Over 40 US water systems hit as FBI probes suspected Iranian cyber campaign
At least 39 water facilities across Michigan and Minnesota were targeted in a week-long cyberattack campaign, prompting FBI and CISA investigation. The incidents highlight critical OT vulnerabilities and align with prior warnings of Iranian state-sponsored activity against the water sector.
Key Takeaways
- At least 39 water facilities across Michigan and Minnesota were targeted in a week-long cyberattack campaign, prompting FBI and CISA investigation.
- The incidents highlight critical OT vulnerabilities and align with prior warnings of Iranian state-sponsored activity against the water sector.
Mentioned
Key Intelligence
Key Facts
- 1Nine water systems in Michigan were confirmed impacted by the cyberattacks, but all continued safe operation with no public health concerns.
- 2Minnesota reported over 30 water systems targeted, with localized disruptions including Braham's water plant going offline, forcing residents to minimize water use.
- 3A federal cyber alert on July 28, 2026, warned states of attempts to tamper with operational technology at water facilities.
- 4An FBI-CISA advisory issued in late July 2026 explicitly warned that Iranian hackers are targeting water/wastewater systems and other critical infrastructure.
- 5The city of Braham, Minnesota (population ~1,700) attributed its water outage to a cyberattack that disabled well and treatment plant controls.
- 6The FBI is investigating but has not publicly attributed the attacks, though the pattern matches known Iranian state-sponsored group tactics.
Who's Affected
All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern.
Statement on August 1, 2026 confirming 9 systems impacted
Analysis
For cybersecurity professionals, these attacks on water systems underscore the escalating risk to operational technology (OT) environments. With over 40 systems impacted across two states, the incident demonstrates how internet-facing SCADA components can be exploited for disruptive or destructive purposes. The FBI's ongoing investigation and prior advisories linking Iranian groups to water sector targeting make this a critical threat intelligence case study.
A coordinated cyber campaign targeting water and wastewater systems in the United States has expanded to Michigan, with state officials confirming nine water facilities impacted following a federal cyber alert. This development comes days after Minnesota disclosed that over 30 of its water systems were similarly targeted, raising the total number of known incidents to at least 39 across the two states. The Federal Bureau of Investigation (FBI) is actively investigating the intrusions, while earlier joint advisories from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other agencies have explicitly warned that Iranian state-sponsored hackers are focusing on the water sector and other critical infrastructure. Despite the widespread nature of the attacks, authorities in both states have emphasized that no public health threats materialized and all systems continued to operate safely, though some localized service disruptions did occur.
In Minnesota, Minnesota IT Services reported over 30 affected systems, most involving remote monitoring and control equipment.
The incidents came to light after states received a federal cyber alert on Tuesday, July 28, 2026, about attempts to tamper with operational technology (OT) used to run water systems. In Michigan, Dale George, communications director for the Department of Environment, Great Lakes, and Energy (EGLE), said the state received a small number of reports from communities consistent with the federal warning, later confirming nine impacted systems. In Minnesota, Minnesota IT Services reported over 30 affected systems, most involving remote monitoring and control equipment. The city of Braham, about 70 miles north of Minneapolis, experienced a tangible operational impact: its water plant went offline for several hours on Monday, July 27, forcing the city of approximately 1,700 people to ask residents to minimize water use while the system relied on its water tower.
The timing and pattern align with a classified FBI-CISA advisory issued the previous week (week of July 20) that highlighted Iranian hackers' focus on water and wastewater systems. The advisory specifically warned that these actors—likely tied to Iran's Islamic Revolutionary Guard Corps (IRGC)—were exploiting internet-facing human-machine interfaces (HMIs), programmable logic controllers (PLCs), and other industrial control system (ICS) components. The attackers are believed to be using tactics such as brute-force attacks, default credential exploitation, and known vulnerability scanning to gain access and then manipulate system settings or cause disruptions. The FBI has not publicly attributed these recent breaches, but the advisory and the sophistication and scale of the incidents strongly suggest a nation-state actor.
For critical infrastructure operators, this campaign is a stark reminder that water systems—often underfunded and inadequately defended—remain a prime target. Many municipal water utilities rely on legacy SCADA systems with minimal network segmentation, lack multi-factor authentication, and have limited cybersecurity staffing. The Braham outage illustrates how a successful attack on OT controls can disrupt service, even if drinking water quality was not compromised. The broader scanning activity across dozens of systems indicates a systematic effort to identify and potentially preposition for future disruptive or destructive operations.
What to Watch
The implications extend beyond immediate service disruption. Successful tampering with water treatment processes could alter chemical levels, posing serious public health risks. The FBI's full engagement alongside interagency partners underscores the gravity; the agency stated it remains "well-equipped to protect against cyber threats of all varieties." However, the decentralized nature of US water systems—with over 50,000 community water systems—makes comprehensive defense challenging. Federal regulators, including CISA and the Environmental Protection Agency (EPA), are likely to accelerate mandates for cybersecurity hygiene requirements and information-sharing programs. The incidents may also prompt congressional hearings and additional funding for OT security grants to states and localities.
Looking ahead, the investigation's outcome will be critical. If attribution to Iran is confirmed, expect diplomatic consequences and potential sanctions. For the cybersecurity community, the campaign reinforces the need for prioritized vulnerability management in OT environments, real-time threat detection, and robust incident response plans. Water utilities must urgently assess their internet-exposed assets, enforce strong credential policies, and deploy network monitoring to detect anomalous commands. The attackers have demonstrated intent and capability; the sector must now demonstrate resilience to prevent a more catastrophic event. As adversaries refine their tradecraft against lifeline sectors, the line between espionage and sabotage grows increasingly thin.
Timeline
Timeline
FBI/CISA Advisory on Iranian Hackers
The FBI, CISA, and partner agencies issue an advisory warning that Iranian state-sponsored hackers are targeting water and wastewater systems as well as other critical infrastructure.
Braham, MN Water Plant Goes Offline
The city of Braham attributes water plant outage to a cyberattack, shutting down well and treatment controls and leaving the city on its water tower for hours.
Federal Cyber Alert Issued to States
State and local officials receive an alert about attempts to tamper with operational technology in water facilities.
Minnesota Reports 30+ Water Systems Targeted
Minnesota IT Services discloses that over 30 water systems in the state were targeted, mostly in remote monitoring/control technology.
Michigan Confirms 9 Water Systems Impacted
Michigan's EGLE announces nine water facilities were affected, all continuing safe operation with no public health impact.
Sources
Sources
Based on 2 source articles- India Today World Desk (in)Michigan joins Minnesota as cyberattacks hit US water systemsAug 1, 2026
- Michael Casey (gb)More states experience water system cyberattacks as FBI continues to investigateAug 1, 2026
Cite This Page
"Over 40 US water systems hit as FBI probes suspected Iranian cyber campaign." Cyber Intelligence Brief, August 2, 2026. https://getcyberbrief.com/story/over-40-us-water-systems-hit-suspected-iranian-cyber-campaign
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |