


Perceptive Security
SOC/SIEM Consultancy

Hackers target over 30 Minnesota water utilities in coordinated OT attack
Published:
29 July 2026 at 14:55:57
Alert date:
29 July 2026 at 15:01:32
Source:
bleepingcomputer.com
Critical Infrastructure, Network Infrastructure, Mobile & IoT
Hackers launched a coordinated cyberattack targeting more than 30 community water systems across Minnesota. The Minnesota IT Services (MNIT) agency activated its full cybersecurity incident response capabilities in response to the attack. The attack focused on operational technology (OT) systems used by water utilities. The scale and coordination of the attack prompted a statewide response. This incident highlights the ongoing vulnerability of critical water infrastructure to cyber threats. The attack affected community-level water systems, raising concerns about public safety and service continuity. MNIT's involvement suggests state-level coordination is required to manage the incident effectively.
Technical details
On July 26-27, 2025, unknown hackers conducted a coordinated cyberattack targeting operational technology (OT) systems at more than 30 community water utilities across Minnesota. The City of Braham reported its water plant went offline due to a malicious cyber-attack on computerized operating systems. The plant was restored within approximately three hours. Other affected communities reported temporary equipment malfunctions and switched to manual operations or contingency plans to maintain services. MNIT activated its cybersecurity incident response capabilities statewide. The attack vector and threat actor remain unidentified. The incident bears similarities to prior attacks by Iranian-linked cyber actors who exploited exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) in critical infrastructure since March of the same year, though no direct attribution has been made. CISA issued guidance titled 'CI Fortify – Advice for isolating vital systems' recommending isolation of key OT systems during cyberattacks, co-authored with the Australian Signals Directorate's ACSC, the FBI, and international partners.
Mitigation steps:
1. Activate cybersecurity incident response capabilities and coordinate with federal, state, local, Tribal, and private-sector partners. 2. Isolate key OT systems from IT networks to ensure continuity of critical services during a cyberattack, per CISA's 'CI Fortify – Advice for isolating vital systems' guidance. 3. Switch to manual operations or implement contingency plans if automated systems are compromised. 4. Share threat intelligence with MNIT and relevant agencies for situational awareness. 5. Review and secure internet-exposed PLCs, particularly Rockwell Automation/Allen-Bradley devices, by restricting remote access and applying vendor patches. 6. Implement network segmentation between IT and OT environments. 7. Monitor OT systems for unauthorized access or anomalous behavior. 8. Follow CISA guidance for critical infrastructure protection and engage with CISA for incident response support. 9. Ensure water safety monitoring continues via manual processes if automated systems are offline.
Affected products:
Operational Technology (OT) systems at Minnesota community water utilities
Rockwell Automation / Allen-Bradley Programmable Logic Controllers (PLCs) - referenced in related Iranian actor advisory
Related links:
https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/
https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/
https://mn.gov/mnit/media/blog/?id=38-761869
https://www.facebook.com/BrahamMinnesota/posts/pfbid02DagFKxfmau7d8vzhhcEnXx2GewVUKhyZJeZsH28rDEzmYBByhcsFLmRHHT7s1Pz9l
https://www.facebook.com/BrahamMinnesota/posts/pfbid034VQiF2Gc9PHLEdrRSwcivevLMMXYtgkSVz9mVaa8erYstAFeXiMwsQkcM1GNBxnbl
https://www.facebook.com/CityofMaplePlain/posts/pfbid0nVZXQNwY9hueYnK5RqDstGokwSu2EBrtQkWZeiWjHgWz1KvyBJCad8HfPL12pNgTl
https://www.facebook.com/sspminnesota/posts/pfbid035MD6oSRqUsoj7QYzztv2mKAKFYZM5DhA4m1XBixP5NNV5ml
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
