Coordinated OT cyberattacks hit 30+ Minnesota water utilities

A coordinated attack disrupted automated controls at more than 30 Minnesota water utilities on July 26–27; officials say drinking water remained safe.
State and federal investigators are probing a coordinated cyberattack that disrupted operational technology systems at more than 30 Minnesota community water utilities on July 26 and 27. The attacks affected automated control functions and prompted emergency procedures at several sites.
Minnesota IT Services said cities reporting impacts include Maple Plain, Braham, South St. Paul and Plymouth. Contingency procedures were activated and, in most cases, water and wastewater operations continued to function.
The City of Braham temporarily took its water plant offline after detecting the intrusion and asked residents to limit water use. City officials reported that attackers shut down operating controls, which stopped the well and the water treatment plant.
Plymouth described the behavior as limited to equipment that connects via cellular communications. Other municipalities reported interruptions to automated control functions rather than complete service outages. All affected cities informed residents that drinking water remained safe.
Investigators have not attributed the incidents to any actor. Federal agencies earlier warned about Iran-linked groups targeting industrial control systems, and security analysts have identified groups such as CyberAv3ngers and Handala as actors with profiles consistent with attacks on water networks. Officials emphasized no formal attribution has been made and the investigation is ongoing.
Harry Thomas, CTO and co-founder of OT security firm Frenos, noted that tactics cataloged in MITRE ATT&CK for industrial control systems include denial of view, denial of control and manipulation. ‘Manipulation can be especially dangerous because operators may be shown incorrect system states,’ Thomas warned, adding that a sustained loss of view or control can require hands-on intervention or manual operation.
Denis Calderone, CTO of Suzu Labs, pointed to cellular modems as a likely vector. He said remote assets such as water towers, lift stations and pump stations often connect to SCADA systems over cellular links that may be overlooked during vulnerability studies, increasing the chance those paths are exploited.
Security researchers recalled 2020 attacks on water facilities in which threat actors used vulnerable cellular routers to reach control systems. Seemant Sehgal, founder and CEO of BreachLock, urged investigators to determine whether a shared weakness explains the Minnesota incidents because similar vulnerabilities may exist in other water systems.
State and federal teams continue to review logs, communication paths and device configurations to determine how attackers gained access and whether the incidents are linked. Affected municipalities are restoring automated controls and reassessing vulnerabilities. Officials said drinking water remains safe and that a final technical assessment has not yet been released.








