SYS::ONLINE
Wasteland.
Briefs1634
Issues21
SinceFeb 2026
LIVE
▣ Breach MINNESOTA-WATER-SY 2026-07-31

Minnesota Water Utilities: Coordinated OT Attack With a Contested Iran Link

"More than 30 Minnesota community water and wastewater systems were hit by a coordinated cyberattack against operational technology on July 26 and 27, 2026, according to a public statement from Minnesota IT Services…"

More than 30 Minnesota community water and wastewater systems were hit by a coordinated cyberattack against operational technology on July 26 and 27, 2026, according to a public statement from Minnesota IT Services (MNIT) issued July 28. At least one treatment plant, in the city of Braham, went briefly offline. State and local officials say drinking water quality was never affected. Attribution is unresolved and the sources disagree sharply on it: WIRED reports that a memo circulated within the water industry ties the attacks to Iran, U.S. officials told ABC News (via KSTP) that an Iran link is under preliminary investigation, and MNIT told KSTP flatly, "We are not attributing this activity to a specific threat actor at this time." The incident landed four days after CISA expanded advisory AA26-097A on Iranian-affiliated exploitation of internet-exposed PLCs.

What Happened

MNIT's own release (S7) is the anchor document: a coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, prompting activation of the state's cybersecurity incident response. MNIT says it is working with the Minnesota Department of Public Safety, the Bureau of Criminal Apprehension's Minnesota Fusion Center, the Department of Health, the Minnesota Pollution Control Agency, CISA, the EPA, the FBI, and local utilities.

The clearest single impact is Braham, a city of roughly 1,700 people. StateScoop and SOFX both report the city posted that its water plant was offline for an unknown reason and asked residents to minimize use because the water tower held only a limited quantity, then followed up the same day to say the plant was back online and that the outage resulted from "a malicious cyber-attack of computerized operating systems by unknown actors."

Plymouth, a Minneapolis suburb of about 80,000, gave the most technically specific account. A city spokesperson told StateScoop that the IT division "disconnected the affected equipment from the network to stop the cyberattack and avoid any potential retargeting while the equipment is reconfigured," and that impact was limited to "equipment connected via cellular communications" at two water towers and multiple lift stations. Plymouth said water quality was unaffected.

SOFX additionally reports that Maple Plain declared a local state of emergency and that South St. Paul kept water and wastewater services running manually after automated controls were hit. Those two details appear in the OTHER-tier source and are not corroborated by the PRIMARY or OUTLET reporting here, so treat them as single-source.

Two figures are worth stating precisely because officials have not: the number of systems targeted is "more than 30," and the number actually breached is unknown. SOFX notes explicitly that officials have not said how many of the 30-plus targeted systems were compromised. Do not read "30+ systems attacked" as "30+ systems breached."

What Was Taken

No source in this set reports theft of customer data, personal information, or billing records from any Minnesota utility. There is no record-count figure to report, and no breach-notification volume has been published. This was a disruption event, not a disclosed data-theft event, and the reporting to date is consistent on that point.

The relevant exfiltration signal is one level up, in the threat intelligence rather than the victim reporting. Tenable's Research Special Operations team notes that the July 22, 2026 update to CISA Advisory AA26-097A documented PLC project file exfiltration for the first time, alongside manipulation of reusable code modules embedded in PLC programs. Project files are the engineering blueprints of a plant: tag databases, control logic, I/O mapping, network layout. An actor holding them can plan a far more precise second intrusion than the first one required. If the Iran link is confirmed, defenders should assume the possibility that logic and configuration data left Minnesota networks even though no such loss has been announced.

What has been reported as affected is availability and control: automated control systems, cellular-connected remote equipment at towers and lift stations, and in Braham's case plant operation itself. The Minnesota Department of Health said it is not aware of any active requests from Minnesota cities for residents to modify drinking water usage.

Why It Matters

This is the widest simultaneous disruption of U.S. water OT publicly reported in this campaign. Prior incidents in the CyberAv3ngers lineage tended to be single-site defacements or nuisance manipulations of exposed HMIs. Thirty-plus systems inside one state across a single weekend is a different operational profile, and Tenable characterizes the timing as aligning closely with escalating Iranian-affiliated PLC exploitation.

WIRED frames it as the widest and most disruptive strike inflicted by Iranian hackers against the U.S. since the war began in late February, placing it in a series that WIRED says includes intrusions at medical supplies company Stryker and the personal email of FBI director Kash Patel. That is a strong claim from a single OUTLET source resting on a leaked memo, and it sits against MNIT's explicit refusal to attribute and ABC News sources describing the analysis as preliminary with forensics still outstanding. The honest read: an Iran nexus is plausible and being actively investigated by federal agencies, and it is not confirmed. No formal U.S. government determination has been announced.

The structural lesson is about victim size. Braham has 1,700 residents. Small municipal utilities are the softest layer of U.S. critical infrastructure: minimal or no dedicated security staff, remote sites reachable over cellular modems, and control equipment that is often unpatchable by design. An adversary that wants demonstrative pressure without crossing a casualty threshold gets exactly that from this target class, and MNIT's whole-of-government response model is the realistic compensating control for utilities that cannot defend themselves.

The Attack Technique

The initial access vector for the Minnesota intrusions has not been disclosed by MNIT or any federal agency, and none of these sources claims to know it. What follows is the documented adjacent tradecraft, not a confirmed account of this incident.

CISA Advisory AA26-097A, updated July 22, 2026, is the operative reference. Per Tenable, that update expanded observed PLC exploitation beyond Rockwell Automation to include Schneider Electric and Siemens devices, added the project file exfiltration behavior noted above, and added detection guidance for tampering with reusable code modules inside PLC programs. CISA has separately said it is seeing "a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector," that actors are "targeting water entities of all sizes," and that the activity has produced boil water notices in some locations.

The specific vulnerability to hunt for is CVE-2021-22681, a CVSS 9.8 authentication bypass in Rockwell Automation Logix controllers with no available vendor patch. CISA added it to the Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors. Tenable attributes the broader campaign to CyberAv3ngers, an IRGC-linked group it has profiled previously, including the group's four-phase capability escalation and IOCONTROL malware.

Plymouth's detail is the most operationally useful clue available: impact confined to cellular-connected equipment at towers and lift stations. Remote sites on cellular links frequently sit outside the perimeter that protects the main plant, are often directly addressable, and are commonly excluded from the segmentation diagram entirely. That is a pattern worth checking in your own estate regardless of what Minnesota's forensics eventually conclude.

What Organizations Should Do

  1. Get PLCs and HMIs off the public internet. This is CISA's own top-line instruction in its WWS guidance and it remains the single highest-yield action. Enumerate your external attack surface from the outside using Shodan or Censys against your netblocks, not from an internal asset inventory that will not show you what an attacker sees.
  2. Inventory cellular-connected remote assets specifically. Towers, lift stations, well houses, and booster stations on LTE modems are the exact class Plymouth reported as affected. Treat every cellular link as an internet connection, put it behind a VPN or private APN, and confirm it is covered by your segmentation policy.
  3. Change every default and shared credential on controllers and engineering workstations, and disable remote programming access where operations do not require it. CVE-2021-22681 has no patch, so compensating controls are the only mitigation: network isolation, ACLs restricting which hosts can reach controller ports, and keying the controller to RUN mode where the process allows.
  4. Hunt against AA26-097A, including the July 22 update. Look for unauthorized project file access or transfer, unexpected changes to reusable code modules and add-on instructions, controller mode changes, and unfamiliar sessions to Rockwell, Schneider Electric, and Siemens devices. Compare running logic against a known-good offline baseline.
  5. Establish and rehearse manual operation. South St. Paul reportedly kept water and wastewater services running by hand after automated controls were hit, per SOFX. That capability, plus a current offline copy of control logic and configuration for rapid rebuild, is what converts an OT compromise into an inconvenience rather than a service outage.
  6. Wire up your reporting path before you need it. MNIT's response, sharing threat intelligence and helping utilities contain, investigate, and remediate, is what small utilities in Minnesota had available. Know your state CISO, fusion center, CISA regional advisor, and WaterISAC contacts now, and report suspected OT intrusions to the FBI and CISA immediately rather than after internal triage.

Sources: Cyberattack Hits More Than 30 Minnesota Water Systems Days After Ir... | Minnesota Water Cyber Attack and CISA Advisory AA26-097A | Hackers target over 30 Minnesota water utilities in coordinated OT... | Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline | Coordinated cyberattack disrupts water utilities in 30+ ... | A Leaked Memo Ties Cyberattacks on Minnesota Water ... | MNIT activates statewide cybersecurity response to ... - MN.gov | Cyberattack on over 30 Minnesota water systems may be ...