Skip to main content
Emerging ThreatsData Breaches

Minnesota Water Systems Hit by Coordinated Cyberattack

Municipal water treatment plant in a Midwestern town with subtle digital infrastructure.

"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota chief information security officer—a fitting summation as state and federal teams moved to contain a coordinated intrusion that affected more than 30 Minnesota community water systems on July 26–27.

Immediate impacts: Braham, Plymouth, South St. Paul and Maple Plain

Local officials reported a range of operational effects across the state. Braham's water plant went offline and the city asked residents to minimize water use until treatment resumed. Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating systems manually. South St. Paul and Maple Plain both maintained services after automated utility controls were affected; Maple Plain declared a local state of emergency to support its response.

Minnesota IT Services (MNIT) told The Hacker News on July 28 that it was not aware of any active requests for residents to change their drinking-water use. The agency also said the response helped contain the incidents and prevent more serious impacts to critical services.

MNIT and federal partners coordinate containment and investigation

MNIT said it was coordinating containment, investigation, recovery and threat-intelligence sharing with the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the Federal Bureau of Investigation and affected utilities. The agency described the incidents as sharing common characteristics—timing, methods of access and the type of infrastructure targeted—supporting its description of the activity as coordinated.

Investigators identified similarities in how the systems were accessed but are not sharing technical details while the probe continues. As of July 29, MNIT said the investigation remained active and responders were continuing to assess affected systems. Attribution has not been finalized; officials have not publicly identified an attacker, affected products, an exploited vulnerability, or whether data was stolen.

Technical pattern, timing and possible links to prior warnings

State officials said the similarities in the incidents were consistent with activity observed by federal partners in other states and industries, but investigators could not yet determine whether a single actor was responsible for all the incidents. Four days before the Minnesota attacks, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers (PLCs) made by Rockwell Automation, Schneider Electric, Siemens and potentially other manufacturers.

That earlier campaign involved investigators observing attackers exfiltrate and modify project files, manipulate data shown through human-machine interfaces and supervisory control and data acquisition systems, and disable shutdown and alarm logic. State and federal officials have not publicly connected the Minnesota attacks to that campaign.

Security vendor Tenable observed that the Minnesota timing and operational pattern were consistent with the broader CyberAv3ngers threat ecosystem, while noting the incident has not been officially attributed. "While MNIT did not provide attribution, these tactics remain consistent with the tradecraft attributed to CyberAv3ngers and other IRGC-CEC affiliated groups, who have been known to target critical infrastructure since at least 2023," Scott Caveza, senior staff research engineer at Tenable, told The Hacker News.

CISA guidance and defensive steps cited in the response

CISA's advisory, cited in reporting on the wider warning, provides sector-wide defensive guidance that aligns with the types of access investigators said they observed. Recommendations include logging cellular modem connections, restricting controller access to authorized systems, and inspecting running project files for unauthorized changes. Operators should validate backups before restoration and, where a controller has a physical mode switch, place it in run mode only after validating its project files.

Minnesota officials have not publicly identified a PLC family, a specific access method, or a vulnerability used in the July incidents. MNIT said it was sharing threat intelligence and coordinating containment to help prevent escalation.

How technologists, policymakers, and the public are responding

  • Technologists and security teams: MNIT and federal partners are exchanging threat intelligence and following defensive practices such as the CISA recommendations—logging cellular modem connections, inspecting project files, restricting controller access, and validating backups—while investigators continue to assess affected systems.
  • Policymakers and regulators: State and federal agencies, including CISA, the EPA and the FBI, are coordinating on containment, investigation and recovery efforts; Minnesota described the response as coordinated across government.
  • Residents and local operators: Where a specific operational request was issued, Braham asked residents to minimize water use until treatment resumed; otherwise MNIT told reporters on July 28 it was not aware of active requests for residents to change their drinking-water use.

The facts assembled so far paint a picture of simultaneous disruptions tied together by common timing and methods, with investigators and multiple federal agencies working to determine scope and origin. With more than 30 systems affected and technical details withheld while the probe continues, the next clear milestones will be any public identification of exploited controllers, access methods, or an attribution that ties the incidents to the broader warnings issued days earlier.

Original story