Read this before you share it. The "30 locations in 7 states" headline
conflates two different numbers. The 30-plus (investigators now say ~36) is
Minnesota alone . Separately, the FBI/EPA said utilities in at least seven
states reported incidents since July 27 — and the federal agencies have not
named those states . Two of the seven are known only because the states
identified themselves: Minnesota, and Michigan on August 1. Only four exact
locations exist in public reporting, all in Minnesota. Every other point on this
map would be a guess, so it isn't here.
Confirmed locations
Not disclosed
~31 systems · 2 states
Roughly 32 of Minnesota's ~36 affected systems have not been identified, and the
state has now said they won't be: MNIT and the Minnesota Department of Health
classify cyberattack reports as
nonpublic under state law . Michigan
disclosed nine affected systems on August 1 and named none of them either. That
leaves five of the seven states unnamed, and still no utility outside Minnesota
self-disclosed.
There is no public source that maps to 30 pins. If a map claims otherwise, it invented them.
Timeline
Jul 26–27 Overnight intrusions hit 30+ (now ~36) Minnesota community water and wastewater systems.
Jul 27 Braham, Plymouth, South St. Paul and Maple Plain disclose. Maple Plain declares a local state of emergency.
Jul 27→ Utilities in at least seven states begin reporting similar internet-facing PLC incidents to the FBI.
Jul 30 CISA alert AA26-097A: disconnect PLCs from the internet now . FBI/EPA public service announcement names Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 as targeted devices.
Jul 30 Preliminary US assessment points to Iranian actors; researchers flag CyberAv3ngers (IRGC-CEC). No formal attribution.
Jul 31 FBI confirms the seven-state footprint publicly. States still unnamed.
Aug 1 Michigan reports nine of its water systems were targeted — the second state to identify itself. EGLE says all "continued to operate safely." No utility named. Wisconsin's DNR warns utilities of ongoing PLC-targeted activity but reports no confirmed compromise .
Aug 1 Minnesota Department of Health will not release the list: cyberattack reports are nonpublic under state law. The other ~32 Minnesota systems may never be named.
How they got in
Internet-exposed programmable logic controllers — the boxes that run
pumps, valves and chemical dosing. Attackers changed IP addresses and passwords to lock
operators out of their own equipment, and in at least one case modified PLC project
files (ladder-logic discrepancies found across several sites). CISA assessed the likely
intended effect as loss of system pressure and potential contamination .
No contamination has been reported. Cited CVEs: CVE-2021-22681 (unpatchable on affected
Rockwell models), CVE-2023-3595, CVE-2024-6242.
Grey pins: earlier 2026 incidents
Toggle the "Earlier 2026 incidents" layer to see attacks that are frequently pulled into
coverage of this one but are separate events : the June 12 Handala claim
against California water utility billing systems (no OT compromise, no service
impact) and a June ransomware incident at a Minot, North Dakota treatment plant. Neither
belongs in a count of this week's attack. Reported California city lists differ by outlet.
Sources