Power Grid

US water and energy control systems — PLC exploitation campaign

7 April–10 August 2026

United States (at least twelve states; 30+ Minnesota and nine Michigan systems reported)

What happened

Federal agencies issued joint advisory AA26-097A on 7 April and expanded it on 22 July, documenting an Iran-affiliated campaign against internet-facing programmable logic controllers at US water, wastewater, energy and government facilities. The update widened the affected equipment from Rockwell Automation/Allen-Bradley devices to Schneider Electric and Siemens systems, described project-file exfiltration and malicious project files, and noted cases where altered programming disabled shutdown and alarm functions or manipulated HMI/SCADA displays. On 26–27 July, coordinated intrusions affected operational technology at more than 30 Minnesota community water systems: one plant went temporarily offline, other operators switched to manual control, and Braham, Plymouth, South St. Paul and Maple Plain were named publicly. Minnesota officials reported no effect on water quality or safety. By 10 August, Dark Reading reported related attacks across at least twelve states, with disclosed activity in Minnesota, Georgia, Michigan, South Dakota, Alabama and New Jersey. Attackers reportedly changed PLC passwords and IP addresses, locking some operators out of remote visibility and control and forcing manual workarounds. The most consequential publicly reported case was in Clayton County, Georgia, where cyber activity was linked to a water-pressure drop and a boil-water advisory. Michigan reported nine affected systems, all operating safely and without a public-health concern. No definitive attribution has been announced for the latest multistate intrusions: researchers noted similarities to earlier IRGC-linked CyberAv3ngers activity, while federal authorities continued to treat attribution as unresolved. The affected water utilities are normally outside this map's core energy scope; this campaign is retained because the same documented activity targets energy facilities and shared industrial-control equipment.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Reported / attributed
Confidence
Moderate
Infrastructure
Power Grid
Latitude
46.0000°
Longitude
-94.6000°

Attribution

Responsibility disputed Iran-affiliated actors suspected; incident attribution unresolved

Federal agencies associate the broader PLC campaign with Iran-affiliated actors tracked as CyberAv3ngers or Hydro Kitten. The FBI had not publicly attributed the Minnesota and Michigan intrusions to a specific actor when this record was updated; state and municipal investigations remained active.

Sources

  1. Iran-Affiliated Threat Actors Targeting Critical Infrastructure PLCs (AA26-097A)CISA, FBI, NSA, EPA, DOE and USCYBERCOM joint advisory · Incident reporting
  2. Multistate Water System Attacks Widen, Iran SuspectedDark Reading · Updates the campaign to at least twelve states and documents manual workarounds, the Clayton County pressure drop and the unresolved attribution
  3. Cyberattacks disrupt dozens of Minnesota water systems as Michigan reports nine affected utilitiesCISA, FBI, NSA, EPA, DOE and USCYBERCOM joint advisory · Video report