A coordinated cyberattack targeted operational technology at more than 30 community water systems across Minnesota on July 26 and 27, prompting a statewide cybersecurity response.
In Braham, the water treatment plant was taken offline, leading city officials to request residents minimize water usage until services were restored. Plymouth experienced cellular communication disruptions at two water towers and multiple wastewater lift stations but managed to continue operations manually. South St. Paul and Maple Plain reported impacts to automated utility controls; Maple Plain declared a local state of emergency to bolster its response efforts.
Minnesota IT Services (MNIT) stated on July 28 that there were no active requests for residents to alter their drinking water usage. However, officials have not disclosed details regarding the attackers, methods of initial access, specific products affected, vulnerabilities exploited, or whether any data was compromised.
The reported figure of over 30 targeted systems refers to the number of systems attacked, not necessarily those confirmed as compromised or disrupted. Authorities have not specified how many systems experienced unauthorized access or operational impacts.
MNIT has not provided information on what evidence led them to classify the attack as coordinated, nor have they confirmed whether a single actor or method was responsible for the breaches.
In response, MNIT is collaborating with state agencies, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the Federal Bureau of Investigation, and affected utilities to manage containment, investigation, recovery, and threat intelligence sharing.
John Israel, MNIT assistant commissioner and Minnesota chief information security officer, emphasized the necessity of a unified governmental approach to cyberattacks on critical infrastructure.
Just days prior to the Minnesota incidents, U.S. agencies expanded warnings about Iranian-affiliated actors targeting internet-facing programmable logic controllers (PLCs) from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens. These attackers have been known to exfiltrate and modify project files, manipulate data displayed through human-machine interfaces and supervisory control and data acquisition systems, and disable shutdown and alarm functions.
While there is no official connection between the Minnesota attacks and the Iranian-affiliated campaign, cybersecurity firm Tenable noted that the timing and operational patterns are consistent with the broader CyberAv3ngers threat ecosystem. However, this incident has not been officially attributed to any specific group.
CISA’s advisory offers sector-wide defensive guidance, recommending measures such as logging cellular modem connections, restricting controller access to authorized systems, and inspecting running project files for unauthorized changes. Operators are advised to validate backups before restoration and, where applicable, place controllers in run mode only after confirming the integrity of project files.
This incident underscores the growing vulnerability of critical infrastructure to cyberattacks. The increasing digitization and interconnectivity of essential services necessitate robust cybersecurity measures and proactive threat intelligence sharing to safeguard public utilities from future disruptions.