Over 30 individual Minnesota water and wastewater treatment facilities were simultaneously hit with a cyber-attack from an unknown source on July 26 and 27, 2026. The coordinated attack targeted the utilities’ operational technology systems and caused some affected communities to request that residents minimize water use due to limited stored water. Other communities experienced equipment malfunctions requiring them to implement contingency plans and switch to manual operations.

The Minnesota IT Services agency activated its incident response plan statewide in response to the attack. Although the attacker is unknown, there is speculation that it may be attributable to Iran-backed hackers in response to attacks on a southern Iranian water treatment plant.

Australia and the U.S. Cybersecurity & Infrastructure Security Agency (CISA) issued guidance on July 28, 2026, for critical infrastructure operators to isolate vital systems during cyber attacks “or periods of increased cyber threat.” CISA has been warning critical infrastructure operators about increased threats from Iranian-affiliated cyber actors repeatedly since the war in Iran commenced.

The fact that the threat actors coordinated this attack to affect multiple utilities across an entire state is rather frightening. Critical infrastructure operators should stay informed of the CISA issued guidance and take the warnings seriously.

Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.