Skip to content
Beveiligingsnieuws

Coordinated cyberattack disrupts 30+ Minnesota water systems

gecommitteerde cyberaanval water

More than 30 community water systems across Minnesota were affected by a coordinated cyberattack over July 26 and 27, according to Minnesota IT Services (MNIT). The incident triggered a statewide cybersecurity response as officials worked to contain impact, investigate what happened, and coordinate recovery efforts with multiple partners.

While the overall pattern points to coordinated activity, the effects were not identical across every site. Some facilities reported plants going offline, communications disruptions, or problems with automated controls, while others continued operating with manual procedures.

What happened across Minnesota

MNIT confirmed that the coordinated cyberattack impacted over 30 water systems statewide. Officials said the nature and extent of disruption varied from one system to another, and that investigators were still determining how many sites experienced operational interruptions.

Several communities publicly described issues linked to the event. Braham reported its water plant went offline, and the city asked residents to limit water usage until treatment resumed. Plymouth described cellular communications problems affecting water towers and multiple wastewater lift stations, but said it continued operating manually.

South St. Paul and Maple Plain also reported impacts tied to utility automation. Both maintained services after automated utility controls were affected, but Maple Plain declared a local state of emergency to support its response.

Emergency response and public guidance

Because critical infrastructure is involved, MNIT coordinated a broader response with state agencies and major federal partners. The goal was to contain the incident, support recovery, and share threat intelligence so other systems could reduce the risk of more serious outcomes.

In the days following the attacks, Minnesota officials did not publicly identify the attacker, the specific products involved, the vulnerability that may have been exploited, or whether any data was stolen. MNIT also stated that, as of July 28, it was not aware of any active requests for residents to change their drinking-water use.

That said, at least one locality did ask residents to adjust water use temporarily. Braham’s public message to residents reflected a practical response to its plant being taken offline until treatment could resume.

Why investigators call it coordinated

MNIT said the incidents shared common characteristics, including their timing, how attackers gained access, and the type of infrastructure targeted. According to the agency, those similarities supported the state’s assessment that the activity was coordinated rather than isolated.

Investigators also recognized overlaps in how the systems were accessed. However, MNIT said it would not share specific technical details while the investigation is ongoing, and attribution has not been finalized.

MNIT added that the shared features align with activity observed by federal partners in other states and industries. Still, investigators were not yet able to determine whether one single actor was responsible for all incidents.

Containment, recovery, and threat intelligence sharing

MNIT described a coordinated response that included containment steps, investigation, recovery support, and threat-intelligence sharing. The agency said it was working with state entities as well as federal partners including CISA, the Environmental Protection Agency, the Federal Bureau of Investigation, and affected utilities.

MNIT’s statement emphasized that critical-infrastructure cyberattacks require a whole-of-government approach. The response, the agency said, helped partners contain the incident and reduce the likelihood of more severe impacts to critical services.

Potential link to broader PLC-targeting activity

Several days before the Minnesota event, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers (PLCs) from multiple vendors, including Rockwell Automation, Schneider Electric, and Siemens. Investigators in that earlier campaign reported behaviors such as exfiltrating and altering project files, manipulating displays in human-machine interfaces and supervisory control and data acquisition (SCADA) systems, and disabling shutdown and alarm logic.

In the separate Minnesota investigation, officials have not publicly connected the Minnesota attacks to that earlier campaign. However, security firm Tenable said the timing and operational pattern it observed were consistent with the broader CyberAv3ngers threat ecosystem, while also stressing that the incident had not been officially attributed.

Tenable’s research engineer Scott Caveza noted that tactics reportedly align with tradecraft attributed to CyberAv3ngers and other groups associated with IRGC-CEC. These groups have been known to target critical infrastructure since at least 2023.

FBI and EPA warning: internet-facing PLC incidents in multiple states

On July 30, the FBI and EPA issued a separate warning describing PLC-related incidents reported since July 27 in at least seven states. That advisory focused on activity involving internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs.

The FBI reported it had only observed the behavior with those specific models, but operators using other PLC brands were advised to apply similar protective measures. The warning indicated that attackers remotely changed PLC IP addresses and passwords, which led to loss of monitoring and control.

Some incidents reportedly degraded water operations, including effects such as loss of pressure and flooding. At least one organization also identified modified PLC project files after noticing ladder-logic discrepancies across several sites.

Neither the FBI nor the EPA connected that PLC activity publicly to the Minnesota attacks, and neither advisory named an attribution to CyberAv3ngers or another actor.

CISA guidance for defensive action

In addition to the sector-wide warning, CISA provided defensive guidance intended to reduce risk from similar PLC-related intrusions. The recommendations include monitoring and logging cellular modem connections, restricting controller access to authorized systems, and inspecting running project files for unauthorized changes.

CISA also advised operators to validate backups before restoring systems. For environments with a physical mode switch on a controller, the agency recommended placing it in run mode only after validating project files.

These steps focus on limiting exposure, improving visibility, and verifying that control logic has not been tampered with before returning operations to normal.

Status of the Minnesota investigation

As of July 29, 2026, MNIT said the investigation remained active and responders were continuing to assess impacted systems. Officials did not publicly identify the specific PLC family, access method, or vulnerability used in the attacks.

Updates to the reporting included comments from MNIT and Tenable. A further update on July 31 added the FBI and EPA’s separate warning about internet-facing PLC attacks reported across at least seven states.

What operators and communities can take away

The main lesson from this coordinated cyberattack is that operational technology in water and wastewater systems can affect real-world services quickly—even when public effects differ by location. Some facilities may continue running manually, while others experience outages that require urgent operational changes.

For utilities, the recommended direction remains consistent with broader guidance: reduce unnecessary remote exposure, strengthen access controls, improve monitoring of communications pathways, and verify PLC project integrity using known-good baselines and validated backups.

For residents and local leaders, timely communication matters as much as technical response. Clear guidance—such as temporary conservation requests when a plant is offline—can help reduce risk during periods when treatment operations are interrupted.

Conclusion: A coordinated cyberattack disrupted operational technology at more than 30 Minnesota community water systems, leading to a statewide cybersecurity response. While some systems were able to keep providing service using manual processes, others experienced plant outages and communications failures. Authorities are still investigating impact details and have not finalized attribution, but ongoing federal guidance around PLC defenses highlights the types of safeguards utilities should prioritize.

Source: https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html