Over 30 community water systems in Minnesota were targeted by a coordinated cyberattack on July 26 and 27, 2026, causing some systems to go offline and forcing manual resets and operations [1, 2, 3, 4, 5]. Some systems experienced reduced water pressure and flooding as a result [2, 3, 5]. The town of Braham, in the Minneapolis metropolitan area, saw about two hours of water service interruption due to the attack [6, 7, 4].

The FBI confirmed its involvement and stated it was actively engaged with victims across at least seven US states reporting similar attacks against water and wastewater utilities [8, 2, 3, 5]. "The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors. We are actively engaged with victims and committed to supporting critical infrastructure entities against malicious cyber actors attempting to harm the United States," the FBI Cyber Division said [8].

Authorities including Minnesota IT Services and the Cybersecurity and Infrastructure Security Agency (CISA) have advised operators of water systems to disconnect internet connections to help reduce further intrusion risks [2, 3, 5]. Emily Zimmer, spokesperson for Minnesota IT Services, said, "The timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure" [8].

US officials largely link the attacks to Iranian government-aligned hacker groups, citing similarities to previous incidents [1, 8, 2, 3, 6, 7, 4, 5]. Specific groups mentioned include CyberAv3ngers and Handala, which US authorities associate with Iran [6, 7]. However, officials caution that attribution remains preliminary. Some reports suggest the possibility of false-flag tactics mimicking Iranian hackers, although former intelligence officials consider this unlikely [8, 4].

Mayor Nate George of Braham described the attack's impact: "There was power but we had no control of water flow. They hacked the water well system, basically shutting it down." [4]

Despite the disruptions, officials say the attacks did not threaten water safety or require residents to change their water use habits [1, 2, 3, 5].

The FBI and other federal officials publicly acknowledged the investigation between July 29 and 30, confirming the scope of affected areas extends beyond Minnesota [8, 2, 3, 5].

The attacks follow a CISA warning issued on July 22 about rising cyber threats targeting critical infrastructure linked to Iran-related groups [6, 7].

Authorities continue investigations amid efforts to protect water systems from further attacks.