MINNEAPOLIMEDIA NEWS | FBI Investigation Expands as Cyberattacks Reach Water Systems Across Multiple States
ST. PAUL, MN (August 2, 2026). A federal investigation into coordinated cyberattacks against Minnesota water systems has widened after officials disclosed that municipal utilities in Michigan and several other states were also targeted.
More than 30 community water systems across Minnesota were affected by cyberattacks earlier in the week, according to state officials. The incidents targeted operational technology used to monitor and control municipal water infrastructure.
Michigan officials reported Saturday that nine water systems in that state had also been attacked. All nine continued operating safely, and authorities said there was no known threat to public health.
The FBI, Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency and state authorities are investigating the attacks. Officials had not publicly identified the responsible individual, organization or government as of Saturday.
Federal authorities have been examining whether the activity could be connected to hackers associated with Iran. However, investigators have not formally attributed the attacks, and no organization has publicly claimed responsibility.
Minnesota officials said the affected communities experienced different levels of disruption.
In Braham, attackers temporarily disabled operating controls for the city’s well and water-treatment plant, leaving the community dependent on water stored in its tower until the system was restored. Plymouth experienced a temporary communications disruption involving water infrastructure.
There has been no indication that drinking water was contaminated or that attackers attempted to introduce dangerous substances into any system.
The expanding investigation nevertheless demonstrates how cyberattacks can interfere with the equipment municipalities use to operate wells, pumps, treatment facilities and distribution systems.
Water and wastewater utilities can be particularly vulnerable because many rely on aging equipment, small technical staffs and control systems that may be connected to the internet for remote monitoring.
Federal agencies have advised utilities to review remote-access practices, change passwords, apply available security updates and disconnect vulnerable operational equipment from the public internet whenever possible.
Authorities said the investigation remains active and the number of affected systems could change as additional communities examine their networks and report suspicious activity.
STAY CONNECTED TO MINNEAPOLIMEDIA
Local stories matter. Subscribe free to MinneapoliMedia and receive independent news, community reporting and important updates from Minneapolis, the North Metro and communities across Minnesota.
SUBSCRIBE FREE: https://minneapolimedia.town.news/subscribe
MinneapoliMedia | Community. Culture. Civic Life.