Skip to main content

Sweeping cyberattack on water systems in multiple states has US officials on edge

(CNN) — Hackers have targeted water systems in several US states in a coordinated cyberattack that has caused some utilities to issue boil-water notices and switch to manual mode, taking their systems offline, according to US officials.

It’s one of the most serious cyberattacks on water systems in the US in years, according to some analysts. The US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Environmental Protection Agency have for the last week been scrambling to try to help secure the water facilities and ensure that the safety of drinking water isn’t affected. No incidents of contamination have been reported.

The hackers “are targeting water entities of all sizes,” CISA said in a warning Thursday that urged water facilities to get vulnerable industrial equipment offline.

US and state officials are treating Iran as one of the suspects behind the hack, but have not made a formal determination of who is responsible and are wary of false flags.

The first public sign of the cyberattacks came from Minnesota authorities, who said that hackers on Sunday night and Monday morning targeted about 30 water systems in that state. The “likely desired impact” of the hackers’ intrusion at the water facilities was “to cause loss of system pressure and subsequent potential contamination of water supply,” said the memo distributed this week by the Minnesota Bureau of Criminal Apprehension and obtained by CNN.

At a cabinet meeting Friday, President Donald Trump blamed Minnesota authorities for the hack and cast doubt on whether Iran was involved. “They like to say, “Oh, it’s Iran.’” Trump said. “Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

The New York Times first reported on the possible Iran connection.

The hackers are targeting internet-facing programmable logic controllers (PLCs), the devices that allow machinery to communicate at water facilities and other industrial plants. PLCs monitor water pressure, chemical dosing and other features in water systems to ensure they are safe.

The hacks are not complicated: The attackers are breaking into PLCs that are sitting online and vulnerable.

“I suspect that those attackers are going to … continue to look nationally across the infrastructure,” John Israel, Minnesota’s chief information security officer, told CNN on Tuesday. The hackers will “continue to rattle those doorknobs and try to break into systems that have weak configurations,” Israel added.

He was right.

Roughly six states have reported related cyber incidents over the last week, according to multiple sources familiar with the investigation.

Officials in Wisconsin detected malicious cyber activity at their water facilities on Monday and urged utilities to take “immediate action to prevent potentially serious impacts to our systems,” according to a memo from the state’s Department of Natural Resources obtained by CNN.

The incident is another in a series of recent cyberattacks that have raised safety concerns for US water utilities. The water sector has for years struggled with funding and training to defend itself from cyber threats.

The Water Information Sharing and Analysis Center (WaterISAC), an industry hub for cyber threat data, has urged utilities to shore up their systems in the last week.

“The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented,” Gus Serino, a longtime cybersecurity specialist focused on the water sector told CNN.

“While the inherent resilience of the water sector helped limit operational impacts, these incidents once again demonstrate that many drinking water utilities continue to rely on technology architectures that lack fundamental cybersecurity controls capable of preventing or significantly impeding this type of attack,” Serino said.

While the US government has not blamed anyone for the spate of hacks, Iran does have a history of hacking the water sector, including during the current war with the US.

In April, CNN reported that Iran-linked hackers had successfully targeted and caused disruptions at multiple US oil and gas and water sites.

“The rising number of water compromises is deeply concerning. So much depends upon water… No water, no hospital, no kidding… in 2-4 hours,” Joshua Corman, another industrial cybersecurity expert who co-founded I am the Cavalry, a volunteer group that focuses on cybersecurity for resource-poor organizations.

“Water systems have enjoyed the benefits of remote access, but now those who wish us harm have it, too,” Corman told CNN. “With great connectivity comes great responsibility. We should be asking ourselves: if we can’t protect it, should we disconnect it?”

This story has been updated with additional developments.

The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.

Once peruanos murieron combatiendo por Rusia y otros 114 están desaparecidos, dicen autoridades de Perú

Once peruanos han muerto, 114 están desaparecidos y tres fueron capturados por el Ejército ucraniano después de enlistarse en las fuerzas armadas rusas, informó el Ministerio de Relaciones Exteriores de Perú. La Cancillería señaló que, oficialmente, 459 ciudadanos peruanos se han enlistado en las fuerzas armadas rusas.El nuevo balance fue difundido mientras el Gobierno anunciaba la repatriación de dos jóvenes peruanos que, según la Cancillería, escaparon del reclutamiento forzado al que fueron sometidos para prestar servicios en la guerra contra Ucrania.El consulado de Perú en Rusia “asistió y gestionó la repatriación de dos jóvenes peruanos en situación de vulnerabilidad, que fugaron del reclutamiento forzado del que fueron víctimas”, señaló la cancillería en un comunicado.“Todos ellos arribaron al Perú y se encuentran con sus familias”, añadió.Los jóvenes se suman a otros dos peruanos atendidos a finales de julio por la sección consular de la Embajada del Perú en Rusia. En total, la Cancillería informó que 31 peruanos han sido evacuados: 28 regresaron al Perú y tres permanecen en Europa por “decisión propia”.El Ministerio también pidió a los ciudadanos tener cuidado con las ofertas de trabajo en el extranjero. “Se alerta a la ciudadanía a no dejarse engañar por falsas ofertas laborales, pues podrían caer en redes delictivas de trata”, señaló la Cancillería. El Gobierno recordó además que prestar servicio militar para un Estado extranjero requiere autorización previa.El anuncio llega después de meses de reclamos de familias que buscan información sobre sus parientes. CNN habló recientemente con 12 familias peruanas que han participado en protestas y vigilias frente a la Embajada de Rusia en Lima y ante el Ministerio de Relaciones Exteriores.Los testimonios recogidos muestran que algunos hombres viajaron a Rusia después de recibir ofertas de trabajo como cocineros, guardias de seguridad u otros empleos de civiles. Sus familiares dijeron que no esperaban que terminaran vinculados a las fuerzas rusas y, en algunos casos, enviados al frente.Pedro Bravo, director de Comunidades Peruanas en el Exterior de la Cancillería, dijo a CNN que muchos de los reclutas provienen de entornos empobrecidos y con una necesidad urgente de dinero, lo que puede hacerlos más vulnerables a este tipo de ofertas. “Es mucho más fácil engañarlos”, dijo.Una de las madres entrevistadas por CNN, identificada como Norma, contó que su hijo de 31 años viajó a Rusia después de aceptar un supuesto trabajo como cocinero para el Ejército ruso. Poco después comenzó a enviarle fotografías y videos en los que aparecía con equipo militar, cavando trincheras y construyendo refugios.A principios de abril dejó de enviar mensajes.“Tengo esta luz de esperanza de que está en algún lugar, escondido en una trinchera, pero realmente no lo sé”, dijo Norma a CNN.Ante las denuncias, la Fiscalía peruana anunció en mayo que investiga el reclutamiento ruso por posibles casos de “trata de personas”.Percy Salinas, un abogado que representa a algunas familias de los reclutas, entregó a CNN una copia de una orden fiscal que describe el alcance del caso judicial.Las autoridades están investigando 36 denuncias de ciudadanos peruanos que afirman que sus familiares o amigos fueron engañados “mediante ofertas de trabajo falsas en el extranjero —específicamente en la Federación Rusa— con el propósito de transportarlos fuera del país y someterlos a… participación forzada en un conflicto armado entre Rusia y Ucrania”, según la orden.La fiscalía declinó hacer comentarios sobre el caso cuando fue contactada por CNN.Bravo, del Ministerio de Relaciones Exteriores de Perú, dijo a CNN que el Gobierno había realizado al menos 247 solicitudes a Moscú para obtener información sobre peruanos incorporados a las fuerzas rusas y ha exigido “el regreso inmediato y seguro de nuestros compatriotas a su país de origen, dado que salieron sin la debida autorización”.Rusia ha dicho que “respeta profundamente la decisión de ciudadanos extranjeros de participar en la defensa de la soberanía y seguridad (rusas)”.“La embajada reafirma su permanente disposición a tomar todas las medidas necesarias para obtener información lo más rápido posible en base a solicitudes presentadas formalmente”, dijo la Embajada de Rusia en Lima en un comunicado de abril sobre las “preocupaciones de las familias peruanas”.The-CNN-Wire™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.
Read Next Story