The bottom line: The first distributed cyberattack on multiple U.S. water systems indicates a coordinated Iranian campaign targeting programmable logic controllers, potentially linked through shared infrastructure or a systems integrator.
In July, Iranian cyber actors conducted a coordinated attack on more than 30 water supply systems in Minnesota. Experts assess the operation as a turning point: for the first time, attackers targeted multiple independent utilities across a wide geographic area that shared a common technical vulnerability.
Between July 26 and 27, cyber actors attacked over 30 water systems in Minnesota. Affected municipalities reported that drinking water remained safe and disruptions were limited. The city of Braham (approximately 1,700 residents) shut down portions of its water supply for just under two hours. Plymouth disconnected mobile equipment connections at two water towers and several wastewater pumping stations. South St. Paul experienced disruptions to automated controls, and Maple Plain declared a local state of emergency.
The attack came immediately after CISA, FBI, NSA, and EPA issued an expanded warning: Iranian cyber actors are increasingly targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. CISA Director Nick Andersen warned of “a significant increase in cyber actors attacking PLCs at water utilities” and urged operators to immediately remove publicly exposed PLCs and other operational technology from the internet.
What is new is the coordination across numerous utilities. Markus Mueller, Field CISO at Nozomi Networks, sees this as evidence of escalation: “This is the first distributed attack on water utilities. It was clearly aimed at disruption, not financial gain.” Experts suspect that the selection of targets was based on shared technical infrastructure—possibly a systems integrator, communications architecture, or other connecting factors that collectively made the geographically distributed utilities vulnerable. Rockwell Automation systems are also in the focus of investigations.
For CISOs, this incident underscores the need to remove PLCs and operational technology from publicly accessible networks, identify common vulnerabilities in the supply chain, and establish coordinated warning mechanisms with neighboring critical infrastructure operators. Incident reporting to CISA is considered essential to fully capture the scope and patterns of such campaigns.
Source: www.csoonline.com · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.