Under the Surface: The 2026 Water-System Cyberattacks and Where Lodi Stands

Under the Surface: The 2026 Water-System Cyberattacks and Where Lodi Stands

Overview

In the last week of July 2026, hackers reached into the control systems of water utilities in at least seven states, locked operators out of their own equipment, and forced treatment plants to run by hand. Minnesota took the brunt of it — more than thirty community water systems in a single 48-hour window. No ransom was demanded, no one's drinking water was contaminated, and in the towns hit hardest, the taps kept running.

Lodi runs the same kind of automated, widely dispersed water system these attackers target. It also has the redundancy and manual fallback that kept water flowing everywhere the attacks landed: two independent sources, dozens of wells, local storage, and deep upstream reserves. This report explains the attacks, how long they actually disrupted service, how Lodi's water and its upstream sources are built, where Lodi fits the target profile, and what residents can watch for and do now.

What happened

The first public sign came from Minnesota. State IT officials disclosed that a coordinated cyberattack had struck the operational technology at more than thirty community water systems on July 26 and 27, triggering a statewide response. Four cities described the impact publicly: Braham, Plymouth, South St. Paul, and Maple Plain. Minnesota's chief information security officer later put the count at roughly thirty-six affected systems.

Within days the picture widened. On July 30, the FBI and the Environmental Protection Agency issued a joint public service announcement warning that water and wastewater utilities in at least seven states had reported incidents since July 27, some of which degraded water operations. The advisory did not name the states. Beyond Minnesota, officials and reporting have since surfaced incidents or related activity in Michigan, Wisconsin, South Dakota, and California — and the FBI's "at least seven" phrasing signals that more may remain undisclosed.

Two things set this campaign apart from the ransomware attacks that usually make headlines. It went after operational technology — the systems that physically monitor and control pumps, valves, and pressure — rather than billing or business networks. And no ransom was demanded. Analysts reading the public evidence described the intent as disruption, not money.

How the attacks work

Water plants rely on small industrial computers called programmable logic controllers, or PLCs, to open and close valves, run pumps, and track pressure. The federal advisory named the equipment: internet-facing Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 series controllers, legacy devices still deployed by the thousands across U.S. water, manufacturing, and municipal systems. The FBI said it had only observed the activity on those Rockwell models but that operators of other brands should take the same precautions.

The method was consistent. After reaching controllers exposed directly to the internet, the attackers changed the devices' IP addresses and set passwords — actions that disconnected operators' monitoring systems and locked them out of their own equipment. The result was a loss of "view," and in some cases a loss of control.

A smaller group of victims saw something worse. At least one utility found that attackers had modified the PLC project files themselves, altering the ladder logic — the program that tells physical equipment what to do. That change matters because it can survive a password reset: the program running on the device has itself been rewritten. It is the one path in this campaign that turns a quick recovery into a longer forensic rebuild.

The multiplier. The federal advisory flagged a systemic factor: across several victims, similar network setups installed by third-party vendors let attackers repeat one success across many customers. When a single integrator deploys the same exposed configuration to dozens of small systems, that shared template becomes a shared weakness — the mechanism that turned "one town" into "thirty towns" in Minnesota.

The reported physical effects were loss of pressure and, in some cases, flooding. Pressure loss carries a theoretical risk of drawing untreated groundwater into pipes, which is why boil-water notices exist as a precaution — but no contamination has been reported in any confirmed case.

How long the disruption actually lasted

This is the finding that should anchor how residents think about the threat. Where details are public, the disruption to automated control lasted hours to about two days, while water service itself was largely preserved.

  • Braham (about 1,700 residents): the attack disabled computerized controls and briefly took the well and treatment plant offline. Crews isolated the affected system, restored a backup, and restarted within roughly ninety minutes to two hours. The city's tower holds about two days of supply, and residents saw no loss of service.
  • Plymouth (about 80,000 residents): after compromised controllers turned up at two water towers and more than a dozen sewer lift stations, the city disconnected the affected equipment and switched to manual operation. Systems were back online within about two days, and water quality, treatment, and pressure were never affected.
  • South St. Paul and Maple Plain: both kept normal water and wastewater operations running through manual procedures despite affected automated controls. Maple Plain declared a local emergency to widen its response.

How long the disruption lasted: time to restore automated control

Source: Minnesota IT Services and city statements, July 2026. South St. Paul and Maple Plain maintained water service through manual operation, so they carry no service-restoration figure.

In every confirmed Minnesota case, officials said drinking-water quality was never affected and no boil-water advisories were issued. Analysts credited the quick, clean recoveries to the manual safety controls built into most water facilities — the ability to send staff to run the plant by hand when the computers go dark. The realistic profile, then, is hours-to-days of degraded automation with service preserved, not days-to-weeks of dry taps, as long as a utility can staff manual operation and has storage to draw on. The ladder-logic case is the exception that can stretch recovery, which is why "we went manual and recovered in two hours" is the good outcome rather than the guaranteed one.

How Lodi's water system is built

Lodi draws from two independent sources: groundwater from a field of wells, and treated surface water from the Mokelumne River. Since the surface plant came online in 2012, the blend has run close to half and half, with each source's share shifting year to year.

The wells are computer-controlled and start automatically on water-pressure demand: as use rises, more wells come online. The surface plant is a membrane facility, heavily instrumented by design. Both draw from entirely different physical systems — the river on one side, the Eastern San Joaquin groundwater subbasin on the other — which is the root of Lodi's resilience.

ComponentDetails
Groundwater wells25 operational (28 built), spaced about a half-mile apart; individual capacity 1.2–3.0 MGD; combined capacity about 55.5 MGD; nine wells carry Granular Activated Carbon filtration
Surface water plantMembrane treatment, 8 MGD design / 10 MGD maximum; online since 2012; raw water pumped from the Woodbridge Irrigation District intake on the Mokelumne River
Finished-water storageTanks at Well 23 (Maggio Circle, since 2020) and Well 28 (Kettleman Lane and Westgate Drive)
Contracted river supply6,000 acre-feet per year purchased from WID since 2003, about $1.2 million annually
WastewaterWhite Slough Water Pollution Control Facility (built 1966), 8.5 MGD dry-weather capacity, serves Lodi plus Flag City (about 67,000 people), discharges tertiary-treated water to the Delta; processes are largely automated

The upstream chain

Lodi sits near the bottom of a long, multi-operator river system. Understanding who controls the water upstream shows where risk does and does not concentrate.

FacilityOperatorRole
Pardee Dam (1929)East Bay Municipal Utility District345-foot dam where the Mokelumne enters EBMUD's system; holds about 198,000 acre-feet
Camanche Dam (1964)East Bay Municipal Utility DistrictEarthen dam holding 417,120 acre-feet; releases meet downstream fishery and flow obligations
Woodbridge Diversion DamWoodbridge Irrigation DistrictImpounds Lodi Lake and diverts river water into WID canals; the same structure that makes Lodi Lake makes Lodi's surface supply possible
Surface Water Treatment FacilityCity of LodiTreats WID-diverted river water and feeds Lodi's distribution system

EBMUD's 82-mile Mokelumne Aqueduct carries most of this water across the valley to about 1.4 million East Bay residents; Lodi's contracted 6,000 acre-feet is a small slice of the flow. The chain runs through at least three independent operators, each with its own separate control systems. A problem at any one does not automatically reach the others. There is also a standing water-rights dispute in the background: WID sued EBMUD in 2018 over Mokelumne releases, arguing its older licenses carry seniority. That is supply politics, not cybersecurity, but it is part of the map of who controls the water.

Where Lodi and its suppliers fit the profile

This report treats the specific configuration of Lodi's and its suppliers' control systems as out of scope. The fit below is drawn at the level of asset class, not device detail.

By category, Lodi is the kind of utility this campaign targets: an automated system with dispersed, remotely monitored assets. Its wells run automatically on pressure demand, its surface plant is membrane-based and heavily instrumented, and its wastewater plant is automated. Wells at half-mile intervals, plus towers, storage, and lift stations reporting to central monitoring, mirror the topology hit in Plymouth. Lodi belongs to the same category of system that came under attack and carries the generic exposure any dispersed, automated utility does.

The upstream suppliers sit in different tiers. WID operates physical diversion infrastructure with its own control elements, but it is an agricultural-delivery district — a smaller, less-hardened class of operator. EBMUD runs major dams, hydropower, and a long aqueduct; it is heavily instrumented but also large, well-resourced, and mature on security, which makes it a far harder target than a small municipal well field. The most relevant upstream risk is not a dramatic dam attack. It is the same third-party-integrator weakness applied to the many small community and mutual water systems around San Joaquin County that may share vendors and templated setups.

Why Lodi is well-hedged

For a city its size, Lodi carries unusual redundancy, and that redundancy limits the consequence of any single control-system compromise. The two sources are separable, and the groundwater side alone can carry the city: the wells' combined capacity dwarfs the surface plant's output.

Lodi's treatment and pumping capacity, by source

Source: City of Lodi water-system documents. Groundwater figure is combined well capacity; surface figure is the plant's maximum output.

A compromise of the membrane plant does not stop the wells, and a problem on the river side does not touch the groundwater. With wells spread across the city, no single well is critical, and finished-water storage provides the same kind of buffer that let Braham ride out its outage on tower supply. Upstream, hundreds of thousands of acre-feet sit behind Camanche and Pardee, and EBMUD's own system has a dry-year fallback to Sacramento River supply.

One structural vulnerability sits outside all of this, and it is long-term rather than cyber: the Eastern San Joaquin subbasin is critically overdrafted, so the "just run the wells" fallback has limits over extended periods. That is a supply-sustainability problem, and it is the reason the surface source matters and cannot be treated as optional.

Who is behind the attacks

Attribution is preliminary and contested. U.S. investigators believe Iranian-linked actors were probably responsible for the Minnesota attacks, according to reporting citing state and federal officials, while cautioning that the assessment could change as evidence develops. Investigators are also weighing whether an actor deliberately made itself look Iran-based to inflame tensions during the ongoing U.S. conflict with Iran.

The circumstantial case rests on pattern and timing. Researchers said the operation resembled the tactics of CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps that has targeted U.S. water infrastructure since at least 2023 and drew U.S. Treasury sanctions in early 2024. The United States entered open conflict with Iran on February 28, 2026, followed by an April ceasefire, and days before the Minnesota attacks an Iran-linked group warned that U.S. water, electricity, and transportation networks would be targeted.

There are reasons for caution on both sides. No group has claimed the Minnesota attacks, a break from the usual practice of posting proof, which several analysts found notable. And President Trump publicly dismissed the idea that Iran was responsible, arguing investigators had not yet established who did it. The honest state of knowledge is probable but unproven. Iran-linked actors do carry a documented history against U.S. water systems, from a 2013 intrusion into a dam's controls in Rye, New York, to the 2023 shutdown of pumping equipment in Aliquippa, Pennsylvania — the latter by exploiting internet-connected controllers whose default passwords had never been changed. That last detail is the recurring theme: the equipment was reachable from the internet and poorly secured.

The questions that remain open

The public record shows that Lodi's water and wastewater systems are automated and dispersed — the general profile these attacks exploit. What the record cannot answer, and what would decide actual vulnerability, is a short list only the utility can address on the record:

  • Are any control devices or well-telemetry units reachable from the public internet, or do they sit behind a secure gateway and firewall?
  • Is the operational-technology network segmented from business IT and the internet?
  • Which vendor or integrator maintains the control systems, and is a shared configuration used across multiple sites?
  • Has the city rehearsed manual operation of its wells and plants for a scenario in which automated controls go dark?
  • Has the city acted on the July 30 FBI/EPA advisory and the related CISA guidance to remove any exposed controllers from direct internet access?

These are answerable without anyone disclosing a vulnerability, and the answers turn "the attack surface exists" into a specific, qualified risk level. They are the readiness core of the story.

What residents should watch for — and prepare for

The honest headline is low alarm, basic preparedness. No U.S. resident has lost safe drinking water to one of these attacks, and Lodi's redundancy makes it a poor candidate for an actual shutoff.

Watch for these, from official sources only: a boil-water notice or any request to cut water use from the City of Lodi or San Joaquin County; noticeably low pressure or discolored water, which residents should report to Lodi Public Works rather than diagnose themselves; and any announcement that the city has switched to manual operations. One media-literacy point matters here: threat groups sometimes post exaggerated claims online — as happened earlier this year when a group claimed a California water breach the utility said never touched its supply networks — so unverified "our water was hacked" posts deserve skepticism until the utility or county confirms.

Prepare with ordinary, all-hazards readiness that works the same for earthquakes, floods, and outages. Keep an emergency water supply on hand; the common federal benchmark is one gallon per person per day for at least three days. Rotate stored tap water about every six months. And sign up for the city's and county's official alert systems so information reaches you from the source rather than from rumor. Households that take those steps are covered for the realistic worst case here, a short and localized interruption.

How you'd hear about it: Lodi's notification channels

If something did go wrong with the municipal water supply, residents would not be left to find out on their own. Lodi and San Joaquin County run several notification channels, and it helps to know which to trust and how each works.

The primary emergency channel is SJReadyAlert. Lodi joined with San Joaquin County to run a free automated notification system powered by Everbridge, at SJReady.org. It sends alerts about emergencies and public-safety events through whatever contact paths a resident picks: cell phone, text, home phone, email, or TTY/TTD. Residents whose numbers are in the county's 911 database are enrolled automatically for phone alerts, and self-registration adds a cell number, email, or text, lets you choose which cities and message types you receive, and lets you list several addresses.

The one action worth taking today. Automatic enrollment reaches phones in the 911 database, which increasingly leaves out cell-only households, internet-based (VoIP) phone users, and anyone who kept an old number after moving to Lodi. Those residents get nothing unless they self-register at SJReady.org. It takes a few minutes and closes the gap.

Water-specific advisories follow a legally required timeline. Beyond the general alert system, drinking-water systems operate under the public-notification rules of the Safe Drinking Water Act, administered in California by the State Water Board's Division of Drinking Water. The rules set a tiered schedule by severity.

  • Tier 1 — urgent: for acute risks such as a boil-water situation or confirmed contamination, notice must go out as soon as practical and within 24 hours, by the fastest available means — broadcast media and, for a problem confined to certain streets, door-to-door notice or door hangers.
  • Tier 2 — within 30 days: for non-acute violations that matter but pose no immediate health risk.
  • Tier 3 — annual: routine reporting, including the yearly Consumer Confidence Report Lodi already publishes.

City channels carry the same information. Expect notices on the City website at lodi.gov and on the city's official social media, with direct outreach from Lodi Public Works and the water utility. The Lodi News-Sentinel and Sacramento- and Stockton-area television and radio amplify anything significant.

The Minnesota response shows what a cyber incident would likely look like to the public. There, utilities moved operationally first — isolating equipment and switching to manual operation — and issued public notice only where service, quality, or pressure were actually affected. In several cities where automated controls were hit but service held, officials still posted proactively that the water was safe and that residents did not need to change anything, without any formal advisory. So in a Lodi scenario, the more likely message is reassurance rather than a warning, unless pressure or quality were actually compromised. The practical takeaway: the absence of a boil-water notice is itself information, and official confirmation should outweigh unverified online claims in either direction.

The bottom line

The July 2026 attacks were a real escalation: coordinated, disruption-focused, and aimed straight at the small industrial computers that run America's water. They also showed the limits of that kind of attack against a utility built with redundancy and staffed to go manual. Lodi shares the profile of the systems that were hit. It also shares the qualities that kept water flowing everywhere the attacks landed — two independent sources, distributed wells, local storage, and deep upstream reserves.

The threat is real, the consequences so far have been contained, and the meaningful work is preparation — the utility's and the public's. That is the frame this issue deserves: not fear, but readiness.

LodiEye is the original civic-reporting and analysis arm of Lodi411.com, a citizen-run civic data and transparency platform serving Lodi, California and San Joaquin County. LodiEye gathers information of public interest, applies editorial judgment to public records, meetings, and data, and publishes original explanatory reporting for its readers — the work of a newsroom, and a representative of the news media as that term is defined under federal law. Our reporting emphasizes primary sources, public data, and full source transparency so readers can check every claim. LodiEye complements, and does not replace, the other outlets covering this region; for additional reporting on Lodi, San Joaquin County, and the broader region, we also encourage readers to consult the Lodi News-Sentinel, Stocktonia, The Sacramento Bee, CalMatters, and other established news organizations. Our full editorial standards and news-media-status statement is published at lodi411.com/editorial-standards.

This LodiEye investigative report was produced using artificial intelligence tools under the direction and review of the founder. Lodi411 uses multiple AI platforms in its research and publication workflow, including Anthropic's Claude (primarily Opus and Sonnet models) and Perplexity AI across a variety of large language models offered by each. These tools were used in the following capacities:

Source Discovery: AI-assisted search and retrieval identified roughly two dozen primary and secondary sources, including the July 30, 2026 FBI/EPA public service announcement, CISA industrial-control-system advisories, statements from Minnesota IT Services and affected city officials, contemporaneous reporting from Reuters, CBS News, the Star Tribune, and others, and City of Lodi, Woodbridge Irrigation District, and East Bay Municipal Utility District records on the local water system. Perplexity AI was used for initial source discovery and real-time data retrieval; Claude was used for deeper analysis of identified sources.

Credibility Validation: AI cross-referenced claims across multiple independent sources, prioritizing federal agency advisories, state and municipal records, and established news reporting over secondary aggregation. Multiple AI models independently verified key data points — the affected states, the equipment named in the federal advisory, restoration times, and Lodi's supply figures — and flagged inconsistencies for editor review.

Analysis and Synthesis: Claude Opus and Sonnet assisted in mapping the national attack profile onto Lodi's specific water-system architecture, assessing the redundancy that limits local risk, and breaking down the notification pathways residents would encounter. The analysis deliberately kept the specific control-system configuration of Lodi and its suppliers out of scope, separating what the public record establishes from what it cannot.

Presentation: Claude assisted in drafting, structuring, and formatting the report for clarity and readability, including the supply-capacity and restoration-time charts, the system and upstream reference tables, and the tiered-notification breakdown.

Final Review: Multiple AI models reviewed the completed draft for factual consistency, source attribution accuracy, logical coherence, and balanced presentation. Throughout the process, the editor sets the report's goals, scope, and tone; creates and shapes draft content; reviews and edits the report; integrates independent fact checks; and reviews the AI cross-checks and validations. Multi-tool cross-checking across independent models and sources is the primary error-reduction mechanism.

Lodi411/LodiEye believes that transparency about how our research is produced — including our use of AI under human direction — strengthens trust with readers and the broader information ecosystem. Readers who spot an error are encouraged to write editor@lodi411.com so we can correct it.

Previous
Previous

The Delivery Decade: How Food Delivery Apps Reshaped Lodi Restaurants, Wages, and Tasting Rooms

Next
Next

It's Here: El Niño Arrives Ahead of Schedule — and the Forecast Keeps Climbing