VYPR
breachPublished Jul 28, 2026· Updated Aug 3, 2026· 13 sources

Coordinated Cyberattack Disrupts Water Utilities in Over 30 Minnesota Communities

A coordinated cyberattack has disrupted water and wastewater utilities in more than 30 Minnesota communities, prompting a multi-agency response and raising concerns about critical infrastructure security.

A coordinated cyberattack struck water and wastewater utilities across more than 30 Minnesota communities on Sunday and Monday, state officials announced Tuesday. The incident disrupted operations, forcing some municipalities to issue water conservation advisories and prompting a swift, multi-agency response.

In Braham, a small city of 1,700 residents, officials reported on Monday morning that its water plant was offline due to a "malicious cyber-attack of computerized operating systems by unknown actors." Residents were urged to minimize water usage as the city's water tower held only a limited supply. By later that day, the plant was back online, but the incident highlighted the vulnerability of essential services.

Plymouth, a Minneapolis suburb with approximately 80,000 residents, also experienced disruptions. The city's IT division disconnected affected equipment from the network to contain the attack and prevent further spread. The disruption was limited to equipment connected via cellular communications at two water towers and multiple lift stations. City officials assured the public that water quality remained unaffected and safe.

Minnesota's Information Technology Services bureau is coordinating the response, providing threat intelligence, guidance, and assistance to affected utilities for containment, investigation, and remediation. The agency is collaborating with state public safety and health departments, a state fusion center, and federal partners including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI. John Israel, Minnesota's chief information security officer, stated that the "whole-of-government response" was effective in preventing more serious impacts.

While no specific threat actor has been officially named, the timing and nature of the attack have drawn attention to recent advisories from CISA and other federal agencies warning of Iranian hacking groups, such as CyberAv3ngers, targeting internet-connected operational technology (OT) devices. These groups have been observed attempting to compromise programmable logic controllers (PLCs) used in industrial control systems.

The incident also follows heightened geopolitical tensions, including U.S. strikes on an Iranian water facility and subsequent claims by the hacker group Hanzala of breaching water utility systems in several California cities. These events underscore a growing trend where nation-state or state-sponsored actors may prioritize disruption and destruction over data theft or financial gain.

Experts note that U.S. water utilities, many of which are small and resource-constrained, represent a significant target. A large percentage of these systems struggle to meet regulatory requirements for risk assessments and emergency response plans. The vulnerability of these systems is exacerbated by outdated infrastructure and a lack of dedicated cybersecurity resources, making them prime targets for sophisticated attacks.

The full scope of the Minnesota attack and its long-term implications are still under investigation. However, the incident serves as a stark reminder of the critical need for enhanced cybersecurity measures and preparedness across the nation's water infrastructure, especially as the threat landscape continues to evolve with new attack vectors and motivations.

This Tenable Blog article provides further technical context and attribution indicators for the coordinated cyberattack on Minnesota water utilities. It highlights the alignment of the attack pattern with Iranian-affiliated PLC exploitation activity, specifically referencing the updated CISA Advisory AA26-097A which now includes Schneider Electric and Siemens devices and details new exfiltration tactics. The article also reiterates the exploitation of CVE-2021-22681, a critical vulnerability in Rockwell Automation controllers.

The attacks, which occurred on July 26 and 27, impacted automated control functions at over 30 municipal water systems across Minnesota. While most operations remained online, the City of Braham briefly shut down its water plant, highlighting the potential for significant disruption. Investigators are examining potential links to Iran-linked threat groups, though no formal attribution has been made.

Security researchers at Tenable have identified the Iran-linked threat actor CyberAv3ngers as the suspected perpetrator behind the disruption of over 30 Minnesota water facilities. This attribution aligns with a recent CISA advisory warning of Iran-linked actors targeting programmable logic controllers (PLCs) in critical infrastructure, a tactic previously employed by CyberAv3ngers, which often exploits default passwords on devices like Unitronics PLCs.

The new reporting indicates that the coordinated cyberattack on Minnesota water systems, which impacted over 30 utilities, may be linked to the broader CyberAv3ngers threat ecosystem, though official attribution is pending. While state and federal officials have not publicly connected the incidents, security firm Tenable noted the timing and operational patterns align with this group's known activities. The investigation is ongoing, with responders continuing to assess affected systems and officials seeking to clarify the exact number of systems compromised.

The state of Minnesota has activated its cybersecurity incident response capabilities, involving federal partners such as CISA, the EPA, and the FBI, to investigate the cyberattack that disrupted operational technology at over 30 community water systems. While no specific threat actor has been publicly attributed to the attacks, the incident aligns with recent federal advisories warning of Iranian-affiliated actors targeting internet-connected industrial controllers across U.S. critical infrastructure.

The coordinated cyberattack on Minnesota water utilities, which occurred on Sunday and Monday, July 26 and 27, specifically targeted operational technology (OT) systems. While the City of Braham reported its water plant was back online after the outage, the full scope of the impact and the specific attack vector remain under investigation by Minnesota IT Services and federal partners. The incident highlights ongoing concerns about the security of critical infrastructure, with CISA recently issuing guidance on isolating OT systems.

The cyberattack on Minnesota water utilities, which occurred on July 26-27, has been linked by security researchers at Tenable to the Iran-linked group CyberAv3ngers. This attribution is based on patterns consistent with the group's past targeting of small water utilities, particularly following a CISA advisory on July 22 warning about Iranian-affiliated actors compromising internet-connected PLCs across U.S. water, energy, and government sectors. While officials have not publicly attributed the attack, the researchers noted that CyberAv3ngers has a history of compromising similar facilities, often exploiting remote access tools or directly exposed PLC interfaces.

The article from Tenable Blog provides crucial context for the recent cyberattack on Minnesota water utilities by detailing the evolving regulatory landscape. It highlights that while the EPA's direct sanitary survey mandate for cybersecurity was withdrawn, federal and state agencies are actively using existing authorities to enforce compliance. Specifically, it points to the upcoming June 30, 2026 deadline for community water systems serving over 3,300 people to certify their Risk and Resilience Assessments under AWIA 2013, and the finalized binding cybersecurity regulations for wastewater facilities in New York, which are expected to be mirrored by other states. Furthermore, it emphasizes the impending mandatory reporting of significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours under CIRCIA, underscoring the urgent need for water utilities to bolster their cybersecurity posture and compliance efforts.

The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. While the attacks do not appear to have significantly affected water supply or safety, they follow a recent CISA warning about Iran-affiliated threat groups targeting programmable logic controllers (PLCs) and other Internet-connected OT devices at critical infrastructure organizations across the US, including water systems.

CISA has issued an urgent advisory to water and wastewater utilities, urging them to secure operational technology (OT) systems, particularly internet-exposed programmable logic controllers (PLCs). This directive follows coordinated cyberattacks that recently compromised dozens of PLCs within Minnesota's water infrastructure, mirroring the disruptions reported in the initial advisory. The agency specifically highlighted the risk posed by undocumented cellular modems and emphasized the need to disconnect PLCs from the internet, implement strong password protection, and enable IP address allowlisting.

Officials are investigating the cyberattacks that targeted over 30 water systems in Minnesota on Sunday and Monday, with early warnings suggesting potential involvement by Iranian state-sponsored hackers. While no widespread impact on residents was reported, one city briefly asked for water conservation as they worked to restore controls. The FBI, CISA, and other agencies are involved in the investigation, noting similarities in timing and technology used across the incidents.

The cyber campaign targeting the US water and wastewater sector has expanded significantly beyond Minnesota, with at least six other states now confirmed to be affected. While specific details on the attack vectors and impacts in these new locations, including Michigan, South Dakota, and Georgia, remain limited, the widespread nature of the incidents points to a coordinated effort. This escalation highlights a persistent and growing threat to critical infrastructure from nation-state actors, with Iran being the primary suspect in these ongoing attacks.

Synthesized by Vypr AI