened in Braham was not an isolated outage caused by aging pipes or a power failure. It was a deliberate intrusion – one piece of a coordinated water systems cyberattack that simultaneously targeted more than 30 municipalities across the state.
The full scale of what was unfolding took days to become clear. Cyberattacks targeting municipal water systems were reported in at least seven states, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers were trying to disrupt critical water infrastructure. By the time federal agencies issued formal warnings, Wisconsin had already alerted its water operators, and multiple states were scrambling to assess whether their own systems had been touched.
The hacks were not complicated: the attackers were breaking into PLCs that were sitting online and vulnerable. PLCs – programmable logic controllers – are the small industrial computers that tell pumps when to run, monitor water pressure, and manage valves at treatment facilities. Most residents have never heard of them. That obscurity is part of the problem.
What Happened in Minnesota – and How Fast It Spread
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul, and Maple Plain all publicly described a plant outage, communications failures, or affected automated controls. Braham’s water plant went offline, and the city asked residents to minimize water use until treatment resumed.
Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually. South St. Paul and Maple Plain maintained services after automated utility controls were affected. In Maple Plain, Mayor Julie Maas-Kusske declared a local state of emergency and implemented crew responses to restore the water systems.
The attack prompted Minnesota IT Services to activate a statewide cybersecurity incident response involving local, state, and federal agencies. That response quickly expanded beyond state lines. Roughly six states reported related cyber incidents over the following week. Officials in Wisconsin detected malicious cyber activity at their water facilities and urged utilities to take “immediate action to prevent potentially serious impacts to our systems,” according to a memo from the state’s Department of Natural Resources obtained by CNN. The FBI and EPA confirmed the scope had widened further: water and wastewater utilities in at least seven states had reported incidents since July 27, with some activity degrading operations.
The Specific Equipment the Hackers Targeted
The FBI’s public service announcement named the specific equipment targeted: Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers manufactured by Rockwell Automation – internet-facing industrial computers that manage pumps, valves, and pressure monitoring at water facilities.
Threat actors targeting exposed PLCs modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity resulted in boil-water notices and sustained manual operations. At some facilities, the intrusion went deeper than a simple lockout. In at least one victim organization, attackers modified the PLC project files themselves – the software logic governing how the physical equipment behaves.
The vulnerability at the center of many of these intrusions had been known for years. CVE-2021-22681, a critical authentication bypass affecting Rockwell Automation Logix controllers, carries no available vendor patch. It was added to CISA’s Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated threat actors. A July 2026 update to a CISA advisory also expanded the scope of targeted devices to include Schneider Electric and Siemens PLCs alongside Rockwell Automation hardware. The attack surface, in other words, is not limited to one manufacturer.
3. How Hackers Were Able to Get In

The entry method required no sophisticated spycraft. These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes were advised to validate their external connections, since the targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.
The EPA warned that many water systems had critical vulnerabilities including outdated software, poor network security, weak access controls, and a lack of employee cybersecurity training. Many of these systems were never designed to be internet-connected. As utilities added remote monitoring and cellular communications over the years for efficiency, they inadvertently exposed industrial equipment that was built for a pre-internet era.
Minnesota’s chief information security officer, John Israel, put it plainly after the first wave of intrusions. He told CNN he suspected the attackers would “continue to look nationally across the infrastructure,” adding that hackers would “continue to rattle those doorknobs and try to break into systems that have weak configurations.” That prediction proved accurate within days.
Who Is Behind the Attacks
A preliminary report by American investigators suggested that Iranian hackers were probably responsible for the cyberattack, while stressing that their assessments could change. The pattern fits a recent track record. Iranian-affiliated hacking groups had previously targeted PLCs at water facilities in the United States, and the specific vulnerability exploited in March 2026 was confirmed to have been used by Iranian-linked actors before the Minnesota attacks began.
Authorities in the United States continued to monitor developments following the cyberattack targeting dozens of community water systems, with Minnesota IT Services – the state agency for information technology – confirming more than 30 systems were affected. Attribution in cyberattacks is rarely simple, and officials were careful not to declare Iran definitively responsible while the investigation remained active.
President Trump offered a different read at a cabinet meeting. According to CNN’s reporting, he blamed Minnesota authorities for the compromised systems and dismissed an Iran connection, saying the country had “bigger problems than worrying about Minnesota.” The New York Times had first reported the possible Iran link. As of the time of publication, no government agency had formally and definitively attributed the attacks.
The Federal Response – and Its Limits
CISA, the FBI, and the EPA spent the better part of a week scrambling to help secure the affected water facilities and ensure that drinking water safety wasn’t compromised. On July 30, 2026, the FBI and EPA issued a joint public service announcement warning water and wastewater utilities nationwide of the coordinated attacks.
CISA confirmed it was observing a significant increase in cyber threat actors targeting PLCs in the water and wastewater sector, urging critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. CISA acting director Nick Andersen stated: “CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities. We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”
The federal response, though rapid, arrived against a backdrop of pre-existing institutional gaps. A GAO review found that, as of 2024, the EPA had not performed key cybersecurity risk management steps for the water and wastewater sector. Under the Trump administration, CISA lost approximately one-third of its workforce through cuts, layoffs, and reassignments, including the elimination of its counter-ransomware initiative and portions of its critical infrastructure protection programs. The agency had also been operating without a Senate-confirmed permanent director since January 2025.
Years of Warnings That Went Unheeded
The events of late July 2026 did not emerge without warning. The EPA’s own data showed the problem festering long before the Minnesota attacks. In 2025, the EPA identified cybersecurity vulnerabilities at 277 water systems and directly eliminated 350 vulnerabilities. That same EPA assessment found that many systems were still running outdated software with no clear remediation plan.
A 2026 GAO report on water sector cybersecurity found that the water sector remains one of the most cyber-vulnerable U.S. critical infrastructure sectors due to widespread under-resourcing, legacy operational technology systems, and persistent exposure of remote access pathways. Funding disparities between large urban utilities and small rural ones make uniform security standards nearly impossible to enforce. A municipality of 1,500 people like Braham does not have a dedicated cybersecurity team.
The Iran-linked attack on a water facility in Aliquippa, Pennsylvania, in late 2023 – where hackers exploited a default password on an internet-facing controller – should have accelerated upgrades across the sector. Threat actors affiliated with the Iranian Government Islamic Revolutionary Guard Corps had carried out malicious cyberattacks against United States critical infrastructure, including drinking water systems, targeting and disabling common operational technology used at water facilities. The 2026 attacks used a strikingly similar method. The door that was left open in 2023 was still open three years later.
Read More: Iran-Linked Hackers Target U.S. Infrastructure
What Was Actually at Risk – and What Wasn’t
No incidents of contamination were reported from any of the affected systems. That outcome was partly the result of manual failsafes kicking in – operators at Plymouth and South St. Paul switched to manual operations and kept water flowing. It was also partly luck: the attackers appear to have focused on disrupting access and operations rather than manipulating treatment chemistry.
The stated goal, according to a memo from the Minnesota Bureau of Criminal Apprehension cited by CNN, was to cause loss of system pressure – which, in a worst case, can allow contaminants to enter water lines through backflow. That contamination scenario did not materialize. The activity did result in boil-water notices and sustained manual operations at some facilities.
Cybersecurity specialist Gus Serino, speaking to CNN, described the scale and coordination of the attacks on Minnesota water suppliers as “unprecedented.” The fact that no one was harmed does not mean the vulnerability has been resolved. The PLCs that were exposed on July 26 remain a risk at thousands of facilities across the country that have not yet removed their equipment from public internet access.
What This Means for You

The drinking water that comes out of your tap passes through industrial control systems that, in many American communities, have the same level of internet security as a home Wi-Fi router with the default password still set. The July 2026 water systems cyberattack made that concrete rather than theoretical. Thirty-plus Minnesota systems were disrupted in a single weekend. Seven states were affected within days.
Federal advisories now call on system operators to remove PLCs from direct internet exposure by placing them behind secure gateways and firewalls, use strong passwords, and limit communications between authorized control system devices through access control lists. Those are baseline steps that should have been standard practice years ago. If you want to know whether your local utility has taken them, most water systems serving over 10,000 people are required to submit cybersecurity assessments to the EPA – those records can be requested through your state’s public records process. For smaller systems like Braham’s, attending a city council meeting and asking directly remains the most reliable option.
AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.
Read More: RFK Jr. Finally Tells Parents to Vaccinate as Measles Hits a 35-Year High





