NOW PLAYING
A United States cybersecurity agency is investigating a coordinated cyberattack on over 30 municipal water facilities in Minnesota which contains details of possible Iranian hackers.
The Minnesota Information Technology (MNIT) agency released an advisory Tuesday about the attacks, saying it was coordinating its investigation with federal agencies including the Cybersecurity and Infrastructure Security Agency (CISA), U.S. Environmental Protection Agency (EPA) and Federal Bureau of Investigation (FBI).
Officials in the advisory state that they have “not attributed the activity to a specific actor” or that the attacks can be attributed to a single actor, as the investigation is ongoing.
Investigators have been able to identify similarities among the incidents across Minnesota including the timings of the attacks and the “types of technology involved.”
MNIT added the Minnesota Department of Health is researching the effect on local water systems, with the agency not aware of “any active requests” from cities to “modify their drinking water usage.”
The attacks occurred Sunday and Monday with targets being “programmable logic controllers” (PLCs) and “human-machine interfaces” (HMIs), which are the computer screens operators.
Minnesota’s Chief Information Security Officer John Israel said that the state provided information to federal agencies who are “evaluating this activity in the broader national context.”
A July 22 advisory from the CISA, FBI and other federal agencies warned that Iranian hackers have been targeting water systems and other PLCs. It also emphasized the importance of operational technology (OT) owners and operators to “restrict direct internet access and ensure secure PLC deployment.”
The FBI’s Cyber Division Assistant Director Brett Leatherman said in the advisory Iranian actors “continue to target U.S. critical infrastructure” and “disrupt the essential services Americans rely on.”
This follows attacks by the U.S. during the Iran war targeting critical infrastructure in the country. The U.S. military sent strikes to a port facility, energy infrastructure and bridges in Iran.
MNIT advises water and wastewater systems to identify OT that can be accessed from the internet and take immediate steps to secure the system like checking remote access capabilities in facilities.
Add as preferred source on Google TagsCopyright 2026 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.
Comments: Link copiedMore Technology News
See All
Technology Anthropic says Claude models ‘gained unauthorized access’ to 3 companies during cyber test by Miranda Nazzaro 3 hours ago Technology / 3 hours ago