Attack datesJuly 26–27, 2026
Utilities hit30-plus community
water systems
ImpactOT controls disabled
one plant offline
AttributionUnder investigation
no actor confirmed
What happened
Between Sunday July 26 and Monday July 27, attackers hit operational technology systems at more than 30 Minnesota community water and wastewater utilities in what Minnesota IT Services described as a coordinated cyberattack. Four cities publicly confirmed the incident. In Braham, population approximately 1,700, the water plant went entirely offline after computerized operating controls were disrupted. Crews restored operations within roughly two hours. Plymouth, population approximately 80,000, reported cellular communication failures at two water towers and multiple wastewater lift stations and disconnected affected cellular-connected equipment to halt the spread. South St. Paul and Maple Plain maintained water service after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response. By July 28, Minnesota IT Services confirmed the total affected count exceeded 30 communities. Minnesota officials described the attack as sharing characteristics with other coordinated cyberattacks on critical infrastructure that federal partners have observed. No specific access method, vulnerability, or industrial control system family has been publicly identified as the attack vector. CISA, the FBI, the EPA, the Minnesota Department of Public Safety, the Minnesota Department of Health, and the Minnesota Pollution Control Agency are all participating in the investigation and response. Water quality was not affected at any reported utility, and no communities have been asked to change their water use as of today.
Why it matters
A coordinated attack reaching more than 30 utilities simultaneously is not an opportunistic scan that happened to land on multiple targets. It reflects a deliberate operation against water sector operational technology at scale, in a single geographic region, over a two-day window. The EPA's own 2024 audit of 1,000 water systems found 97 with critical or high-risk vulnerabilities, and more than 70 percent of water systems failing to comply with risk assessment requirements under a 2018 law. The sector's security posture is distributed, under-resourced, and difficult to improve quickly. The Minnesota incident demonstrates what a coordinated attack on that posture looks like in practice.
Don't miss
The same week as the Minnesota attack, hacker group Hanzala separately claimed attacks on water utility systems in several California cities including Bakersfield, Chico, Salinas, and Stockton. Minnesota IT Services noted that the attack's timeline, access methods, and targeted infrastructure share characteristics with coordinated incidents federal partners have observed. US water utilities have previously been targeted by Iranian-affiliated actors, including the CyberAv3ngers group associated with Iran's Islamic Revolutionary Guard Corps, which has targeted internet-facing programmable logic controllers at water utilities. CISA's advisory AA26-097A, updated July 22, specifically expanded its documented scope of Iranian-affiliated PLC exploitation to include Schneider Electric and Siemens devices and added detection guidance for manipulation of reusable code in PLC programs.
Potential actions
- Water and wastewater utilities should review CISA Advisory AA26-097A and CISA's CI Fortify guidance published this week for sector-specific defensive steps including isolating internet-facing OT systems, restricting controller access to authorized systems, and logging cellular modem connections to field equipment.
- Validate backups of PLC project files before restoration and inspect running project files for unauthorized changes. CISA's AA26-097A specifically documented project file exfiltration in Iranian-affiliated campaigns as a new observed behavior. A restored project file from backup should be verified clean rather than assumed so.
- Utilities still operating internet-exposed PLCs or human-machine interfaces without network isolation should treat the Minnesota incident as a direct operational risk signal and prioritize network segmentation for field control systems above other pending security projects.
The Sip
More than 30 water utilities, two days, coordinated. The attack hit operational technology directly and knocked one plant offline. No actor has been confirmed. The EPA found that more than 70 percent of water systems were not meeting their own risk assessment obligations. The Minnesota incident is what the gap between that finding and reality looks like.