💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Residents across Minnesota and six neighboring states faced an unexpected vulnerability last week when hackers launched a coordinated assault on operational technology controlling community water systems. The attack unfolded over July 26 and 27, affecting more than 30 water utilities across the seven-state region. Minnesota IT Services activated the state’s cybersecurity response protocols and mobilized federal agencies to investigate the breach.
At least one water treatment facility went temporarily offline as a result of the intrusion, while other communities experienced degradation in automated control systems and communications infrastructure. Workers at affected utilities shifted to manual operating procedures and activated backup systems to maintain continuous service delivery. State authorities confirmed that no public health emergency declarations became necessary, with no orders issued to residents to curtail water consumption.
The FBI subsequently confirmed that water and wastewater utilities in seven states sustained operational damage from the attack. Investigators have preliminarily attributed the breach to Iranian state-sponsored hackers, according to a July 30 New York Times report citing U.S. and state officials involved in the investigation. President Donald Trump disputed this assessment, though federal officials cautioned that evidence remained incomplete and alternative explanations had not been ruled out.
In Braham, Minnesota, plant operators discovered their facility offline and restored normal filtration and treatment functions within hours. Plymouth reported compromised communications at two water towers and multiple wastewater lift stations, though water levels and quality indicators remained stable. South St. Paul’s water utility controls experienced a confirmed cybersecurity incident, but public works staff implemented contingency protocols to preserve service. Maple Plain confirmed its water technology had been targeted as well.
The Cybersecurity and Infrastructure Security Agency issued a warning in April that Iranian-affiliated actors were targeting internet-connected programmable logic controllers at critical infrastructure sites. CISA expanded that advisory on July 22 to include equipment from Schneider Electric, Siemens and other manufacturers beyond the initially cited Rockwell Automation and Allen-Bradley products.
The vulnerability exposed by the Minnesota attack reflects a broader national concern about water system defenses. The United States operates approximately 170,000 drinking water and wastewater systems, many now connected to internet-enabled remote monitoring technology. The Government Accountability Office noted that cybersecurity capabilities vary significantly among utilities, with smaller communities particularly challenged by outdated equipment, limited budgets and staffing constraints.
Federal officials have documented significant gaps in water utility security practices. The Environmental Protection Agency found that more than 70 percent of inspected systems failed to meet basic federal requirements for risk assessment and emergency response planning. Inspectors also discovered systems still operating with factory default passwords, shared staff accounts and access credentials that remained active after employees departed.
CISA published international guidance on July 28 titled “CI Fortify: Advice for Isolating Vital Systems,” urging critical infrastructure operators to segregate essential operational technology from less secure networks. The agency recommended that water utilities eliminate unnecessary internet exposure, implement strong authentication controls and restrict remote access capabilities where feasible.
Residents should verify water safety information through official municipal channels, including city websites, county health departments and utility notices rather than social media. The Centers for Disease Control and Prevention recommends households maintain emergency water reserves of at least one gallon per person daily for three-day periods. Authorities urged vigilance against scams that exploit service disruptions by impersonating utilities or offering fraudulent assistance.
More Stories
Federal Authorities Charge 19 in Philadelphia-Based Medicare, Medicaid Fraud Scheme Worth $4 Million
Spain Investigates Security Threats as Thousands Surge Into Ceuta Enclave, Straining EU Border
Cruz Pushes Senate Vote on College Sports Protection Bill Before August Recess