**Coordinated Cyberattack Targets Over 30 Minnesota Water Systems**
On July 26 and 27, Minnesota experienced a significant cybersecurity incident when over 30 community water systems were targeted in a coordinated attack. The incident, which triggered a statewide cybersecurity response, resulted in operational disruptions at several facilities, including plant outages, communication failures, and affected automated controls. Minnesota IT Services (MNIT) is leading the investigation alongside federal partners, though details about the attacker, exploited vulnerabilities, and data theft remain undisclosed.
—
### Key Incidents and Impacts
The attack primarily targeted operational technology within water systems. Some of the most notable incidents include:
– **Braham:** The water plant went offline, prompting the city to issue a public request for residents to minimize water use until service was restored.
– **Plymouth:** Experienced cellular communication problems at two water towers and multiple wastewater lift stations. Despite these issues, the facility continued operating manually.
– **South St. Paul and Maple Plain:** Both maintained services after automated utility controls were affected. Maple Plain went as far as declaring a local state of emergency to streamline its response efforts.
According to MNIT, the incidents shared common characteristics, including timing, methods of access, and targeted infrastructure. These similarities led officials to describe the activity as coordinated. While investigators have not yet determined whether a single actor was responsible, the patterns align with tactics observed in other states and industries.
—
### Ongoing Investigation and Response
MNIT has been working closely with state agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the Federal Bureau of Investigation (FBI), to contain the threat and support recovery efforts. John Israel, MNIT assistant commissioner and Minnesota chief information security officer, emphasized the importance of a unified response:
> “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response.”
This broader effort is part of a larger federal warning issued four days before the Minnesota attacks, which highlighted Iranian-affiliated actors targeting programmable logic controllers (PLCs) from manufacturers like Rockwell Automation, Schneider Electric, and Siemens. Although MNIT has not confirmed a direct link to this campaign, security analysts noted that the tactics align with the CyberAv3ngers threat ecosystem, a group associated with Iran’s Islamic Revolutionary Guard Corps.
—
### Recommendations for Operators
CISA has issued sector-wide defensive guidance to help mitigate risks, including:
– Logging cellular modem connections.
– Restricting controller access to authorized systems.
– Inspecting running project files for unauthorized changes.
– Validating backups before restoration.
– Ensuring physical mode switches on controllers are set to “run” only after verifying file integrity.
As of July 29, 2026, MNIT has stated that the investigation remains active, with responders continuing to assess the damage and restore affected systems.
—
### Frequently Asked Questions (FAQ)
**Q: How many water systems were affected in the cyberattack?**
A: More than 30 community water systems across Minnesota were impacted.
**Q: Were any water services completely shut down?**
A. Yes, facilities like the water plant in Braham went offline temporarily. Others, like Plymouth, South St. Paul, and Maple Plain, maintained services despite operational challenges.
**Q: Who is investigating the attack?**
A: The investigation is led by Minnesota IT Services (MNIT), in collaboration with federal agencies, including CISA, the EPA, the FBI, and state responders.
**Q: Has the attacker been identified?**
A: No, attribution is still under investigation. Officials have not publicly identified the actor or group responsible.
**Q: What vulnerabilities were exploited?**
A. Specific vulnerabilities, affected products, and access methods have not been disclosed as the investigation is ongoing.
**Q: Were any large-scale data breaches reported?**
A: There has been no public confirmation of data theft related to the attacks.
**Q: How can water system operators protect themselves?**
A: CISA recommends measures such as logging modem connections, restricting access to authorized systems, inspecting project files, validating backups, and ensuring proper use of physical mode switches on controllers.
—
### Conclusion
The July 2026 cyberattack on Minnesota’s water systems highlights the growing vulnerability of critical infrastructure to sophisticated cyber threats. While officials have successfully contained much of the damage, the incident serves as a reminder of the importance of proactive cybersecurity measures, interagency collaboration, and robust defensive strategies. As the investigation continues, state and federal agencies will likely refine their guidance to help prevent future incidents and strengthen the resilience of essential services.



