'Coordinated Cyberattack' Hits More Than 30 Minnesota Water Systems

ZeroHedge
Published
'Coordinated Cyberattack' Hits More Than 30 Minnesota Water Systems

The short version

  • Minnesota IT Services (MNIT) stated on July 28 that it activated its incident response capabilities immediately after learning of the attack.
  • MNIT stated that an investigation remains active, and responders continue to “assess affected systems.” “At this time…
  • It stated that local utilities make prime targets because of their size and that most U.S. water utilities are tiny operations.
  • According to the Environmental Protection Agency (EPA), 97 percent of the nation’s 156,000 public water systems serve fewer than 10,000 customers.
  • While it is not yet clear who is responsible for the attacks, Iranian-linked hackers have, for years, targeted U.S. water systems to varying levels of success.

The story

'Coordinated Cyberattack' Hits More Than 30 Minnesota Water Systems

Authored by Owen Evans via The Epoch Times,

A “coordinated cyberattack” targeted more than 30 community water systems ‌in Minnesota on July 26 and July 27, the state’s information technology agency said in a statement.

Minnesota IT Services (MNIT) stated on July 28 that it activated its incident response capabilities immediately after learning of the attack. MNIT stated that an investigation remains active, and responders continue to “assess affected systems.”

“At this time, they are not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage,” the agency stated.

John Israel, MNIT assistant commissioner and Minnesota chief information security officer, said such attacks require “a coordinated, whole-of-government response.”

“[The agency] is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks,” he said.

Emily Zimmer, a spokesperson for the agency, told Reuters in an email that while the investigation remains ongoing, “the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure.”

Zimmer said the agency could not yet discuss formal attribution or specifics of the incidents. She noted that ‌the agency used the term “attack“ to describe the situation ”because investigators identified unauthorized access with malicious intent directed at these systems.”

The FBI said in a statement that it ‌was ⁠aware of the incident and was in contact with the victims “to resolve the matter.”

In a June 16 article about safeguarding critical water infrastructure, Microsoft stated that while cyberattacks typically “wreak havoc” on digital systems, at a water utility, a network breach “can move quickly into the physical realm.”

“Online systems can give an attacker access to operational technology—physical equipment like pumps, sensors, and chemical treatment systems,” it stated.

It stated that local utilities make prime targets because of their size and that most U.S. water utilities are tiny operations.

According to the Environmental Protection Agency (EPA), 97 percent of the nation’s 156,000 public water systems serve fewer than 10,000 customers.

While it is not yet clear who is responsible for the attacks, Iranian-linked hackers have, for years, targeted U.S. water systems to varying levels of success.

Handala Warning

Iran’s state-run Press TV, which the U.S. Treasury has sanctioned for acting as a propaganda arm of the Islamic Revolutionary Guard Corps, reported on July 23 that the Handala hacking group warned that it will continue targeting U.S. industrial control systems.

Handala is one of several public personas used by a hacking unit operating ​under the Iranian Ministry of Intelligence and Security (MOIS) as part of the agency’s psychological ⁠operations, according to the U.S. Department of Justice.

An April 7 U.S. Cybersecurity and Infrastructure Security Agency (CISA) ​advisory warned that Iranian-affiliated ​hackers were attacking internet-facing ⁠programmable logic controllers, computer devices used to interact with machinery and other critical infrastructure networks, manufactured by Rockwell Automation.

The group said on July 23 that attacks targeting programmable logic controllers and supervisory control and data acquisition systems represented only a portion of its capabilities and warned that wider campaigns could target sectors including water, electricity, and transportation networks, Press TV reported.

A July 22 update to the advisory expanded the ​scope of the targeting to include devices manufactured by Schneider Electric, Siemens, and ​potentially other manufacturers.

CISA stated in its advisory that some hacking activity resembles operations previously attributed to CyberAv3ngers, also known as the Shahid Kaveh Group, which is affiliated with the Cyber Electronic Command of Iran’s Islamic Revolutionary Guard Corps.

CISA acting Director Nick Andersen told The Epoch Times by email: “CISA is aware of multiple potential incidents affecting local water utilities and is coordinating with the EPA and other government and industry partners to understand the scope and provide any information or technical support to help critical infrastructure owners and operators protect their systems.”

On June 11, the cybersecurity company Dataminr issued an alert about Handala, stating that the hacking group had claimed to have compromised California Water Service (Cal Water), one of the largest investor-owned water utilities in the United States, serving approximately 2 million customers across 100 California communities. The hackers published 5 gigabytes of data.

“CISA’s ⁠updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States,” Joe Slowik, director of threat research and cyber engineering at Dataminr, said in a July 27 blog post on the company’s ⁠website.

CyberAv3ngers struck a small water utility in Aliquippa, Pa., in November 2023, gaining control of a device at the Municipal Water Authority, according to a 2025 report by the Maryland Cybersecurity Council.

Cyberattacks on Water Systems

According to Xylem, a global water technology provider, there’s “no lack of examples” of cyberattacks involving water systems.

In October 2024, New Jersey-based American Water, the largest regulated water and wastewater utility company in the United States, which serves more than 14 million people in 14 states and on 18 military installations, had to shut down computer systems due to a cyberattack.

In January 2024, the Russian hacktivist group Cyber Army of Russia Reborn claimed responsibility for attacks on water facilities in the United States and Poland. In Muleshoe, Texas, one breach resulted in the loss of tens of thousands of gallons of water.

Authorities have assessed that a Chinese Communist Party state-sponsored cyber group known as Volt Typhoon is seeking to pre-position itself on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure.

In a 2024 statement, CISA said that Volt Typhoon uses hacking techniques that avoid installing malware, which can be relatively easily detected, and instead rely on built-in tools that are harder to spot.

This means that they exploit weak admin passwords, factory-default logins, and unpatched internet-connected devices

In a January report from the Congressional Research Service, Chris Jaikaran, a specialist in cybersecurity policy, said that the U.S. Intelligence Community assesses that China is “the most active and persistent cyber threat” to U.S. institutions.

Tyler Durden Thu, 07/30/2026 - 09:10
Read the full story at ZeroHedgeOriginal

Related Markets

All Markets
View full chart →
View Full Chart
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

How other outlets covered this

Compare all

Alto found this story at 5 outlets. Same event, different framing — compare the headlines.

How this story developed

Full timeline

Alto has tracked this across 6 days of coverage from 5 outlets.

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

Up next

Related coverage from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What does gas cost in Minnesota right now?Current statewide average
  2. How does Minnesota rank on taxes and cost of living?Taxes, wages, cost of living
  3. What were the latest Minnesota lottery numbers?Recent winning numbers
  4. Who represents Minnesota in Congress?House and Senate members
  5. What are Minnesota's voter ID rules?ID rules and deadlines
  6. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  7. Where does $75,000 rank in Minnesota?Census percentile — national and state
  8. What federal tax bracket is $80,000 (single)?Marginal and effective rate on the next page
  9. What's Alto covering on the Finance desk?Latest headlines on this beat
  10. What else is Alto tracking on Federal Reserve & Interest Rates?Topic hub with related coverage
  11. What else is Alto tracking on Inflation?Topic hub with related coverage

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Markets Freely

Trade ideas, earnings, and the Fed with investors who aren't waiting on a moderator's approval.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.