Cyberattacks Target US Water OT Systems in Seven States
Operational technology at more than 30 Minnesota water facilities was targeted July 26–27; officials say at least seven states were affected and drinking water remained safe.
A coordinated cyber campaign targeted water and wastewater operational technology systems across multiple U.S. states on July 26–27, with Minnesota reporting more than 30 facilities were hit. Officials in several states said systems continued to operate and there were no public health concerns.
Minnesota authorities reported the largest number of incidents, identifying attacks on OT equipment at over 30 water and wastewater sites during the two-day period. Michigan confirmed that a small number of communities experienced malicious cyber activity but that systems remained operational. Rapid City, South Dakota, reported an incident involving a wastewater lift station and posted that “At no time was the city’s water or wastewater infrastructure systems placed in jeopardy and city officials assure Rapid City residents the city’s water supply remains safe and protected.” Officials indicate at least seven states were affected, including Georgia.
Federal investigators are reviewing the campaign and examining potential links to Iran. A sector information-sharing organization reported that a state fusion center found the activity aligned with earlier campaigns that U.S. officials have connected to Iran. That analysis was distributed under Traffic Light Protocol as TLP:AMBER. No formal public attribution has been issued by federal agencies.
Technical details released by local authorities are limited. One Minnesota city said the incident was confined to equipment that uses cellular communications. Security professionals note that OT devices with cellular links can provide an entry point for attackers. A nonprofit tracker is maintaining an updated technical report to support incident responders and OT defenders.
Before the July incidents, federal agencies warned that industrial control systems made by major vendors, including Siemens, Schneider Electric and Rockwell Automation, have been targeted by state-linked actors. An Internet scanning service reported roughly 10,000 programmable logic controllers from those vendors appear exposed to the internet, though it is not clear how many are reachable or vulnerable.
The Cybersecurity and Infrastructure Security Agency urged water-sector operators to strengthen protections for OT devices, including programmable logic controllers and other industrial control components. Sector guidance emphasises isolating OT networks from business networks, improving authentication for remote access, monitoring connections that use cellular links, and applying vendor patches and configuration changes where recommended.
Water utilities, vendors and information-sharing groups have been asked to review logs, block suspicious access, and follow published mitigation checklists. Industry monitors and specialist organisations are continuing to publish indicators of compromise and consolidated technical summaries to assist local utilities and state and federal partners as investigations continue.








