1
1TL;DR: Hackers targeted the computer systems controlling water pumps and treatment at over 30 Minnesota towns this week. No drinking water was contaminated, but some cities had to switch to manual operations. Federal agencies warn this is part of a broader campaign hitting at least seven states, possibly linked to Iranian hackers.
Imagine you have a remote control for your garden sprinkler. Now imagine someone else grabs that remote and turns your sprinklers on and off whenever they want. That’s essentially what happened to more than 30 community water systems across Minnesota this week.
Important Point: The attackers went after Programmable Logic Controllers (PLCs).
Think of a PLC as a tiny, rugged computer that sits inside a water tower or pump station. Its job is simple: "If the water level drops below X, turn on the pump. If pressure gets too high, open the relief valve."
These devices are not supposed to be directly on the public internet—but many were, often through cellular modems installed by vendors that the utility didn’t even know about.
| City | What Happened | How They Fixed It |
|---|---|---|
| South St. Paul | Detected issue early Monday. | Switched to manual operations immediately. Water service never stopped. No customer data accessed. |
| Braham (rural, north of Minneapolis) | Well pump malfunctioned Monday. Workers noticed before automated alert. | Isolated the system, restored a backup, restarted plant in ~90 minutes. Water tower had 2-day supply. Now disconnected from public internet. |
| Plymouth (suburban) | Compromised PLCs at 2 water towers + 14 sewer lift stations Sunday night. | Disconnected from cellular network. Manual mode until Tuesday afternoon. Water quality, pressure, delivery unaffected. |
Quote from Plymouth Public Works Director Michael Thompson:
"I think you never expect it to happen to you."
Three major agencies issued joint warnings on Thursday, July 30, 2026:
Investigator Notes (Not Publicly Confirmed):
- U.S. officials and sources say they are probing possible Iranian hacker involvement.
- Attribution is not definitive—assessment could change as more technical evidence is collected.
- Investigators are also checking if the attacker deliberately made it look like Iran to stir tensions amid ongoing U.S.–Iran conflict.
- Minnesota and federal govt. have NOT publicly blamed any specific actor.
If you run a water or wastewater system—or know someone who does—here’s the immediate action checklist from CISA:
No. Multiple officials (Minnesota Dept. of Public Safety, city managers) confirmed water quality, treatment, pressure, and delivery were never affected. The attack hit the control computers, not the water itself.
A Programmable Logic Controller (PLC) is a small industrial computer that automatically runs equipment—like turning on a pump when a water tower gets low. If a hacker takes over the PLC, they can turn pumps off, open valves, or disable alarms. That’s why keeping them off the public internet is critical.
Yes. In 2023, hackers linked to Iran’s Revolutionary Guard Corps breached several U.S. water utilities using the same method: finding PLCs on the internet that still had default passwords.
Attackers often go after easy targets—small utilities with limited IT staff and older equipment. Also, hitting many small systems creates widespread disruption and fear, even if each individual system is small.
Final Thought: This attack is a wake-up call. Water systems are critical infrastructure, and their control computers must not be reachable from the open internet. The fix isn’t high-tech—it’s basic hygiene: disconnect, password-protect, and monitor.