Full Breakdown
Coordinated Cyberattack Hits Minnesota Water Utilities
7/30/2026, 9:21:27 PM
Core Event: Multi-City Disruptions of Operational Technology
On July 26-27 a coordinated cyberattack targeted the operational technology (OT) that controls water and wastewater treatment at more than 30 community water systems across Minnesota. The intrusion caused a temporary shutdown of Braham’s treatment plant, cellular-communication failures at two Plymouth water towers, and automated-control disruptions in Maple Plain and South St. Paul. No city reported contamination, and state officials said there were no active requests for residents to alter water usage.
Background & Context: Growing Threats to U.S. Critical Infrastructure
The attacks arrived days after the Cybersecurity and Infrastructure Security Agency (CISA) updated a July 22 advisory warning that Iranian-affiliated actors were exploiting internet-facing programmable logic controllers (PLCs) in water, energy and government sectors. Similar intrusions have previously been linked to the Iran-aligned group CyberAv3ngers.
Timeline
- July 26–27 – Coordinated intrusion hits OT at >30 Minnesota water systems.
- July 28 – Minnesota IT Services (MNIT) reports no resident-use advisories and confirms unauthorized access with malicious intent.
- July 29 – MNIT says the investigation remains active and responders continue assessing affected systems.
Data & Statistics
- >30 water systems experienced unauthorized access; four municipalities (Braham, Plymouth, Maple Plain, South St. Paul) disclosed impacts.
- No ransom demand was detected, and water quality remained safe.
- Operational impact varied: Braham’s plant offline for roughly two hours; Plymouth’s equipment isolated; Maple Plain declared a local state of emergency; South St. Paul operated manually.
Official Statements & Responses
State and federal agencies described the incident as a “whole-of-government response.” MNIT coordinated with CISA, the EPA, the FBI and private-sector partners to contain the breach, share threat intelligence and restore services. The Minnesota Department of Health monitored public-health implications, while the FBI confirmed contact with victims. Officials emphasized the attack appeared aimed at disruption rather than financial gain.
On-the-Ground Reports
Braham’s mayor noted a brief advisory for residents to minimize use until the plant was back online. Plymouth’s IT division disconnected affected equipment from the network. Maple Plain’s emergency declaration enabled rapid resource coordination, and South St. Paul staff maintained water and wastewater flow manually despite compromised automated controls.
Conflicting Reports & Gaps
Sources differ on the number of municipalities that have publicly acknowledged the attack: some list only four cities, while others cite “more than 30” systems impacted without naming additional communities. Attribution remains unsettled; technical details about the exploited vulnerability, specific PLC models or data exfiltration have not been disclosed.
Verbatim Quotes
- “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” — John Israel, MNIT assistant commissioner and Minnesota chief information security officer
- “At this point, we can confirm that more than 30 water systems throughout the state were impacted,” — MNIT, assistant commissioner
- “While MNIT did not provide attribution, these tactics remain consistent with the tradecraft attributed to CyberAv3ngers and other IRGC-CEC affiliated groups, who have been known to target critical infrastructure since at least 2023,” — Scott Caveza, senior staff research engineer at Tenable
