Michigan authorities have confirmed that cyberattacks have affected nine of the state's water systems, with the Department of Environment, Great Lakes and Energy reporting the breaches. This follows similar incidents reported in Minnesota, where 30 locations across the state were recently compromised. The United States Federal Bureau of Investigation is currently conducting investigations into both sets of attacks, but as of now, no specific group or individual has been identified as the source of the breaches.
Breach timeline and details
Michigan officials revealed that a federal cyber alert was issued on Tuesday, warning of efforts to tamper with the operational technology used in water systems. Just days later, officials noted that a small number of communities in the state had experienced activity that matched the descriptions provided by federal cybersecurity agencies. In Minnesota, the state's IT agency confirmed that most of the 30 attacks targeted systems used for remotely monitoring and controlling water infrastructure equipment.
The recent cyberattacks have emerged following a warning released last week by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other organizations. The alert warned that Iranian hackers had been targeting water and wastewater systems, as well as the operational controls of other critical infrastructure sectors. CISA is urging critical infrastructure owners, operators and integrators to remove publicly exposed programmable logic controllers (PLC) devices and other operational technology (OT) from the internet as soon as possible. CISA said it is currently observing a significant increase in cyber threat actors targeting PLC devices in the water and wastewater sector. The agency said threat actors targeting exposed PLCs have modified passwords to lock out operators and have disconnected the PLCs by changing their IP addresses.
Trump denies Iranian connection
When asked about the Minnesota cyber incidents on Friday, former President Donald Trump rejected the possibility that Iranian hackers were responsible. 'I think Minnesota is behind it,' Trump stated, but he provided no evidence or reasoning to support his claim. He also did not address the situation in Michigan directly. Conversely, Minnesota Governor Tim Walz has stated that he believes Iran was responsible for the attacks. Walz further criticized Trump for weakening U.S. cyber defenses, claiming that reductions in the number of federal government employees have made the nation more vulnerable to cyber threats.
Impact and system status
Officials in Michigan stated that all water systems continued to operate safely and without disruption following the cyber incidents. Similarly, in Minnesota, as of Thursday, no active alerts were issued to residents about modifying their water usage. However, earlier in the week, some communities had been advised to make changes to their water systems to ensure stability and safety. Despite the incidents, multiple reports have said there has been no reported contamination of municipal drinking water as a result.
Water treatment facilities are generally more at risk of cyber threats than other infrastructure types. This is due to the widespread use of outdated and less secure cybersecurity measures. The FBI has emphasized its ongoing commitment to protecting critical infrastructure and stated that it is well-equipped to address all types of cyber threats.
The initial signs of the attack emerged between July 26 and 27, 2026 when authorities in Minnesota reported that hackers targeted about 30 water systems in their state. After gaining access to PLCs, the threat actors remotely modified the passwords and disconnected them by changing their IP addresses to lock out operators, as the CISA warning notes. The FBI elaborates that this causes loss of view and even function of the equipment in some cases, with at least one organisation reporting modifications in the PLC project files. The operational impacts reported to the FBI were loss of water pressure and flooding.
Federal investigators, including the FBI and CISA, have stated that the activity is consistent with Iranian-linked cyber actors, with intelligence and industry reporting indicating the attacks likely involved Iranian state-sponsored operators or affiliated proxy groups targeting vulnerable internet-connected industrial control systems. The attacks should serve as a warning that every utility, no matter the size, must assume it is a potential target and accelerate efforts to remove internet-exposed control systems, strengthen identity and remote access security, continuously monitor operational technology networks and ensure facilities can safely transition to manual operations when cyber incidents occur.
While it was widely reported that U.S. Officials are considering Iran as a suspect behind the hack, it is important to note that a formal determination has not been made. The US President Donald Trump had other culprits in mind, as he blamed Minnesota authorities for the attacks. 'Iran should be so lucky,' Trump said in a cabinet meeting. 'Iran’s got bigger problems than worrying about Minnesota.'

