FBI probes 39+ water system cyberattacks across Michigan, Minnesota
A coordinated cyber campaign has struck over 39 water utilities across Michigan and Minnesota, targeting operational technology and triggering an FBI investigation. The incidents follow an FBI/CISA advisory warning that Iranian state hackers are actively probing U.S. water infrastructure, though no attribution has been confirmed. While operations were not disrupted, the attacks expose systemic OT vulnerabilities in a sector with historically weak defenses.
Key Takeaways
- A coordinated cyber campaign has struck over 39 water utilities across Michigan and Minnesota, targeting operational technology and triggering an FBI investigation.
- The incidents follow an FBI/CISA advisory warning that Iranian state hackers are actively probing U.S.
- water infrastructure, though no attribution has been confirmed.
- While operations were not disrupted, the attacks expose systemic OT vulnerabilities in a sector with historically weak defenses.
Mentioned
Key Intelligence
Key Facts
- 1Over 30 water systems in Minnesota were targeted by a cyberattack in the final week of July 2026, compromising operational technology.
- 2Michigan confirmed 9 water systems affected by similar activity after receiving a federal cyber alert on July 28, 2026; all systems remained operational and posed no public health risk.
- 3The FBI, CISA, and other agencies issued an advisory in the prior week warning that Iranian hackers have been targeting water and wastewater systems and other critical infrastructure OT.
- 4The FBI is investigating and has not publicly attributed the attacks, but stated it is 'fully engaged' and 'well-equipped' to protect critical infrastructure.
- 5No known impacts to public health or safety were reported in either state, and local operators addressed the issues quickly.
Who's Affected
The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors. The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties.
Statement on August 1, 2026, responding to the cluster of water system cyberattacks
Analysis
The latest wave of cyberattacks on U.S. water utilities is a chilling escalation in the targeting of operational technology, as adversaries move beyond IT disruption to directly fiddle with the systems that keep communities safe. With over 39 water systems in Minnesota and Michigan reporting intrusions in a single week, and an FBI advisory pointing to Iranian hackers, the incidents signal that the water sector is now a proving ground for state-sponsored groups testing America's critical infrastructure resilience. For CISOs and security engineers, the message is clear: the convergence of IT and OT in under-resourced utilities has opened a new front that demands immediate attention.
A cascading cyberattack has struck critical water infrastructure across two U.S. states, prompting an FBI investigation and elevating concerns over state-sponsored threats to operational technology (OT). In late July 2026, over 30 water systems in Minnesota were compromised, and Michigan subsequently confirmed nine additional systems affected by similar activity. No public health or safety impacts were reported—all systems continued safe operation—but the incidents underscore the fragility of the water and wastewater (WWS) sector and the growing sophistication of adversaries targeting industrial control systems.
states, prompting an FBI investigation and elevating concerns over state-sponsored threats to operational technology (OT).
The attacks in Minnesota were first disclosed earlier the week of July 27, with officials reporting that the cyber intrusion targeted OT at more than 30 water utilities across the state, including the city of Plymouth. Within days, Michigan's Department of Environment, Great Lakes, and Energy (EGLE) revealed it had received a federal cyber alert on Tuesday, July 28, warning of attempts to tamper with operational technology at water systems. “Soon after” the alert, Michigan received a “small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” according to EGLE communications director Dale George. Nine systems were ultimately flagged, though all continued to function normally and posed no known public health risk.
The timing of the incidents dovetails with a joint advisory from the FBI, CISA, and other agencies issued the previous week, which warned that Iranian hackers have been actively targeting water and wastewater systems and the operational controls of other critical infrastructure sectors. While the FBI has not publicly attributed the Minnesota or Michigan attacks to any specific actor, the advisory suggests a possible link to an ongoing campaign by Iranian state-sponsored groups, which have historically probed U.S. critical infrastructure. The Bureau stated on August 1 that it is “fully engaged to protect critical infrastructure” and remains “well-equipped to protect against cyber threats of all varieties,” but declined to identify a suspect.
The WWS sector has long been recognized as a weak link in national cybersecurity. Many water utilities are small, underfunded, and rely on legacy OT/SCADA systems with minimal segmentation from IT networks. The 2021 Oldsmar, Florida water treatment plant incident, where a hacker attempted to raise sodium hydroxide levels to dangerous concentrations, demonstrated the potential for catastrophic harm. The current incidents, while reportedly non-disruptive, reveal a coordinated, multi-state operation that may have been intended to test defenses, gather intelligence, or establish persistent access for future disruption.
For the cybersecurity community, the attacks highlight several key trends. First, the targeting of OT—rather than purely IT systems—signals an escalation in adversary capabilities and a willingness to cross a red line by meddling with processes that directly affect public health and safety. Second, the rapid spread across states, likely leveraging common vulnerabilities in remote access tools or internet-facing HMIs, points to systemic weaknesses that extend beyond any single utility. Third, the parallel between the advisories and the incidents reinforces the value of threat intelligence sharing; however, the fact that attacks occurred after alerts were issued suggests that many utilities were unable to implement mitigations in time.
What to Watch
The implications are far-reaching. Financially, water systems may face increased pressure to invest in OT security monitoring, network segmentation, and incident response planning. Regulatorily, the incidents could accelerate efforts by the EPA and DHS to mandate cybersecurity standards for water utilities, akin to those imposed on the electric grid. Insurance underwriters may also reassess risk for the WWS sector, potentially leading to higher premiums or coverage exclusions. Geopolitically, attribution to Iran would mark a significant escalation in state-sponsored cyber aggression, potentially inviting diplomatic or retaliatory measures.
Looking ahead, the investigation will be critical in determining whether these were reconnaissance probes, pre-positioning for future disruption, or opportunistic attacks by copycat actors. Security leaders at water utilities nationwide should immediately audit remote access controls, apply the mitigations outlined in the CISA advisory, and enhance visibility into OT network traffic. As the FBI and interagency partners dig deeper, the full scope and intent of the campaign may only become clear over weeks or months. For now, the message is unequivocal: the nation's water systems are in the crosshairs, and the time for fortified defenses is overdue.
Timeline
Timeline
FBI/CISA advisory warns of Iranian targeting of water/wastewater OT
A joint advisory alerts critical infrastructure sectors to a campaign by Iranian state-sponsored hackers targeting water and wastewater systems, and operational technology controls.
Federal cyber alert sent to states
States receive a federal cyber alert specifically about attempts to tamper with operational technology at water systems.
Minnesota reports cyberattacks on over 30 water systems
State officials announce that OT at more than 30 water utilities was targeted earlier in the week, with no reported public health impact.
Michigan reports nine affected water systems
Days after the federal alert, Michigan EGLE confirms nine communities reported activity consistent with the attempted tampering; all systems continued safe operation.
FBI acknowledges investigation
The FBI issues a statement acknowledging public reporting and affirming full engagement with interagency partners to protect critical infrastructure, without attributing the attacks.
Sources
Sources
Based on 2 source articles- newsday.comFBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systemsAug 1, 2026
- idahostatejournal.comFBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systemsAug 1, 2026
Cite This Page
"FBI probes 39+ water system cyberattacks across Michigan, Minnesota." Cyber Intelligence Brief, August 1, 2026. https://getcyberbrief.com/story/fbi-water-system-cyberattacks-michigan-minnesota-2026
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |