Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

Swati KhandelwalJul 29, 2026Critical Infrastructure / Threat Intelligence

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.

Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls.

Braham‘s water plant went offline, and the city asked residents to minimize water use until treatment resumed. Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually.

South St. Paul and Maple Plain maintained services after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response.

Minnesota IT Services (MNIT) said on July 28 that it was not aware of any active requests for residents to change their drinking-water use. Officials have not publicly identified the attacker, initial access method, affected products, exploited vulnerability, or whether data was stolen.

The statewide figure counts systems targeted, not systems confirmed compromised or disrupted. Officials have not said how many experienced unauthorized access or operational effects.

Minnesota officials have not publicly explained what evidence led MNIT to describe the attack as coordinated or whether one actor or one access method linked the affected systems.

MNIT said it is coordinating containment, investigation, recovery and threat-intelligence sharing with state agencies, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the Federal Bureau of Investigation and affected utilities.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said John Israel, MNIT assistant commissioner and Minnesota chief information security officer.

MNIT said the response enabled agencies to contain the incident and help prevent more serious impacts to critical services.

In a separate development four days before the Minnesota attacks, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens and potentially other manufacturers.

Investigators in that campaign observed attackers exfiltrate and modify project files, manipulate data shown through human-machine interfaces and supervisory control and data acquisition systems, and disable shutdown and alarm logic.

State and federal officials have not publicly connected the Minnesota attacks to that campaign. Tenable said the timing and operational pattern were consistent with the broader CyberAv3ngers threat ecosystem, while noting that the incident has not been officially attributed.

The Hacker News has asked MNIT to clarify the disruption count and its basis for describing the activity as coordinated, and Tenable to explain the evidence behind its CyberAv3ngers assessment. We will update the story with any response.

CISA’s advisory provides sector-wide defensive guidance. Minnesota officials have not publicly identified a programmable logic controller family, access method, or vulnerability used in the attacks.

CISA also recommends logging cellular modem connections, restricting controller access to authorized systems and inspecting running project files for unauthorized changes. Operators should validate backups before restoration and, where a controller has a physical mode switch, place it in run mode only after validating its project files.

As of July 29, 2026, MNIT’s latest update said the investigation remained active, and responders were continuing to assess affected systems.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *