Minnesota Water Utilities Hit By Coordinated Cyberattack Statewide

More than 30 community water systems across Minnesota were targeted in a coordinated cyberattack on July 26 and 27, 2026, according to Minnesota IT Services (MNIT), the state’s technology agency. The attack struck operational technology at water and wastewater utilities statewide, prompting MNIT to activate its cybersecurity incident response and pull in the Cybersecurity and Infrastructure Security Agency, the FBI and the Environmental Protection Agency. Four cities, Braham, Plymouth, South St. Paul and Maple Plain, publicly confirmed impacts ranging from a plant outage to disrupted automated controls, though officials said drinking water quality was not affected and no boil-water advisories were issued.

Four Cities Report Outages, Comms Failures And A Local Emergency

In Braham, a city of roughly 1,700 residents, the municipal water plant went offline and officials asked residents to minimize water use until crews restored treatment, a process that took about two hours. The city later said the outage resulted from a malicious cyberattack on its computerized operating systems.

Plymouth, a suburb of about 80,000 people, reported cellular communications failures at two water towers and multiple wastewater lift stations. The city’s IT division disconnected the affected cellular-linked equipment and switched to manual operations to prevent further targeting.

South St. Paul said some automated utility controls were affected but maintained normal service throughout. Maple Plain declared a local state of emergency to expand its response capacity even as its water system kept operating.

State Agencies Coordinate Under Minnesota’s Whole-Of-State Program

MNIT said investigators found similarities in how the affected systems were accessed, which led the agency to describe the incident as coordinated, though it has not disclosed technical details while the investigation continues. The agency is working with the Minnesota Department of Public Safety, the Bureau of Criminal Apprehension’s Minnesota Fusion Center, the Minnesota Department of Health, the Minnesota Pollution Control Agency and federal partners to contain, investigate and remediate the damage.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer, in the agency’s July 28, 2026 press release.

State law classifies individual cyberattack reports as nonpublic information, so MNIT has not named which of the more than 30 systems were affected beyond the four cities that disclosed impacts on their own. No ransom demand was detected, and the Minnesota Department of Health said it was not aware of any utility asking residents to change their water use.

Investigators Point To A Wider Iranian-Linked PLC Campaign

Officials have not publicly attributed the attack to a specific actor, initial access method or vulnerability. But the timing overlaps closely with a July 22 update to CISA Advisory AA26-097A, which expanded a warning about Iranian-affiliated actors exploiting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric and Siemens.

Security firm Tenable said the operational pattern in Minnesota is consistent with the CyberAv3ngers threat ecosystem, a group the U.S. government has tied to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command, while cautioning that the incident has not been officially attributed. The group has drawn sanctions from the U.S. Treasury Department and a $10 million reward offer from the State Department’s Rewards for Justice program.

CISA’s advisory documents attackers exfiltrating and modifying PLC project files, manipulating data on human-machine interfaces and SCADA displays, and disabling shutdown and alarm logic at victim organizations since at least March 2026. The Plymouth attack’s targeting of cellular-connected equipment mirrors a vector the advisory specifically flags, since a disproportionate share of exposed field-deployed PLCs communicate over cellular modems.

An Unpatched Vulnerability Sits At The Center Of The Exposure

Independent research has tied much of the underlying campaign to CVE-2021-22681, a critical authentication bypass in Rockwell Automation’s Logix controller line carrying a CVSS score of 9.8. The flaw was disclosed in 2021 but confirmed under active exploitation only in March 2026, and Rockwell has said it cannot be fully addressed through a software patch, leaving network segmentation and engineering-workstation isolation as the primary defenses.

Internet-scanning analysis cited by Tenable found more than 5,000 exposed hosts globally identifying as Rockwell or Allen-Bradley devices, with roughly three-quarters located in the United States. CISA’s guidance also recommends placing PLCs with physical mode switches into run mode only after validating project files, and logging cellular modem connections for unauthorized changes.

A Sector Already Flagged As Under-Resourced And Exposed

The Minnesota incident lands against a backdrop of documented structural weakness in U.S. water cybersecurity. The EPA has previously found that more than 70 percent of water systems were failing to meet a 2018 legal requirement to maintain risk assessments and emergency response plans, and a separate audit of 1,000 systems serving 193 million people identified 97 with critical or high-risk vulnerabilities.

Small utilities in particular often rely on consumer-grade remote access tools or expose PLC interfaces directly to the internet, bypassing enterprise security controls. That pattern has recurred internationally, including at Romania’s National Water Authority, which suffered a ransomware attack compromising roughly 1,000 computer systems late last year, part of what Kurrant’s coverage described as an escalating pattern of cyber threats against water utilities across Europe and North America.

Vendors And Utilities Are Already Investing In OT Defenses

The incident adds urgency to a market that was already directing capital toward operational technology security. Engineering firm Jacobs was awarded a $13.4 million cybersecurity contract by the Hampton Roads Sanitation District earlier this year to harden industrial control systems serving 1.9 million residents, an example of the kind of assessment, monitoring and network engineering work that CISA is now urging smaller utilities to adopt.

For water and wastewater operators without dedicated OT security staff, MNIT’s response illustrates a whole-of-state model built around threat-intelligence sharing rather than utility-by-utility defense. Whether that model scales to the tens of thousands of small water systems nationwide, many with limited budgets and no in-house cybersecurity staff, remains an open question for federal and state policymakers.