Skip Navigation

July 30, 2026 |

Coordinated Attacks on Minnesota Water Utilities Highlight Risks from Internet-Exposed Industrial Control Systems

Loading table of contents...

At a glance:  A coordinated cyberattack disrupted water and wastewater operations across more than 30 Minnesota communities between July 26 and July 27, 2026. The incidents affected operational technology environments used to manage water infrastructure and occurred days after the Cybersecurity and Infrastructure Security Agency updated guidance on the active targeting of internet-connected programmable logic controllers. Although the initial access vector and threat actor remain unknown, the attacks serve as a reminder that internet-accessible operational technology systems continue to create risk for critical infrastructure organizations.

Threat summary

Between July 26 and July 27, 2026, multiple Minnesota communities, including Braham, Plymouth, South St. Paul, and Maple Plain, reported cyber incidents affecting water and wastewater (WWS) operations. Minnesota Information Technology Services described the activity as a “coordinated cyberattack” targeting technology used by community water systems. Drinking water quality remained unaffected, and no boil-water advisories were issued.

Federal authorities have not publicly attributed the attacks to a specific threat group and have not disclosed the initial access vector.

Notably, Plymouth reported disconnecting cellular-connected equipment supporting WWS towers and lift stations during its response, while Braham reported that computerized operating controls were disabled, temporarily affecting water treatment operations. These details confirm that operational technology systems were affected, although officials have not identified whether the impacted systems were the original entry point.

WWS utilities rely on industrial control systems (ICS) to manage treatment processes, pumping stations, storage facilities, and distribution networks. These environments commonly use programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, engineering workstations, and remote communications infrastructure to support daily operations. Water towers, wells, pumping stations, reservoirs, and wastewater lift stations are frequently connected to central SCADA environments through cellular, radio, fiber, or other communications networks, enabling operators to monitor and manage geographically distributed assets remotely.

Many utilities use cellular networks to connect geographically distributed PLCs and field assets to centralized SCADA systems. If a PLC, engineering workstation, or management interface is accessible from the internet, an adversary may be able to access systems that control physical operations without first compromising the organization's corporate network.

Although details about the Minnesota incidents remain limited, the attacks occurred days after CISA updated Advisory AA26-097A, which documented Iranian-affiliated threat actors targeting internet-connected PLCs in water, energy, and government environments. According to the advisory, threat actors used legitimate PLC engineering software to access exposed industrial controllers, extract PLC project files, modify controller logic, and manipulate operational displays. These engineering platforms are vendor-provided tools used by operators and engineers to program, configure, troubleshoot, and maintain industrial control systems. Examples cited by CISA include Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation (TIA) Portal.

Because these tools are trusted and routinely used for administration, they provide authorized users with direct access to controller configurations, operational logic, and industrial processes. CISA reported that, in other victim environments, threat actors used these capabilities to review process configurations, transfer PLC project files, modify controller logic, and interact directly with industrial controllers. The advisory also documented instances in which adversaries altered PLC code and affected alarm and safety-related functions within operational technology environments. Authorities have not publicly linked the Minnesota incidents to these specific techniques or attributed the attacks to the threat actors described in the advisory.

Analyst Insight

In July 2025, the Canadian Centre for Cyber Security published The Cyber Threat to Canada's Water Systems: Assessment and Mitigation, which identified operational technology (OT) networks as the primary target for actors seeking to disrupt water systems. The report highlights activity from cybercriminals, state-sponsored actors, hacktivists, and other non-state groups targeting operational technology environments. [

The significance is that these actors do not share the same objectives, but they are increasingly targeting the same systems. Whether the goal is ransomware, disruption, espionage, or publicity, attackers continue to pursue internet-accessible PLCs, engineering workstations, remote access systems, and other industrial technologies that provide access to physical operations.

This suggests the challenge facing critical infrastructure operators is less about a specific threat actor and more about a common set of exposures. The Cyber Centre identifies internet-connected PLCs, exposed management interfaces, weak credentials, inadequate segmentation, and remote access pathways as recurring sources of exposure across WWS sector incidents.

The trend extends beyond water and wastewater utilities. Similar operational technology environments support manufacturing, energy, oil and gas, transportation, and government services. As organizations expand remote connectivity and digital management capabilities, exposed operational technology assets continue to provide a common access path into systems that control critical processes.

Reducing that exposure starts with understanding which industrial assets are accessible from external networks and reducing opportunities for unauthorized access before they are identified by threat actors.

Asset owners, operators would benefit from reviewing sector-specific guidance, including:


 

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up