• Video
  • Shop
  • Culture
  • Family
  • Wellness
  • Food
  • Living
  • Style
  • Travel
  • News
  • Book Club
  • Newsletter
  • Privacy Policy
  • Your US State Privacy Rights
  • Children's Online Privacy Policy
  • Interest-Based Ads
  • Terms of Use
  • Your Privacy Choices
  • Contact Us
  • Recalls and Product Safety Alerts
  • © 2026 ABC News
  • News

Feds issue warning to local water systems over increased cyberattacks, following Minnesota incident

1:43
Iran suspected in hack of Minnesota water systems
Stock Image/Getty Images
ByPierre Thomas, Luke Barr, Shannon K. Kingston, Jack Date, and Ivan Pereira
July 31, 2026, 2:40 PM

The federal government issued a warning Thursday about potential cyber threats to water systems after 30 water plants in Minnesota were hit with cyberattacks that multiple U.S. officials tell ABC News may have been linked to Iran.

The Cybersecurity and Infrastructure Security Agency (CISA) said in an alert that cyber threat actors are targeting programmable logic controllers (PLCs) and modifying passwords to "to lock out operators."

In this undated file photo, a water tower is shown in Minnesota.
Stock Image/Getty Images

"This activity has resulted in boil water notices and sustained manual operations," CISA said.

The alert comes two days after Minnesota officials revealed state water systems were hit with a cyber attack on Sunday and Monday.

Federal and state authorities are investigating whether Iran or hackers associated with the country were behind the attacks, multiple U.S. officials told ABC News. 

Related Articles

Minnesota water systems hit with cyberattack, state officials say

The officials told ABC News they are also waiting for a more detailed level of forensics from the hack.

They stressed that the analysis is preliminary, and another official says that the U.S. has not made any formal announcement or determinations on who might be behind the cyberattacks.

The probe into the Iranian connections was first reported Thursday by The New York Times.

Minnesota IT Services (MNIT) provided more details about the attack Thursday and said it targeted systems to remotely monitor and control equipment, including the PLCs.

"In this situation, 'impacted' means investigators confirmed malicious activity involving a system’s technology. It does not mean every affected community experienced a disruption to water service," the agency said in a statement.

There are no active requests from Minnesota localities for residents to change their water use, MNIT said.

PHOTO: An undated stock photo depicts an unidentified person typing on a computer keyboard.
STOCK PHOTO/Getty Images

"We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor," John Israel, Minnesota’s chief information security officer, said in a statement.

The hacks in Minnesota mirror a similar pattern carried out in other states by suspected Iran-linked actors. 

The FBI said in a statement that the agency is aware of the intrusions but did not assign responsibility. 

Related Articles

DHS shutdown fuels cybersecurity concerns as Iran-linked cyberattacks continue across US

CISA urged water utilities to protect themselves including disconnecting PLCs from the internet and to run the system through a VPN or gateway device if they need to use remote access capabilities.

Cyber experts say the incident in is an example of why it is important to sure up critical infrastructure systems.

"Critical infrastructure facilities like water and wastewater systems are increasingly becoming part of broader geopolitical cyber conflicts, even when they are not the primary targets. Much of the operational technology supporting these essential utilities was never designed with today's rapidly evolving cyber threats in mind," Mark Rorabaugh, CEO of InfraShield, a critical infrastructure cybersecurity firm, said.

He added, "When internet-facing computers and other control systems are exposed, even a small intrusion can create real operational disruption for communities large and small. The answer is a layered resilience strategy, including stronger network segmentation, continuous monitoring, offline recovery options, and sustained investment to harden these environments and reduce internet exposure wherever possible."

-ABC News' Ben Stein contributed to this report.

Up Next in News—

Kids who lost loved ones on 9/11 channel grief into art at America's Camp

September 11, 2026

Anthropic says it blocked potential AI bioweapon misuse

September 11, 2026

Lindsay Clancy's attorney asks judge to force 'not guilty' finding

September 10, 2026

Remembering the hero search-and-rescue dogs of 9/11, 25 years later

September 10, 2026

Shop GMA Favorites

ABC will receive a commission for purchases made through these links.

Sponsored Content by Taboola

The latest lifestyle and entertainment news and inspiration for how to live your best life - all from Good Morning America.
  • Contests
  • Terms of Use
  • Privacy Policy
  • Your Privacy Choices
  • Children’s Online Privacy Policy
  • Advertise with us
  • Your US State Privacy Rights
  • Interest-Based Ads
  • About Nielsen Measurement
  • Press
  • Feedback
  • Shop FAQs
  • ABC News
  • ABC
  • All Videos
  • All Topics
  • Sitemap
  • Recalls and Product Safety Alerts

© 2026 ABC News
  • Privacy Policy— 
  • Your US State Privacy Rights— 
  • Children's Online Privacy Policy— 
  • Interest-Based Ads— 
  • Terms of Use— 
  • Your Privacy Choices— 
  • Contact Us— 
  • Recalls and Product Safety Alerts— 

© 2026 ABC News