A coordinated cyberattack targeted the operational technology of over 30 community water systems in Minnesota on July 26 and 27. This significant breach prompted a statewide cybersecurity response. Cities including Braham, Plymouth, South St. Paul, and Maple Plain reported various disruptions such as plant outages and compromised automated controls. Braham's water plant went offline, prompting officials to urge residents to conserve water. Plymouth experienced communication issues at water towers and wastewater lift stations, though operations continued manually. South St. Paul and Maple Plain maintained their services, with the latter declaring a local state of emergency.
Minnesota IT Services (MNIT) confirmed that more than 30 water systems were impacted, although the extent varied. The investigation is ongoing, and officials have not yet identified the attacker, specific vulnerabilities, or any data breaches. MNIT noted that the incidents shared timing, access methods, and targeted infrastructure, suggesting a coordinated effort. Despite similarities with other national attacks, investigators have not attributed these incidents to a specific actor.
MNIT is collaborating with state agencies, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, and the FBI to contain the situation and share threat intelligence. John Israel, MNIT assistant commissioner, emphasized the importance of a unified government response to such attacks on critical infrastructure.
Meanwhile, a separate alert was issued by U.S. agencies highlighting Iranian-affiliated actors targeting internet-facing programmable logic controllers. Although no direct link has been established between this campaign and the Minnesota attacks, the incident aligns with the CyberAv3ngers threat pattern, known for targeting critical infrastructure. Investigation remains active as of July 29, 2026, with MNIT assessing the systems affected.


