Cyberattack Knocks Out Water Systems in 30+ Minnesota Towns: What Every Water Utility Needs to Learn From It
SecureCyber Threat Alert | July 29, 2026 | Source: Minnesota IT Services (MNIT), StateScoop
The Short Version
Over the weekend of July 26 and 27, a coordinated cyberattack hit the computer systems that run water and wastewater equipment in more than 30 Minnesota communities. Minnesota's state IT agency confirmed the attack and activated emergency cybersecurity response alongside the FBI, CISA, and the EPA. At least one small town had to ask residents to conserve water while crews worked to bring a plant back online. Officials have not said who did it. If you run or oversee a water or wastewater system, the one thing to do this week is find out whether any of your plant control equipment can be reached from the open internet, and if it can, get it behind a firewall now.
What Happened
Picture the equipment that runs a water plant, the pumps, the valves, the alarms, as a car on autopilot. A small computer called a PLC (programmable logic controller) is the autopilot itself. It is not the steering wheel a person touches every day. It is the box quietly making thousands of small adjustments in the background, and operators mostly just watch a screen, called an HMI, that shows them what the autopilot is doing.
Over that weekend, someone reached into that autopilot in more than 30 Minnesota towns at once. In the city of Braham, population 1,700, the water plant went offline and the city had to ask residents to cut back on water use because the town's water tower only holds a limited supply. City officials confirmed the outage was caused by a "malicious cyber-attack of computerized operating systems by unknown actors." In Plymouth, a suburb of about 80,000 people, the city's IT team found the attackers had reached equipment connected through cellular modems at two water towers and several lift stations, and disconnected it to stop the attack from spreading.
Minnesota's state IT agency (MNIT) said it activated its cybersecurity incident response the moment it learned of the attack, and pulled in the state's Department of Public Safety, the Minnesota Fusion Center, the Department of Health, the Pollution Control Agency, CISA, the EPA, and the FBI. As of this writing, officials say there is no indication that drinking water quality was affected, and no community has been asked to boil or avoid using its water.
Who Is Behind It
Officials have been careful here, and so are we. Minnesota state government and the local cities involved have declined to say who is responsible. The investigation is still active.
Here is what we can say with a citation behind it. Just days before this attack, CISA and a group of federal partners updated an existing advisory (AA26-097A) warning that Iranian-affiliated hacking groups have been breaking into internet-connected plant equipment, including PLCs, at water utilities and other critical infrastructure across the country. Outside security researchers have noted that the timing of the Minnesota attack lines up with that warning, but they have also been clear that this is a coincidence worth watching, not a confirmed connection. A senior threat intelligence analyst at the Center for Internet Security told reporters it is still unclear whether the Minnesota attacks even involved the type of PLCs named in the federal advisory.
The honest answer right now: nobody outside the investigation knows for certain who did this or exactly how they got in. What we do know is that the method, which is reaching plant control equipment that should never have been exposed to the internet in the first place, is exactly the pattern federal agencies have been warning about for months.
How This Impacts You
If you operate a water or wastewater system, or you are responsible for one as a city manager, council member, or public works director, this is not a big-city problem. Braham has 1,700 residents. This attack is a reminder that attackers are not hand picking targets. They are scanning the entire internet for any plant equipment that answers when they knock, and small does not mean safe. If anything, small utilities are more exposed, because they often have the thinnest IT staff and the equipment was installed years ago by whoever was available, not necessarily with security in mind.
The EPA's own inspector general found in 2024 that more than 70 percent of water systems reviewed were not meeting basic federal requirements to have a current risk assessment and emergency response plan on file, and an audit of 1,000 systems serving 193 million people turned up 97 systems with critical or high risk vulnerabilities. That was true before this attack, and it is almost certainly still true at plenty of utilities today.
There is also a downstream risk worth naming plainly. Hospitals depend on a steady water supply, and some can only run for a few hours on backup reserves. A water outage is not just an inconvenience. It can become a public safety emergency very quickly for the most vulnerable people in a community.
What To Do Now
Do these first:
- Find out whether any PLC, HMI, or remote telemetry equipment (including anything connected through a cellular modem, like Plymouth's lift stations) can be reached directly from the public internet. If you do not know the answer, that is itself the answer, and it needs to be found out this week.
- If any control equipment is internet-facing, get it behind a secure gateway and firewall immediately. This is the single most repeated recommendation in the federal advisory, and it has not changed since April.
- Change default and shared passwords on any plant control systems, and make sure remote access requires multi-factor authentication.
Then follow up:
- Confirm your emergency response plan is current and that your team knows who to call, both internally and at the state and federal level, if something looks wrong on the HMI.
- Ask your integrator or vendor whether your specific PLC brand is named in CISA advisory AA26-097A (Rockwell Automation, Schneider Electric, and Siemens devices have all been named as of the July update).
- If you see anything unusual, report it. Utilities can reach out to the FBI's Internet Crime Complaint Center at ic3.gov, or CISA at 1-844-729-2472. Reporting early helps your own utility and helps warn others.
How SecureCyber Can Help
This kind of attack is exactly why SecureCyber built relationships with the FBI, Secret Service, and Ohio's fusion center and cyber reserve long before an incident happens, not after. If you operate a water, wastewater, or other critical infrastructure system in Ohio and you are not sure whether your control equipment is exposed, we are local, we know this sector, and we can help you find out. Give us a call at (937) 388-4405 or reach out at info@secdef.com.
Sources
- Minnesota IT Services, "MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure," published July 28, 2026. https://mn.gov/mnit/media/blog/?id=38-761869
- Colin Wood, StateScoop, "Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities," published July 28, 2026, updated July 28, 2026. https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/
- CISA, Joint Cybersecurity Advisory AA26-097A, "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure," originally published April 7, 2026, updated July 22, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
- Colin Wood, StateScoop, "'Critical' cyber vulnerabilities found in many water utilities, warns EPA inspector general," published 2024. https://statescoop.com/epa-critical-cybersecurity-vulnerabilities-water-utilities-2024/