Coordinated Cyberattack Hits 30+ Minnesota Water Systems, Forces One Plant Offline

❓What:
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. thehackernews
Braham's water plant went offline, prompting the city to ask residents to minimize water use, while Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually.
South St. Paul and Maple Plain kept services running after automated utility controls were affected, with Maple Plain declaring a local state of emergency.
Officials have not publicly named the attacker, initial access method, affected products, exploited vulnerability, or whether data was stolen. The 30+ figure reflects systems targeted, not confirmed compromised or disrupted.
MNIT is coordinating with CISA, the EPA, the FBI, and affected utilities on containment, investigation, and recovery.
No confirmed link yet: four days earlier, U.S. agencies had expanded a warning about Iranian-affiliated actors targeting internet-facing PLCs from Rockwell Automation, Schneider Electric, Siemens, and possibly other manufacturers. State and federal officials haven't connected the Minnesota attacks to that campaign, though Tenable said the timing and pattern were consistent with the broader CyberAv3ngers ecosystem — while noting the incident is not officially attributed.
⚠️Impact:
Disrupted water treatment/distribution operations at multiple municipalities, with at least one plant fully offline.
MNIT said as of July 28 it was not aware of any active requests for residents to change drinking-water use — impact so far described as contained, not a public health emergency.
Highlights ongoing exposure of small/mid-size municipal OT environments to coordinated, multi-target campaigns.
Attribution and scope remain unresolved, which limits how defenders elsewhere can act on this specific incident beyond general hardening.
💡Recommendations:
Log cellular modem connections, restrict controller access to authorized systems, and inspect running project files for unauthorized changes.
Validate backups before restoration, and where a controller has a physical mode switch, place it in run mode only after validating its project files.
Review remote access paths into PLC/HMI/SCADA environments, especially internet-facing PLCs from the vendors named in the CISA advisory.
Confirm incident response and manual-operation fallback procedures are current for any OT-dependent utility clients.
Read the full story HERE
