ICS/OT

US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

Water system

The recent cyber campaign targeting the water and wastewater sector in the United States has hit at least seven states as more information has come to light regarding Iran’s connection to the hacker attacks.

Minnesota reported last week that operational technology (OT) systems at more than 30 water and wastewater facilities were targeted in a cyberattack on July 26 and 27. 

Only a handful of cities issued public statements about the attack. One city briefly took down its water plant in response, but most reported no operational impact, reassuring citizens that drinking water remains safe.

As expected, the campaign was not limited to Minnesota, and several mainstream media outlets reported learning from sources that at least seven states are impacted. 

Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity, noting that all systems continued to operate safely and there were no public health concerns.

Rapid City in South Dakota also reported experiencing a cybersecurity incident, and its description suggests that it may be part of the same campaign. 

Advertisement. Scroll to continue reading.

“Recently, the City of Rapid City experienced a cyber incident involving one of its lift stations, which is used as part of the city’s wastewater system,” the city said in a Facebook post, adding, “At no time was the city’s water or wastewater infrastructure systems placed in jeopardy and city officials assure Rapid City residents the city’s water supply remains safe and protected.”

ABC News reported that Georgia is also among the seven states targeted in the water sector cyberattacks. The names of the other affected states remain unknown at the time of writing. 

Iran blamed for the water sector cyberattacks

Iran was immediately named as the primary suspect considering that its hackers have been known to target ICS and other OT systems, including in the water sector. 

While the US government has not publicly blamed Iran for the attacks, several mainstream media outlets reported last week that federal investigators had been looking into Iran’s potential involvement. 

In addition, WaterISAC, which serves as the communications and information-sharing organization for the water sector, reportedly wrote a report revealing that Minnesota’s Fusion Center had found evidence that the attacks were “aligned” with hacking campaigns previously linked by the US to Iran. 

Wired obtained a copy of the report, but WaterISAC noted that it was marked TLP:Amber and was not meant for public release or broad sharing. 

Technical details for OT defenders

Few technical details have been made available by the cities whose water facilities have been targeted by hackers. 

However, one city in Minnesota noted that the incident was limited to “equipment connected via cellular communications,” and industry professionals agree that OT endpoints connected to the internet via cellular networks are a potential intrusion vector.

Iran-linked hackers previously targeted water facilities in Israel via vulnerable cellular routers. 

Infracritical has made available a continuously updated report that summarizes all of the currently known technical information for the OT security community and defenders.

After the attacks on Minnesota water facilities came to light, CISA urged the sector to protect OT, specifically programmable logic controllers (PLCs).

In addition, days before the Minnesota attacks, federal agencies updated an April advisory on Iranian attacks aimed at OT devices, warning that industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation have been targeted. 

Internet security firm Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, though it’s unclear how many are actually vulnerable to attacks.

Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software

Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure

Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers

Related Content

Cybercrime

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

ICS/OT

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

ICS/OT

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

ICS/OT

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

ICS/OT

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version