Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
Coordinated cyberattack disrupts operational technology at 30+ Minnesota water utilities on July 26-27.
Summary
State and federal agencies are investigating a coordinated cyberattack affecting operational technology systems at more than 30 water and wastewater utilities across Minnesota. The attacks, which occurred on July 26 and 27, disrupted automated control functions at facilities including Maple Plain, Braham, South St. Paul, and Plymouth, though contingency procedures kept most services operational. While officials have not formally attributed the incidents, the timing and targeting profile align with known Iranian threat groups such as CyberAv3ngers and Handala, and security experts highlight vulnerabilities in cellular communication links used by remote water infrastructure assets.
Full text
State and federal agencies are conducting an investigation after a coordinated cyberattack hit operational technology (OT) systems at dozens of water utilities in Minnesota. According to Minnesota IT Services (MNIT), more than 30 community water systems were targeted on July 26 and 27. Statements issued by some of the cities whose systems have been targeted – including Maple Plain, Braham, South St. Paul, and Plymouth – revealed that some “automated control functions” were affected. Still, contingency procedures were activated and in a majority of cases water and wastewater operations remained operational. The City of Braham did briefly take its water plant offline after the cybersecurity incident was detected, urging residents to minimize water use. Braham revealed that the “attackers shut down the operating controls, which shut down the well and water treatment plant”. Plymouth noted that “The issue is limited to equipment connected via cellular communications within the system.” The affected cities all informed citizens that drinking water remains safe and water and wastewater services are operational.Advertisement. Scroll to continue reading. It’s unclear who is behind the attack, which comes shortly after the US government warned critical infrastructure organizations about Iran-linked attacks targeting industrial control systems (ICS) made by Siemens, Rockwell Automation, and Schneider Electric. Iranian threat groups such as CyberAv3ngers and Handala would fit the profile for the attacks targeting Minnesota water systems. Still, investigators have not attributed the incidents to any specific actor, and officials have stressed that formal attribution has not been made. Industry professionals comment on the Minnesota water cyberattacks “When I read about cyberattacks affecting water systems in Minnesota, my mind does not immediately go to attribution. It goes to the operator and the potential operational consequences,” commented Harry Thomas, CTO and co-founder of OT security firm Frenos. “In MITRE ATT&CK for ICS those consequences include denial or loss of view, denial or loss of control, and manipulation of view or control. A physical process may continue running even when operators can no longer see it, influence it, or trust what their screens are telling them.” “Those distinctions matter,” Thomas added. “A denial of view or control can be temporary. A sustained loss may require hands-on intervention or manual operation. Manipulation can be even more dangerous because the process may be in a different state than what is being reported to the operator. From there, an incident can escalate into loss of availability, loss of protection, loss of safety, or physical damage.” Denis Calderone, CTO of Suzu Labs, pointed to Plymouth’s statement that the impact is limited to equipment connected via cellular communications. “Water towers, lift stations, pump stations, these remote assets often connect back to the SCADA system over cellular modems, and in our experience secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis, so it’s not too surprising then that the vector of attack may have been via these cellular connections,” Calderone said. “Oftentimes, regarding SCADA and Industrial Control networks, the infrastructure is largely built out by the integrator which increases the chance that these connections get overlooked,” Calderone added. “We saw in the reporting that Braham’s city administrator is now asking for their system vulnerability study to be reevaluated, and I wouldn’t be surprised if that study never included those cellular communication paths in the first place.” SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition It’s worth noting that in the 2020 attacks targeting water facilities in Israel, threat actors linked to the Iranian government exploited vulnerable cellular routers as a point of entry. Seemant Sehgal, founder & CEO of BreachLock, pointed out that investigators need to establish the common thread in the Minnesota water attacks because the same vulnerability “almost certainly exists in water infrastructure well beyond Minnesota”. Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software Related: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Related: Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Origin Energy Data Breach Affects 900,000 AustraliansNvidia and Tech Giants Launch AI Security AllianceCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsMCBS Data Breach Affects 1.2 Million IndividualsRockwell Patches Code Execution Flaws in Arena Simulation SoftwareData Breach Confirmed After Australian Energy Giant Origin Is HackedChick-fil-A Accounts Get Fried in Credential Stuffing Attack Latest News ShinyHunters Claims Ernst & Young HackCyera Acquiring Oasis Security in $1 Billion DealApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeOT Security Startup Frenos Raises $1.52 MillionMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Act Security Emerges from Stealth to Fight the Patch ProblemHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerHush Security Raises $30 Million for AI Agent Governance Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes
Indicators of Compromise
- malware — CyberAv3ngers
- malware — Handala