Hacks Water Plants in attempt to Poison Water in 7 States

Hacks Water Plants in attempt to Poison Water in 7 States

When we first covered the coordinated attacks against more than 30 Minnesota water systems, we were careful not to claim that anyone had tried to poison the water. Nobody had confirmed that, and we were not going to turn a serious story into clickbait by inventing details authorities had not released. At that point, all we knew was that someone had gotten into the systems, interfered with pumps and controls, and knocked water plants offline across multiple communities.

That caution is no longer necessary.

They Were Not Trying to Shut Off the Water. Police Say They Were Trying to Contaminate It.

A memo distributed by the Minnesota Bureau of Criminal Apprehension and obtained by CNN says the likely intended result of the attacks was the “loss of system pressure and subsequent potential contamination of water supply.” That is not some anonymous internet rumor or a prepper forum guessing about worst-case scenarios. It is a state law enforcement agency warning other agencies that the people inside these systems may have been trying to create the exact conditions needed to pull contamination into public drinking water lines.

No contamination has been confirmed, and the Minnesota Department of Health says water quality remained safe at the systems attacked on July 26 and 27. There was no statewide boil-water advisory, and nobody should claim people were poisoned when there is no evidence that happened. But the fact that the attackers failed does not make the intent behind the operation any less serious. These people were not trying to embarrass a city clerk or make a small-town utility website go offline for a few hours. According to the memo, they were trying to manipulate the physical system that keeps sewage, groundwater and everything else outside the pipe from being sucked into the water people drink.

Why Water Pressure Matters More Than Most People Realize

Most news reports have treated “loss of pressure” like it means somebody had a weak shower for a few hours. That completely misses the point. A public water system normally operates somewhere between 40 and 80 pounds per square inch, and that pressure is one of the most important things keeping the water safe.

Buried water mains run next to sewer lines, storm drains, septic systems, industrial properties, old fuel tanks, agricultural runoff and ground that may have been contaminated for decades. A lot of those pipes are old, and many have small cracks, failing joints or improperly protected connections. As long as the water system remains pressurized, treated water pushes outward through those openings and keeps whatever is outside the pipe from moving inward.

The EPA treats 20 psi as the danger line because once pressure falls below that level, the direction of flow can reverse. Groundwater, sewage and other contaminants can be pulled through cracks or cross-connections and into the distribution system. The term engineers use is backsiphonage, but you do not need an engineering degree to understand what is happening. It works like a straw. Create enough negative pressure and whatever is outside gets pulled in.

The FBI and EPA said the same thing in their July 30 warning, explaining that a loss of pressure could allow untreated groundwater to seep into drinking-water pipes. That means the pressure loss was not simply an annoying side effect of the attack. It may have been the entire mechanism. An attacker does not have to physically enter a treatment plant and pour something into a tank. If he can remotely shut down pumps, open the wrong valves or drain pressure from the system, the aging pipes under the town can pull contamination in for him.

That is what makes this different from the usual story about hacked government computers. These were industrial control systems connected to real pumps, real valves and real water towers. When someone changes what those machines are doing, the damage does not stay inside a computer. It reaches homes, hospitals, schools and every business connected to the system.

The Attackers Also Messed With the Alarms

The attackers did not stop at manipulating the equipment that controls water pressure. In at least one victim organization, the FBI found that project files inside the programmable logic controllers had been altered. Those controllers are the devices that tell pumps when to start, valves when to open and equipment how to respond when conditions change.

The programming inside them is called ladder logic. It is not ordinary office software. It is the set of instructions that causes physical machinery to move. Changing that logic is not the same as stealing a password to somebody’s email account. It means rewriting the instructions that run the plant.

CISA says the attackers also manipulated the monitoring and alarm systems that should have warned operators something was wrong. The plant could be pushed into an unsafe condition while the screen in front of the operator continued showing normal readings. That is the part that should scare people more than anything else in this story, because every reassurance a utility gives the public depends on those sensors and screens being accurate.

When a city tells residents that pressure is normal or that the water has not been affected, officials are relying on instrumentation that tells them what is happening inside the system. The technique used in these attacks was designed to make that instrumentation lie. The equipment could be doing one thing while the dashboard showed something completely different.

Minnesota operators caught the problem anyway, and in Braham the issue was discovered before the automated alert even fired. That was not the result of some flawless federal cyber defense system. A plant technician was doing his normal rounds and noticed that the water tower was calling for water but nothing was being pumped into it. A human being paying attention may be the only reason that town did not drain its water tower before anyone realized what was happening.

The Attacks Have Now Reached Michigan

Michigan confirmed that nine of its water systems were also attacked. State officials say those systems continued operating safely and that there was no known public health impact, but that makes two publicly identified states out of at least seven.

The New York Times reported that the attacks have now been identified in seven states and may be much more widespread. Officials described the scale as unprecedented, and evidence increasingly points toward Iran. CISA has also acknowledged that the intrusions disabled digital controls and resulted in boil-water notices somewhere in the country.

The federal government will not say where.

It will not identify the other five states, and most of the affected utilities in Minnesota have also been kept secret. More than 30 systems were attacked, but only a handful have been publicly named. The rest have been classified as nonpublic information.

That leaves ordinary people in an absurd position. Your water utility may have been compromised by a foreign-linked cyber operation. The attackers may have manipulated the equipment responsible for maintaining safe pressure. A boil-water advisory was apparently issued somewhere, but federal officials will not tell the public which communities were affected.

You can call your utility and hope somebody gives you a straight answer. You can watch for changes in pressure, taste, smell or color. You can follow city Facebook pages and local news outlets and hope a warning appears before you use the water. That is apparently the public notification system we are supposed to trust during a coordinated attack against critical infrastructure.

Attribution is still not final, and that should be stated honestly. U.S. intelligence agencies reportedly believe Iran was likely responsible, and the methods resemble those used by CyberAv3ngers, an Islamic Revolutionary Guard Corps-linked group that attacked a Pennsylvania water authority in 2023. Investigators are also looking at whether another group used Iranian tools and infrastructure to make the attack appear Iranian.

Nobody has been formally charged, and no government should be allowed to use an unproven cyber claim as an excuse for another war. What is not in dispute is that the attacks happened, that they reached systems in at least seven states, and that Minnesota law enforcement believes the intended result included possible contamination of drinking water.

America Hit Iranian Water Infrastructure First

There is another part of this story that most American coverage will either bury near the bottom or leave out entirely. In June, U.S. strikes near the Strait of Hormuz destroyed a water facility along Iran’s southern coast. More than 20,000 people reportedly lost access to water while temperatures in the region were running above 100 degrees.

The following day, a hacker group calling itself Hanzala claimed it had breached water utility systems in Bakersfield, Chico, Salinas and Stockton, California. The group said it had the ability to disrupt those systems but had chosen not to do it. It framed that decision as a warning.

The sequence was not hard to understand. The United States destroyed a water facility in Iran, and within a day hackers claimed access to water systems in four American cities and announced that they had decided not to shut them down yet. Six weeks later, more than 30 Minnesota systems were attacked over a single weekend, and a state police memo now says the likely goal was to create the conditions for contamination.

This is what infrastructure warfare looks like. It does not stay on a battlefield or inside a military base. It follows power lines, pipelines, shipping routes and internet connections until it reaches the water plant in a town most Americans have never heard of.

The people living in Braham did not vote to become part of a war with Iran. The families in the Iranian town that lost water during triple-digit heat did not vote to become part of it either. But once governments start targeting the systems civilians depend on to stay alive, everyone connected to those systems becomes part of the battlefield whether they want to be or not.

Iran Is Threatening Energy Infrastructure Too

A senior Iranian security official told the IRGC-affiliated Tasnim News Agency that Iran has prepared response plans that include attacks on critical infrastructure in Israel and U.S. energy assets throughout the Middle East. At the same time, reports say President Trump has ordered additional strikes that could begin soon.

Most Americans hear talk about refineries, tankers and the Strait of Hormuz and assume it is another foreign-policy story that has nothing to do with them. Then oil jumps, gas goes back to four dollars a gallon and grocery prices climb again because every truck bringing food into town runs on diesel.

Brent crude closed at $90.74 on July 29 after earlier threats from Trump, rising nearly eight percent in a single day. Gasoline had already climbed back toward four dollars a gallon, and analysts warned that a major slowdown in shipping through the Strait of Hormuz could push oil above $100 per barrel.

That number eventually shows up in everything you buy. It raises the cost of your commute, the cost of heating your home and the cost of running every ambulance, tractor, delivery truck and backup generator in the country. It also raises the cost of food because modern agriculture and food distribution depend on fuel at every stage.

The domestic side of this conflict is no longer theoretical either. We have now seen what it looks like when somebody on the other side of the world reaches through an internet connection and turns off a small American town’s water plant on a Monday morning.

The Federal Response Has Been Political Theater

During a meeting at Camp David, Trump dismissed the reported Iranian connection and blamed Minnesota. He called the state grossly incompetent, attacked the governor and said he did not believe an Iranian cyberattack had taken place.

Governor Tim Walz responded by accusing the administration of gutting CISA and leaving the country vulnerable. He called the attacks an example of modern warfare.

You do not have to like either of them to see the real problem. The Cybersecurity and Infrastructure Security Agency has reportedly lost around one-third of its workforce through cuts, layoffs and reassignments. Those losses included parts of its critical-infrastructure protection work and the elimination of its counter-ransomware initiative.

CISA has also operated without a Senate-confirmed director since January 2025. The agency issued an urgent warning about Iranian cyber threats on July 22, and four days later more than 30 water systems in Minnesota were attacked.

The president’s public response was not to explain which systems remained vulnerable, what the federal government was doing to secure them or why the public was being kept in the dark. He turned the attack into another fight with a governor he already disliked.

That is not leadership, and it is not a defense plan. It is a press strategy.

While politicians trade insults, small utilities in at least five unidentified states may still be running old industrial controllers connected directly to the public internet. Those systems do not become safer because somebody won an argument on television.

Hospitals Can Run Out of Water in Hours

Joshua Corman, who runs the UnDisruptable27 initiative at the Institute for Security and Technology, has warned that a community hospital may exhaust its emergency water reserves within two to four hours.

A hospital cannot function without water. Dialysis requires it. Surgical instruments have to be sterilized. Staff need it for scrubbing, cleaning rooms and operating cooling systems. Pharmacies use it to prepare medications, laundries need it to process linens, and every patient room has plumbing that becomes a problem the moment the supply stops.

Two to four hours is barely enough time to figure out what happened, let alone arrange enough tanker trucks to replace the normal water use of an entire hospital. Bottled water in the lobby is not going to keep a dialysis unit running or allow an operating room to continue functioning.

Corman also described participation in a recent national cyber exercise organized through the EPA’s water emergency office as extremely low. The exercise asked utilities whether they could operate for a full day without their SCADA systems, the computerized controls used to run the plant. Many apparently could not.

That means a large number of utilities may have no practical way to keep operating once the computers go down. If employees cannot run the equipment manually, then taking out the control system effectively takes out the plant.

That is the state of readiness in a sector now being targeted by foreign-linked hackers in the middle of a widening military conflict.

Small Towns Were Never Given the Money to Defend These Systems

None of this came out of nowhere. A 2024 EPA enforcement alert found that 70 percent of inspected water systems were violating a requirement to maintain current risk assessments and emergency-response plans.

The requirement was not some impossible demand for military-grade cyber defenses. It required utilities to keep a plan on file. Many could not even do that.

The EPA Inspector General also reviewed more than 1,000 drinking-water systems and found critical or high-severity cybersecurity vulnerabilities in 97 of them. Those systems served approximately 26.6 million people.

There are between 150,000 and 170,000 water systems in the United States, and most of them are small local operations. Many are run by a handful of employees responsible for repairing pipes, collecting samples, reading meters, maintaining pumps and keeping equipment alive long after the manufacturer has stopped supporting it.

The Allen-Bradley MicroLogix 1100 and 1400 controllers identified by the FBI in this campaign are legacy equipment approaching or already reaching the end of their supported life. A town cannot solve that problem with another password reset or a software patch. The hardware has to be replaced, and that means purchasing new controllers, hiring specialists, redesigning parts of the system and training employees.

Small-town water budgets were never designed to defend against foreign intelligence services. The same residents who are already angry about rising utility bills will eventually have to pay for those upgrades because Washington spent years warning about the problem without funding a serious solution.

In Braham, the front line of America’s cyber defense was a technician walking through the plant shortly after 9 a.m. He noticed the tower was asking for water but none was being pumped. The plant still had electricity, but the controls were not working. Within about 90 minutes, officials learned that several other cities were dealing with similar failures.

That worker paying attention may be the only reason the town did not empty its water tower. There was no federal cyber team standing beside him and no advanced government system that stopped the attack before it reached the plant. It was one guy doing his rounds and noticing that something looked wrong.

What You Should Do Before the Next Attack

The basic answer is the same one we have given for years: store water. A gallon per person per day is the minimum, and that amount is intended for drinking and limited sanitation during a short emergency. It is not a comfortable supply for a real outage.

Two weeks should be the goal, and households in hot climates or anyone with children, medical needs or animals should store more. Water sitting in a clean container inside your home was collected before the pressure failure or contamination event. That is the main reason it matters.

Once pressure drops, you cannot assume water coming from the faucet is safe because it looks clear. Sewage, groundwater and many chemical contaminants do not always change the appearance, smell or taste of the water.

You also need to understand what your filter can actually remove. A boil-water advisory usually deals with biological contamination. Boiling can kill bacteria, viruses and parasites, but it does not remove fuel, pesticides, heavy metals or industrial chemicals. In some cases, boiling can make chemical contamination worse by evaporating clean water and leaving a higher concentration of the contaminant behind.

A camping filter is not a magic box either. Some filters handle bacteria and protozoa well but do very little for viruses, chemicals or dissolved metals. If nobody can tell you what entered the system, using a basic filter and hoping for the best is still a gamble.

Sign up for emergency alerts from your water utility now. Find out whether your city uses text messages, email, a website or social media. Braham’s first warning appeared on Facebook and said only that the plant was offline for an unknown reason.

You should also have a way to receive information that does not depend on the same systems being attacked. Keep a battery-operated radio, know which local stations carry emergency information and have a backup method of communication.

Learn how much water is already stored inside your house. A typical water heater may hold 40 to 50 gallons and can often be drained from the valve near the bottom, assuming contaminated water has not already entered the building. At the first credible warning of a pressure problem, fill tubs, pots and every clean container you have while the system is still running.

It is also worth finding out what kind of utility serves your community. Small systems serving fewer than 10,000 people are more likely to operate with limited staff, old equipment and remote-access systems installed years ago to make maintenance cheaper. That does not automatically mean your water is unsafe, but it does mean you should not assume a two-person public works department has the resources to stop a foreign cyber operation.

Every Warning Came Before the Attack

A foreign-linked cyber operation gained access to the equipment responsible for producing and distributing drinking water in more than 30 Minnesota communities. A state law enforcement memo says the likely objective was to lower pressure and create the potential for contamination.

The attackers also altered monitoring and alarm systems, which means operators could have been watching normal readings while the equipment underneath them was being pushed into an unsafe condition. Similar activity has now been reported in Michigan and at least five other states the federal government refuses to identify.

This was not an unpredictable event. The EPA warned governors about the vulnerability of water systems in 2024. Its Inspector General found critical weaknesses in utilities serving 26.6 million people. CISA updated its warning about Iranian cyber activity on July 22, and the Minnesota attacks began four days later.

Those warnings landed on an industry where small towns are expected to defend aging industrial equipment against foreign intelligence operations with a public works employee, a contractor’s phone number and whatever money remains in the annual budget.

The federal government cut the agency responsible for protecting critical infrastructure, left it without a confirmed director and then turned the attack into another political argument.

The people in Braham were saved because a technician noticed the tower was calling for water and nothing was flowing. That was the entire margin between a manageable incident and a town draining its supply before anyone understood what was happening.

The next town may not have someone standing in the right place at the right time. The next attacker may hide the damage better, move faster or strike in the middle of the night.

When the water stops and a hospital starts counting down the two to four hours before its reserves are gone, nobody is going to care which politician won the argument.

They are going to want clean water, and by then it will be too late to start preparing.

Preparedness: Your Defense Against Water Threats

  • Water Storage: FEMA and CDC still hammer home the baseline: at least one gallon per person per day for drinking and sanitation—aim for a two-week minimum (or more if space allows; some guides suggest bumping to 1.5 gallons in hot climates or high activity). Use food-grade containers, treat with bleach if needed for long-term storage, and rotate your stock every 6-12 months to keep it fresh. Fill bathtubs, sinks, and pots immediately if a crisis hits—your hot water heater alone can hold 40-50 gallons of usable emergency water (drain it via the bottom valve with a hose).
  • Filtration and Purification: Don’t rely on boiling alone—it kills bacteria and parasites but leaves chemicals, heavy metals, and “forever chemicals” like PFAS behind. Invest in robust gravity-fed systems that tackle biologics, chemicals, and more. Berkey-style filters remain popular for off-grid use, but with recent regulatory scrutiny and much better alternatives, check out systems like Boroux Foundation, Alexapure Pro,or ProOne. Combine with UV purifiers for extra biological kill power, or distillation setups for the toughest contaminants. Portable filters like Katadyn Pocket are great for bug-out bags.
  • Alternative Sources: Diversify beyond the tap. Set up rainwater catchment with barrels or tanks—simple gutters and food-grade containers can harvest hundreds of gallons during storms. If you’re in a position to drill a shallow well, do it. Coastal folks: look into portable desalination kits (hand-pumped or compact units like QuenchSea or emergency marine desalinator packs) for turning seawater usable in a pinch. Scout and map local natural sources—ponds, streams, rivers—note distances, risks, and access. In urban areas, carry a multi-tool and water spigot key to discreetly access commercial faucets (handles often removed to deter misuse—only for true emergencies, and be smart about it). For more on urban resupply tactics, including plotting routes, finding hidden sources, and escape planning, check out my older piece: Urban Resources: Finding Food & Water During a Long-term Disaster.
  • Home Security: Water storage and systems are tempting targets—secure tanks, pipes, and access points against tampering or theft. For off-grid setups, build in redundancies: multiple filters, backup storage, solar-powered pumps if possible. Fortify your property with basic perimeter measures and early-warning tools.
  • Prepper Communities and Monitoring: Prep isn’t solo—link up with local groups, neighbors, or mutual aid networks for shared resources and intel. Download the FEMA App for real-time weather alerts, emergency tips, shelter locations, and disaster updates—it pulls National Weather Service data and can notify you of water-related threats..

Read the full article here