
More than 30 Minnesota community water systems were hit by a coordinated cyberattack on July 26 and 27, 2026, Minnesota IT Services (MNIT) said Tuesday. The attacks on critical infrastructure hit automated control systems at municipal water and wastewater facilities, forcing staff to switch to manual processes. No city had to ask residents to change their drinking water usage, and the quality of their water remained safe (Reuters).
The first public reports came Monday from four cities — Plymouth, South St. Paul, Braham and Maple Plain — but MNIT confirmed Tuesday that the number of affected communities has surpassed 30. Minnesota authorities have activated national cybersecurity capabilities and are working with the FBI, CISA and EPA to investigate and recover. A cyberattack of this scale against critical infrastructure is considered one of the largest the state has ever recorded (StateScoop).
Minnesota water: which units were hit and how they dealt with the cyberattack

The town of Braham (population 1,700) was the first to publicly announce the outage. On Monday morning, the city’s system displayed a message saying the treatment plant was “out of service for an unknown reason” and asked residents to limit their water use. The plant remained offline for about two hours. City Manager Kevin Stahl told the Star Tribune that “bad actors used malware to gain access to the wireless connection” at the plant (Star Tribune).
In Plymouth, a Twin Cities suburb of 80,000, the attack on Minnesota water assets affected equipment connected via cellular communications to two water towers and multiple lift stations. The city’s IT department disconnected the affected equipment from the network to disrupt the cyberattack and prevent re-targeting during reconstruction. In South St. Paul, the attack affected technology that supports parts of the water utility, with staff activating pre-established emergency procedures (WaterWorld).
See also: CISA/ACSC: guide to isolating critical OTs during a cyberattack
Possible Iranian attribution for attack on Minnesota water systems

MNIT spokeswoman Emily Zimmer told Reuters that “the timeline, access methods, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed on critical infrastructure.” There has been no official attribution for the cyberattack on Minnesota water assets, but attacks on U.S. water utilities have repeatedly been attributed to hackers linked to Iran in recent years (Reuters).
CISA and other federal agencies recently issued an updated advisory warning of “urgent” efforts by Iranian hacking groups like CyberAv3ngers to target Internet-facing OT devices, particularly Siemens programmable logic controllers (PLCs). TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed that the Minnesota cyberattack has not yet been attributed to a specific actor and that it is “unclear” whether the PLC devices cited by CISA were involved (StateScoop).
The SecNews editorial team notes that the profile of the attack on Minnesota Water — small municipal units, cellular/wireless connectivity as an entry point, targeting automated control systems — matches the playbook that the CyberAv3ngers group used in the fall of 2023 on Unitronics PLCs at a Pennsylvania pumping station. However, without an official attribution, any nominal connection remains a hypothesis.
Why small critical infrastructure units are an easy target

Community water utilities serve populations of a few hundred to tens of thousands of residents and typically lack dedicated cybersecurity staff. The problem is exacerbated by the widespread adoption of cellular remote monitoring for water towers, lift stations, and treatment nodes: each of these devices becomes a potential entry point for a cyberattack if it is publicly exposed or has default credentials. Critical infrastructure in the US and Europe shares these vulnerabilities.
What’s unique about the Minnesota incidents is that nearly all of the units were able to maintain service through manual operation. This suggests that the cities had real business continuity plans in place — something that many similar critical infrastructure units do not. John Israel, Minnesota’s Chief Information Security Officer, stressed that “our response to the cyberattack worked as intended, enabling coordination across all levels of government, containing the incident, and helping to prevent more severe impacts.”
What Greek critical infrastructure providers are learning from the Minnesota water attack
- Internet-facing OT isolation: Prioritize physical isolation of PLCs, HMIs, and SCADA controllers from the public Internet. The recent CISA/ACSC guidance on vital systems isolation describes the steps in detail (BleepingComputer).
- Changing default credentials on cellular gateways, RTUs, and all field devices — the most common attack entry point in Minnesota was a wireless or cellular connection.
- Manual continuity plans: documented procedures for transitioning to manual operation, with regular familiarization exercises for personnel. Critical infrastructure units that had them maintained service.
- Monitoring of abnormal activity in access logs of control systems, especially outside of business hours.
- Segmentation between IT and OT networks: a compromised billing system should not be able to reach PLC controllers.
See also: CubePilot: DNS hijacking at cubepilot.org took services offline
See also: JFrog: OpenAI models found zero-day in self-hosted Artifactory
The FBI and CISA had not made a public statement Tuesday night. MNIT notes that the investigation is ongoing and details of the attack methods are not being publicly disclosed for operational reasons. The Minnesota water systems cyberattack incident adds to concerns that smaller critical infrastructure units in the U.S. and Europe — which typically operate on tight budgets and without dedicated IT/OT personnel — remain attractive targets for state-sponsored groups and opportunistic hacktivists (Reuters).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
