FBI now says Minnesota water hacks part of 7-state Iranian cyber campaign
Some attacks caused pressure loss and flooding as hackers seized control of exposed PLC devices.

Image by Snehit Photo | Shutterstock
- More than 30 Minnesota water systems were hit as attacks spread across at least seven states.
- Hackers changed passwords and IP addresses – locking operators out of critical water equipment.
- The suspected hacking group CyberAv3ngers has targeted US water systems before.
- Experts warn exposed operational technology could give attackers control of essential services.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The FBI has revealed that public water systems across at least seven states have been attacked – including 30 Minnesota water facilities hit last weekend – as part of a broader campaign believed to be linked to Iranian state hackers.
The new FBI warning, issued Thursday in coordination with the US Environmental Protection Agency (EPA), comes days after Cybernews first reported that hackers had targeted more than 30 public water systems across Minnesota by exploiting internet-connected industrial control devices known as PLCs, or programmable logic controllers.
Minnesota attacks were not isolated
The expanded hacking campaign – aimed at disrupting US water and wastewater treatment systems - is categorized by the US Cybersecurity and Infrastructure Security Agency (CISA) as attacks on US critical infrastructure.
A compromised water and wastewater system could affect the ability to "provide clean, potable water to, and effectively manage the wastewater of a community," CISA says.
The FBI did not name the seven US states or say which threat actor is behind the attacks.
However, in an updated CISA advisory from last week, the ongoing threat has been linked to the CyberAv3ngers – a known hacking group affiliated with the Islamic Revolutionary Guards Corps (IRGC) – which has successfully targeted multiple US and Israeli water utilities in recent years.
The FBI is now providing defenders with a list of steps to harden these critical systems, which also apply to government facilities and energy infrastructure, starting with “disconnecting PLCs from the public-facing internet.”
Other key recommendations include:
- Change default passwords
- Restrict network access
- Set physical PLC mode switches to “Run”
- Maintain manual operation capability
- Review PLC project files
- Plan for end-of-life replacements
FBI says attacks spread across seven states
The FBI says the malicious cyber actors (MCAs) have been targeting internet-facing PLC devices and causing operational disruptions across dozens of municipalities since at least July 27th.
“Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations,”the FBI warning states.
In some cases, attackers reportedly changed device passwords and internet protocol (IP) addresses, preventing operators from remotely monitoring or controlling critical equipment, and forcing staff to switch to manual workarounds.
The FBi said at least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites.
Several Minnesota municipalities, such as the City of Braham, also reported disrupted communications and pressure loss or flooding before access was restored.
“They were able to hack into the control system of the well and just turn the well off,” the city’s mayor described the Monday morning attack.
Pressure loss could potentially allow untreated groundwater to seep into pipes, the FBI warned.
Exposed PLCs remain the target
The FBI warns that even small utilities with limited cybersecurity resources remain attractive targets because many continue to operate older industrial control systems directly accessible from the internet.
PLC devices are public-facing computer systems used to automate industrial machines and processes, made up of four main components: input and output modules, a central processing unit (CPU), and a memory system.
The July 22nd CISA advisory expanded the list of targeted manufactured PLC brands to include Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and others.
The previous campaigns led by the CyberAv3ngers were known to specifically target Unitronics brand PLCs, primarily because they were manufactured in Israel.
Critical infrastructure in the crosshairs
John Bruggeman, virtual chief information security officer (vCISO) at CBTS, says the latest string of incidents shows that threat actors are expanding beyond simple data theft and encryption to manipulate systems – all with the goal of disrupting essential services.
“Attackers are targeting operational technology environments that are publicly exposed, and the concern is not just exposed information, but whether the attackers can gain control of the technology – before security teams can contain it,”Bruggeman says.
The vCISO also points out that a compromise doesn't have to cause an immediate disruption to pose a serious risk.
"Attackers can use their access to learn how systems operate, identify weaknesses, and prepare for future action," he says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Bruggeman says, "Water utilities need to monitor who has remote access, make sure default credentials for the OT systems are changed, restrict communication between IT and OT systems to a few trusted accounts, and implement MFA for remote access."
Check if your data has been leaked