Minnesota Water Systems Hit by Coordinated Cyberattack — 30+ Plants Affected
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack on July 26 and 27, 2026, targeting operational technology and triggering a statewide emergency response from Minnesota IT Services (MNIT), CISA, the EPA, and the FBI. The cities of Braham, Plymouth, South St. Paul, and Maple Plain have publicly confirmed impact. Braham's water treatment plant went fully offline, prompting officials to ask residents to minimize water use until service was restored. Plymouth reported cellular communications failures affecting two water towers and multiple wastewater lift stations, though operations continued in manual mode. South St. Paul and Maple Plain experienced disruptions to automated utility controls, with Maple Plain declaring a local state of emergency to support its incident response. Investigators have not yet identified the threat actor, the exploited vulnerability, or whether sensitive operational or customer data was exfiltrated.
MNIT confirmed that the incidents shared common characteristics — including timing, method of access, and the type of infrastructure targeted — supporting the state's classification of the activity as coordinated. The agency noted that these patterns are consistent with activity previously observed by federal partners in other states and industries, though attribution has not been finalized and investigators could not yet confirm whether a single actor was responsible for all incidents. Specific technical indicators are being withheld while the investigation continues. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO, adding that the response enabled agencies to contain the incident and prevent more serious service disruptions.
The Minnesota campaign comes just days after U.S. agencies expanded a warning about Iranian-affiliated threat actors targeting internet-facing programmable logic controllers (PLCs) manufactured by Rockwell Automation, Schneider Electric, Siemens, and potentially other vendors. In that operation, investigators observed attackers exfiltrating and modifying engineering project files — a tactic consistent with gaining persistent, deep access to industrial control environments. Operators of small and mid-sized water utilities are particularly exposed because many run internet-reachable OT equipment without proper network segmentation. Defenders are urged to run a port scanner to identify any exposed management interfaces, verify that all remote access is funneled through a VPN (and test it with the DNS leak test), and validate TLS configurations on operator dashboards using the SSL/TLS checker. With attribution still pending and the scope expanding, this incident underscores the urgent need for water-sector utilities to harden exposed OT, enforce multi-factor authentication on remote access, and share threat intelligence rapidly with state and federal partners.