On 28 July 2026, Minnesota IT Services announced that more than 30 community water systems had been targeted during a coordinated cyberattack on 26 and 27 July, resulting in operational disruptions across several municipalities. Disclosed Minnesota cases include systems from Plymouth (population approximately 80,000) to Braham (population approximately 1,700), illustrating the range of systems affected; full details for the remaining systems have yet to be disclosed. Reports now indicate the attack has expanded to systems across 12 states.
The attacks come shortly after a 22 July update to the Cybersecurity and Infrastructure Agency’s April advisory concerning increased activity from Iranian state-based hackers. The updated advisory provided expanded guidance on vulnerable programmable logic controller targets, including systems from Rockwell Automation, Schneider Electric, and Siemens, and prompted critical infrastructure organizations to follow best practices for cybersecurity, such as restricting internet access for operational systems, changing default passwords, and limiting remote access points.


